helpcomputer
Topic Starter
Hi,
I live in a share house and we have a comunal laptop to do all things internet on. When i moved in the laptop had a number of viruses on it. I installed Malwarebites and Avast! which both removed a couple of problems. Now when i scan with them they say the computer is clear but…… my browser searches get redirected. when i search for somthing in google i get a list of results, but when i click on any of them it redirects to some random page. the page it redirects to changes depending on the search topic of the original search.
I am stumped.
below is the log i got using OTL:
Log 1:
OTL logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS
Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 96 BB 6A 5F 7E CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/03 20:48:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 20:05:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 20:05:51 | 000,000,000 | —D | M]
[2010/11/07 19:40:14 | 000,000,000 | -H-D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Extensions
[2011/04/04 20:55:03 | 000,000,000 | —D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\extensions
[2010/11/08 15:53:03 | 000,000,903 | -H– | M] () – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\searchplugins\conduit.xml
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/11/08 17:24:10 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/10 13:10:09 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/10 13:10:09 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/03/10 13:10:09 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/03/10 13:10:09 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/04/30 13:56:09 | 000,001,798 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell - "" = AutoRun
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\setup\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.ACDV - ACDV.dll File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
========== Files/Folders - Created Within 30 Days ==========
[2011/04/06 18:42:39 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 09:38:11 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/04/06 06:24:42 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/04/03 20:48:48 | 000,301,528 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2011/04/03 20:48:48 | 000,019,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2011/04/03 20:48:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/04/03 20:48:44 | 000,025,432 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2011/04/03 20:48:42 | 000,049,240 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2011/04/03 20:48:39 | 000,371,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2011/04/03 20:48:31 | 000,053,592 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2011/04/03 20:48:05 | 000,040,648 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2011/04/03 20:48:02 | 000,190,016 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/04/03 20:28:58 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Malwarebytes
[2011/04/03 20:28:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/03 20:28:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/03 20:19:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/04/03 20:19:30 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/04/03 17:33:57 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/30 20:36:21 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/30 11:43:02 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\outfall29mar
[2011/03/23 01:22:20 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{9D80DB5F-BF67-4DED-9F17-A21888A80F65}
[2011/03/22 13:22:07 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{F61A12D9-5FF1-467F-9B3E-ED4FEC9E28D1}
[2011/03/21 18:07:29 | 000,000,000 | —D | C] – C:\Windows\en
[2011/03/21 18:05:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/03/21 18:04:48 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/03/21 18:04:09 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/03/21 18:03:13 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2011/03/21 18:03:13 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2011/03/21 18:03:11 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2011/03/21 18:02:44 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2011/03/21 18:01:52 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2011/03/21 18:01:52 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2011/03/21 17:53:09 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\Windows Live
[2011/03/21 17:53:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/03/20 18:17:49 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Beacon20mar
[2011/03/19 15:05:06 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\schanck19mar
[2011/03/16 15:38:45 | 000,000,000 | -H-D | C] – C:\Users\fodd\dwhelper
[2011/03/13 09:52:44 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Meanos13mar
[2011/03/09 17:33:51 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/09 17:33:51 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/03/09 17:33:45 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 17:33:45 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CPFilters.dll
[2011/03/09 17:33:45 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 17:33:45 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2010/11/03 20:33:35 | 000,695,296 | —- | C] (AnjoCaido) – C:\Users\fodd\AppData\Roaming\MinecraftSP.exe
========== Files - Modified Within 30 Days ==========
[2011/04/06 18:46:54 | 000,359,929 | —- | M] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 06:31:13 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/06 06:31:13 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/06 06:24:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2011/04/03 20:48:48 | 000,002,000 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:48:31 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/31 16:59:36 | 000,005,120 | —- | M] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 20:38:35 | 000,000,392 | —- | M] () – C:\ProgramData\31186696
[2011/03/30 20:36:34 | 000,000,136 | —- | M] () – C:\ProgramData\~31186696
[2011/03/30 20:36:33 | 000,000,152 | —- | M] () – C:\ProgramData\~31186696r
========== Files Created - No Company Name ==========
[2011/04/06 18:46:35 | 000,359,929 | —- | C] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/03 20:48:48 | 000,002,000 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:44:53 | 062,623,864 | —- | C] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/30 20:36:33 | 000,000,152 | —- | C] () – C:\ProgramData\~31186696r
[2011/03/30 20:36:32 | 000,000,136 | —- | C] () – C:\ProgramData\~31186696
