This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot connect to Microsoft or Anti-Virus sites.

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Alright, I got a Windows XP and I've been having this problem for a long while.
I hope I posted everything you need but if there is anything else then just ask and I will answer it.

I used OTL and got these:

OTL.txt

OTL logfile created on: 29/04/2011 11:44:50 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\doug\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 85.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): Reg Error: Value error.

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 15.19 Gb Free Space | 20.39% Space Free | Partition Type: NTFS
Drive D: | 931.50 Gb Total Space | 869.14 Gb Free Space | 93.31% Space Free | Partition Type: NTFS
Drive H: | 0.00 Mb Total Space | 0.00 Mb Free Space | NAN% Space Free | Partition Type: CDFS

Computer Name: DOUG-59FE20CAF4 | User Name: doug | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\doug\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Labtec Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\doug\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)


========== Driver Services (SafeList) ==========

DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (AtiHDAudioService) – C:\WINDOWS\system32\drivers\AtihdXP3.sys (ATI Technologies, Inc.)
DRV - (SaiNtBus) – C:\WINDOWS\system32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\WINDOWS\system32\drivers\SaiMini.sys (Saitek)
DRV - (SaiK0CCB) – C:\WINDOWS\system32\drivers\SaiK0CCB.sys (Saitek)
DRV - (SaiU0CCB) – C:\WINDOWS\system32\drivers\SaiU0CCB.sys (Saitek)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (FLASHSYS) – C:\Program Files\MSI\Live Update 4\LU4\FlashSys.sys ()
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AmdLLD) – C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (FileDisk) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (PID_0928) Labtec WebCam(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Labtec Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/04 20:46:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/09 20:22:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 12\components [2011/04/16 21:19:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugins [2011/04/22 22:19:08 | 000,000,000 | —D | M]

[2011/04/22 22:42:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\doug\Application Data\Mozilla\Extensions
[2011/04/26 17:00:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\extensions
[2011/04/02 23:19:54 | 000,000,000 | —D | M] (Battlefield Heroes Updater) – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\extensions\[removed]
[2011/04/26 16:57:10 | 000,001,732 | —- | M] () – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\searchplugins\zip2-search.xml
[2011/03/03 23:17:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\DOUG\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OVMGJUKP.DEFAULT\EXTENSIONS\[removed]
[2011/03/28 16:36:10 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/28 16:36:26 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 12\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/03 23:53:33 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

O1 HOSTS File: ([2004/08/04 09:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Labtec Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Labtec Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Labtec Inc.)
O4 - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/03/01 09:41:24 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{e29e34c0-43dc-11e0-8f78-806d6172696f}\Shell\Open\command - "" = C:\Program Files\VideoLAN\VLC\vlc.exe – [2011/03/22 21:59:08 | 000,107,520 | —- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: kurlbf - C:\WINDOWS\system32\rfxtor.dll ()

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Labtec Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XFR1 - C:\WINDOWS\System32\xfcodec.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/04/25 22:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/04/25 22:40:39 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/04/24 15:00:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ace of Spades
[2011/04/24 14:55:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ubisoft
[2011/04/22 22:17:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xvid
[2011/04/22 22:17:30 | 000,000,000 | —D | C] – C:\Program Files\Xvid
[2011/04/14 18:54:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DirectX
[2011/04/12 17:00:08 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\AeriaGames
[2011/04/10 16:49:49 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\id Software
[2011/04/10 16:49:11 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Local Settings\Application Data\id Software
[2011/04/10 16:46:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\id Software
[2011/04/10 16:30:50 | 000,000,000 | -HSD | C] – C:\WINDOWS\ftpcache
[