[2011/03/30 20:36:20 | 000,000,392 | —- | C] () – C:\ProgramData\31186696
[2011/03/21 18:06:55 | 000,001,253 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/03/21 18:06:08 | 000,001,322 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/02/13 11:23:43 | 000,005,120 | —- | C] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/14 12:10:57 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/08 17:47:37 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/08 17:13:13 | 000,093,671 | —- | C] () – C:\Users\fodd\AppData\Roaming\Uninstal.exe
[2009/07/14 14:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 14:33:53 | 000,266,808 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 10:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 09:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 07:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/12/01 19:46:12 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/12/01 19:08:40 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/30 13:45:42 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2005/05/06 18:06:00 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
========== LOP Check ==========
[2011/04/01 08:20:33 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\.minecraft
[2010/11/12 18:16:39 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\ACD Systems
[2011/04/06 15:46:18 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\Azureus
[2010/11/12 19:31:40 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\DAEMON Tools Lite
[2010/11/12 19:46:08 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\Sony
[2011/02/15 15:57:07 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\TuneUpMedia
[2009/07/14 14:53:46 | 000,011,932 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 07:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/08 14:01:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/11 07:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2008/03/31 21:44:18 | 000,004,483 | RH– | M] () – C:\dell.sdr
[2010/12/12 16:02:37 | 000,203,836 | RHS- | M] () – C:\grldr
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/17 21:51:46 | 000,000,801 | -H– | M] () – C:\os604495.bin
[2011/04/06 06:24:38 | 2011,172,864 | -HS- | M] () – C:\pagefile.sys
[2010/07/18 10:05:01 | 000,000,072 | —- | M] () – C:\SNDUpgrade.log
[2010/12/12 16:02:38 | 000,000,000 | RHS- | M] () – C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009/07/14 14:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 14:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 14:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 14:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 11:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 11:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/02/24 02:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 14:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/07 19:37:35 | 000,000,221 | -HS- | M] () – C:\Users\fodd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-06 00:39:06
< End of report >
Log 2:
OTL Extras logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS
Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Photo Manager 12.Manage] – "C:\Program Files\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56415658-366E-4E28-A6BD-68EC63E560E0}" = Vegas Pro 9.0
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A5CBD7C5-CF16-443F-A4F2-3503C9DE311B}" = ACDSee Photo Manager 12
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"conduitEngine" = Conduit Engine
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"ffdshow_is1" = ffdshow v1.1.3562 [2010-09-07]
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Minecraft 1.2.0_02" = Minecraft 1.2.0_02
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"TuneUpMedia" = TuneUp Companion 1.9.0
"VLC media player" = VLC media player 1.1.4
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 20/03/2011 3:52:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: DevDetect.exe, version: 5.1.237.0, time
stamp: 0x4bb54196 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0xc000008c Fault offset: 0x00009617 Faulting
process id: 0xd90 Faulting application start time: 0x01cbded09cbb32fd Faulting application
path: C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe Faulting module
path: C:\Windows\system32\KERNELBASE.dll Report Id: fc0bac04-52c6-11e0-a562-001d0939d3f5
Error - 21/03/2011 4:02:07 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program wmplayer.exe version 12.0.7600.16667 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 10ec Start
Time: 01cbe79d1dbb2ba1 Termination Time: 12 Application Path: C:\Program Files\Windows
Media Player\wmplayer.exe Report Id: 7d72158e-5391-11e0-a562-001d0939d3f5
Error - 21/03/2011 10:09:40 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7600.16385,
time stamp: 0x4a5bccb3 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0x0000046b Fault offset: 0x00009617 Faulting
process id: 0x980 Faulting application start time: 0x01cbde760c2a245e Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report
Id: dc1be636-53c4-11e0-a562-001d0939d3f5
Error - 23/03/2011 11:45:18 PM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 30/03/2011 6:39:59 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 31/03/2011 2:59:41 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x0002fa7b Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 72d3fc67-5b64-11e0-9d36-001d0939d3f5
Error - 31/03/2011 2:59:46 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0150010 Fault offset: 0x000817ff Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 75de3a8c-5b64-11e0-9d36-001d0939d3f5
Error - 3/04/2011 8:14:46 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 4/04/2011 4:37:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: 0.10262949141378142.exe, version: 0.0.0.0,
time stamp: 0x49b02529 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x00061b7f Faulting
process id: 0xa7c Faulting application start time: 0x01cbf2a37fb463fc Faulting application
path: C:\Users\fodd\AppData\Local\Temp\0.10262949141378142.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: c1f64f43-5e96-11e0-84dd-001d0939d3f5
Error - 5/04/2011 8:00:25 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7600.16450 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: a7c Start
Time: 01cbf34398692a31 Termination Time: 448 Application Path: C:\Windows\Explorer.EXE
Report
Id: fd924228-5f7b-11e0-a769-001d0939d3f5
[ Media Center Events ]
Error - 25/12/2010 5:38:55 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 8:38:45 PM - Error connecting to the internet. 8:38:51 PM - Unable
to contact server..
Error - 25/12/2010 6:39:01 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:01 PM - Error connecting to the internet. 9:39:01 PM - Unable
to contact server..
Error - 25/12/2010 6:39:07 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:06 PM - Error connecting to the internet. 9:39:06 PM - Unable
to contact server..
Error - 25/12/2010 7:39:11 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:11 PM - Error connecting to the internet. 10:39:11 PM - Unable
to contact server..
Error - 25/12/2010 7:39:18 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:16 PM - Error connecting to the internet. 10:39:16 PM - Unable
to contact server..
Error - 26/12/2010 7:20:47 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:47 AM - Error connecting to the internet. 10:20:47 AM - Unable
to contact server..
Error - 26/12/2010 7:21:04 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:52 AM - Error connecting to the internet. 10:20:52 AM - Unable
to contact server..
Error - 5/01/2011 3:37:22 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:37:12 AM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 9/01/2011 3:47:52 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:47:52 AM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 10/01/2011 3:11:57 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:11:52 AM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
[ System Events ]
Error - 5/04/2011 7:51:34 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 5/04/2011 7:51:35 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 5/04/2011 8:56:57 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 5/04/2011 8:57:27 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 5/04/2011 4:24:46 PM | Computer Name = Hoth | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:11:21 AM on ?6/?04/?2011 was unexpected.
Error - 5/04/2011 4:24:47 PM | Computer Name = HOTH | Source = BugCheck | ID = 1001
Description =
Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Media Player Network Sharing Service service to connect.
Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
Error - 6/04/2011 1:53:28 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 6/04/2011 2:07:17 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
< End of report >
I hope someone can help. It is driving me crazy.
thanks
Joe.
I live in a share house and we have a comunal laptop to do all things internet on. When i moved in the laptop had a number of viruses on it. I installed Malwarebites and Avast! which both removed a couple of problems. Now when i scan with them they say the computer is clear but…… my browser searches get redirected. when i search for somthing in google i get a list of results, but when i click on any of them it redirects to some random page. the page it redirects to changes depending on the search topic of the original search.
I am stumped.
below is the log i got using OTL:
Log 1:
OTL logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS
Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\fodd\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\AVAST Software\Avast\snxhk.dll (AVAST Software)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (OEM02Dev) – C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (OEM02Vfx) – C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (rismxdp) – C:\Windows\System32\drivers\rixdptsk.sys (REDC)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E0 96 BB 6A 5F 7E CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Google Powered Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/04/03 20:48:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/23 20:05:51 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/23 20:05:51 | 000,000,000 | —D | M]
[2010/11/07 19:40:14 | 000,000,000 | -H-D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Extensions
[2011/04/04 20:55:03 | 000,000,000 | —D | M] (No name found) – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\extensions
[2010/11/08 15:53:03 | 000,000,903 | -H– | M] () – C:\Users\fodd\AppData\Roaming\Mozilla\Firefox\Profiles\uccirord.default\searchplugins\conduit.xml
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/08 17:24:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/11/08 17:24:10 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/10 13:10:09 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/03/10 13:10:09 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/03/10 13:10:09 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/03/10 13:10:09 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/04/30 13:56:09 | 000,001,798 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell - "" = AutoRun
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\directx\command - "" = H:\DirectX9\dxsetup.exe
O33 - MountPoints2\{5c863e3e-ee3f-11df-a365-001d0939d3f5}\Shell\setup\command - "" = H:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.ACDV - ACDV.dll File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
========== Files/Folders - Created Within 30 Days ==========
[2011/04/06 18:42:39 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 09:38:11 | 000,000,000 | -H-D | C] – C:\Windows\AxInstSV
[2011/04/06 06:24:42 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/04/03 20:48:48 | 000,301,528 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2011/04/03 20:48:48 | 000,019,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2011/04/03 20:48:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/04/03 20:48:44 | 000,025,432 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2011/04/03 20:48:42 | 000,049,240 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2011/04/03 20:48:39 | 000,371,544 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2011/04/03 20:48:31 | 000,053,592 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2011/04/03 20:48:05 | 000,040,648 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2011/04/03 20:48:02 | 000,190,016 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/04/03 20:47:56 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/04/03 20:28:58 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Malwarebytes
[2011/04/03 20:28:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/03 20:28:54 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/04/03 20:28:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/03 20:19:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/04/03 20:19:30 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2011/04/03 17:33:57 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/03/30 20:36:21 | 000,000,000 | —D | C] – C:\Users\fodd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/30 11:43:02 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\outfall29mar
[2011/03/23 01:22:20 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{9D80DB5F-BF67-4DED-9F17-A21888A80F65}
[2011/03/22 13:22:07 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\{F61A12D9-5FF1-467F-9B3E-ED4FEC9E28D1}
[2011/03/21 18:07:29 | 000,000,000 | —D | C] – C:\Windows\en
[2011/03/21 18:05:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/03/21 18:04:48 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2011/03/21 18:04:09 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/03/21 18:03:13 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2011/03/21 18:03:13 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2011/03/21 18:03:11 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2011/03/21 18:02:44 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2011/03/21 18:01:52 | 002,983,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbon.dll
[2011/03/21 18:01:52 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIRibbonRes.dll
[2011/03/21 17:53:09 | 000,000,000 | -H-D | C] – C:\Users\fodd\AppData\Local\Windows Live
[2011/03/21 17:53:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/03/20 18:17:49 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Beacon20mar
[2011/03/19 15:05:06 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\schanck19mar
[2011/03/16 15:38:45 | 000,000,000 | -H-D | C] – C:\Users\fodd\dwhelper
[2011/03/13 09:52:44 | 000,000,000 | —D | C] – C:\Users\fodd\Desktop\Meanos13mar
[2011/03/09 17:33:51 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/09 17:33:51 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2011/03/09 17:33:45 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 17:33:45 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CPFilters.dll
[2011/03/09 17:33:45 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 17:33:45 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2010/11/03 20:33:35 | 000,695,296 | —- | C] (AnjoCaido) – C:\Users\fodd\AppData\Roaming\MinecraftSP.exe
========== Files - Modified Within 30 Days ==========
[2011/04/06 18:46:54 | 000,359,929 | —- | M] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 10:42:27 | 000,020,576 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/06 06:31:13 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/04/06 06:31:13 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/04/06 06:24:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2011/04/03 20:48:48 | 000,002,000 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:48:31 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/31 16:59:36 | 000,005,120 | —- | M] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/30 20:38:35 | 000,000,392 | —- | M] () – C:\ProgramData\31186696
[2011/03/30 20:36:34 | 000,000,136 | —- | M] () – C:\ProgramData\~31186696
[2011/03/30 20:36:33 | 000,000,152 | —- | M] () – C:\ProgramData\~31186696r
========== Files Created - No Company Name ==========
[2011/04/06 18:46:35 | 000,359,929 | —- | C] () – C:\Users\fodd\Desktop\dds.scr
[2011/04/03 20:48:48 | 000,002,000 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/04/03 20:44:53 | 062,623,864 | —- | C] () – C:\Users\fodd\Desktop\setup_av_free.exe
[2011/04/03 20:28:54 | 000,001,073 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/03/30 20:36:33 | 000,000,152 | —- | C] () – C:\ProgramData\~31186696r
[2011/03/30 20:36:32 | 000,000,136 | —- | C] () – C:\ProgramData\~31186696
[2011/03/30 20:36:20 | 000,000,392 | —- | C] () – C:\ProgramData\31186696
[2011/03/21 18:06:55 | 000,001,253 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/03/21 18:06:08 | 000,001,322 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/02/13 11:23:43 | 000,005,120 | —- | C] () – C:\Users\fodd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/14 12:10:57 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/08 17:47:37 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/08 17:13:13 | 000,093,671 | —- | C] () – C:\Users\fodd\AppData\Roaming\Uninstal.exe
[2009/07/14 14:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 14:33:53 | 000,266,808 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 12:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 12:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 12:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 12:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 12:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 12:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 10:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 09:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 09:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 07:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/12/01 19:46:12 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2008/12/01 19:08:40 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2008/10/30 13:45:42 | 000,180,720 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2005/05/06 18:06:00 | 000,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
========== LOP Check ==========
[2011/04/01 08:20:33 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\.minecraft
[2010/11/12 18:16:39 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\ACD Systems
[2011/04/06 15:46:18 | 000,000,000 | —D | M] – C:\Users\fodd\AppData\Roaming\Azureus
[2010/11/12 19:31:40 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\DAEMON Tools Lite
[2010/11/12 19:46:08 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\Sony
[2011/02/15 15:57:07 | 000,000,000 | -H-D | M] – C:\Users\fodd\AppData\Roaming\TuneUpMedia
[2009/07/14 14:53:46 | 000,011,932 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/11 07:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/07/14 11:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/11/08 14:01:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/11 07:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2008/03/31 21:44:18 | 000,004,483 | RH– | M] () – C:\dell.sdr
[2010/12/12 16:02:37 | 000,203,836 | RHS- | M] () – C:\grldr
[2011/04/06 06:24:36 | 1508,376,576 | -HS- | M] () – C:\hiberfil.sys
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/13 15:58:19 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/03/17 21:51:46 | 000,000,801 | -H– | M] () – C:\os604495.bin
[2011/04/06 06:24:38 | 2011,172,864 | -HS- | M] () – C:\pagefile.sys
[2010/07/18 10:05:01 | 000,000,072 | —- | M] () – C:\SNDUpgrade.log
[2010/12/12 16:02:38 | 000,000,000 | RHS- | M] () – C:\winx.ld
< %systemroot%\Fonts\*.com >
[2009/07/14 14:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 14:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 14:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 14:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 11:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 11:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/02/24 02:04:21 | 000,040,648 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 01:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 14:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/07 19:37:35 | 000,000,221 | -HS- | M] () – C:\Users\fodd\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/04/06 18:43:04 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\fodd\Desktop\OTL.exe
[2011/04/03 20:46:05 | 062,623,864 | —- | M] () – C:\Users\fodd\Desktop\setup_av_free.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-06 00:39:06
< End of report >
Log 2:
OTL Extras logfile created on: 6/04/2011 6:45:06 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\fodd\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 41.46 Gb Free Space | 18.82% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.73 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive E: | 2.81 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 1397.26 Gb Total Space | 770.81 Gb Free Space | 55.17% Space Free | Partition Type: NTFS
Computer Name: HOTH | User Name: fodd | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee Photo Manager 12.Manage] – "C:\Program Files\ACD Systems\ACDSee\12.0\ACDSeeQV12.exe" "%1" (ACD Systems International Inc.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56415658-366E-4E28-A6BD-68EC63E560E0}" = Vegas Pro 9.0
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A5CBD7C5-CF16-443F-A4F2-3503C9DE311B}" = ACDSee Photo Manager 12
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"conduitEngine" = Conduit Engine
"Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011)
"ffdshow_is1" = ffdshow v1.1.3562 [2010-09-07]
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Minecraft 1.2.0_02" = Minecraft 1.2.0_02
"Mozilla Firefox (3.6.16)" = Mozilla Firefox (3.6.16)
"TuneUpMedia" = TuneUp Companion 1.9.0
"VLC media player" = VLC media player 1.1.4
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 20/03/2011 3:52:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: DevDetect.exe, version: 5.1.237.0, time
stamp: 0x4bb54196 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0xc000008c Fault offset: 0x00009617 Faulting
process id: 0xd90 Faulting application start time: 0x01cbded09cbb32fd Faulting application
path: C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe Faulting module
path: C:\Windows\system32\KERNELBASE.dll Report Id: fc0bac04-52c6-11e0-a562-001d0939d3f5
Error - 21/03/2011 4:02:07 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program wmplayer.exe version 12.0.7600.16667 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 10ec Start
Time: 01cbe79d1dbb2ba1 Termination Time: 12 Application Path: C:\Program Files\Windows
Media Player\wmplayer.exe Report Id: 7d72158e-5391-11e0-a562-001d0939d3f5
Error - 21/03/2011 10:09:40 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: wmpnetwk.exe, version: 12.0.7600.16385,
time stamp: 0x4a5bccb3 Faulting module name: KERNELBASE.dll, version: 6.1.7600.16385,
time stamp: 0x4a5bdaae Exception code: 0x0000046b Fault offset: 0x00009617 Faulting
process id: 0x980 Faulting application start time: 0x01cbde760c2a245e Faulting application
path: C:\Program Files\Windows Media Player\wmpnetwk.exe Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report
Id: dc1be636-53c4-11e0-a562-001d0939d3f5
Error - 23/03/2011 11:45:18 PM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 30/03/2011 6:39:59 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 31/03/2011 2:59:41 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x0002fa7b Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 72d3fc67-5b64-11e0-9d36-001d0939d3f5
Error - 31/03/2011 2:59:46 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: ACDSee12.exe, version: 12.0.344.0, time
stamp: 0x4bd8b413 Faulting module name: ntdll.dll, version: 6.1.7600.16695, time
stamp: 0x4cc7ab44 Exception code: 0xc0150010 Fault offset: 0x000817ff Faulting process
id: 0x91c Faulting application start time: 0x01cbef712ab2fd7d Faulting application
path: C:\Program Files\ACD Systems\ACDSee\12.0\ACDSee12.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: 75de3a8c-5b64-11e0-9d36-001d0939d3f5
Error - 3/04/2011 8:14:46 AM | Computer Name = Hoth | Source = EventSystem | ID = 4621
Description =
Error - 4/04/2011 4:37:22 AM | Computer Name = Hoth | Source = Application Error | ID = 1000
Description = Faulting application name: 0.10262949141378142.exe, version: 0.0.0.0,
time stamp: 0x49b02529 Faulting module name: ntdll.dll, version: 6.1.7600.16695,
time stamp: 0x4cc7ab44 Exception code: 0xc0000005 Fault offset: 0x00061b7f Faulting
process id: 0xa7c Faulting application start time: 0x01cbf2a37fb463fc Faulting application
path: C:\Users\fodd\AppData\Local\Temp\0.10262949141378142.exe Faulting module path:
C:\Windows\SYSTEM32\ntdll.dll Report Id: c1f64f43-5e96-11e0-84dd-001d0939d3f5
Error - 5/04/2011 8:00:25 AM | Computer Name = Hoth | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7600.16450 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: a7c Start
Time: 01cbf34398692a31 Termination Time: 448 Application Path: C:\Windows\Explorer.EXE
Report
Id: fd924228-5f7b-11e0-a769-001d0939d3f5
[ Media Center Events ]
Error - 25/12/2010 5:38:55 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 8:38:45 PM - Error connecting to the internet. 8:38:51 PM - Unable
to contact server..
Error - 25/12/2010 6:39:01 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:01 PM - Error connecting to the internet. 9:39:01 PM - Unable
to contact server..
Error - 25/12/2010 6:39:07 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 9:39:06 PM - Error connecting to the internet. 9:39:06 PM - Unable
to contact server..
Error - 25/12/2010 7:39:11 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:11 PM - Error connecting to the internet. 10:39:11 PM - Unable
to contact server..
Error - 25/12/2010 7:39:18 AM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:39:16 PM - Error connecting to the internet. 10:39:16 PM - Unable
to contact server..
Error - 26/12/2010 7:20:47 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:47 AM - Error connecting to the internet. 10:20:47 AM - Unable
to contact server..
Error - 26/12/2010 7:21:04 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 10:20:52 AM - Error connecting to the internet. 10:20:52 AM - Unable
to contact server..
Error - 5/01/2011 3:37:22 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:37:12 AM - Failed to retrieve MCEClientUX (Error: Unable to connect
to the remote server)
Error - 9/01/2011 3:47:52 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:47:52 AM - Failed to retrieve Directory (Error: Unable to connect
to the remote server)
Error - 10/01/2011 3:11:57 PM | Computer Name = Hoth | Source = MCUpdate | ID = 0
Description = 6:11:52 AM - Failed to retrieve Broadband (Error: Unable to connect
to the remote server)
[ System Events ]
Error - 5/04/2011 7:51:34 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 5/04/2011 7:51:35 AM | Computer Name = Hoth | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.
Error - 5/04/2011 8:56:57 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 5/04/2011 8:57:27 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 5/04/2011 4:24:46 PM | Computer Name = Hoth | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:11:21 AM on ?6/?04/?2011 was unexpected.
Error - 5/04/2011 4:24:47 PM | Computer Name = HOTH | Source = BugCheck | ID = 1001
Description =
Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Media Player Network Sharing Service service to connect.
Error - 5/04/2011 4:26:05 PM | Computer Name = Hoth | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
Error - 6/04/2011 1:53:28 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
Error - 6/04/2011 2:07:17 AM | Computer Name = Hoth | Source = NetBT | ID = 4319
Description = A duplicate name has been detected on the TCP network. The IP address
of the computer that sent the message is in the data. Use nbtstat -n in a command
window to see which name is in the Conflict state.
< End of report >
I hope someone can help. It is driving me crazy.
thanks
Joe.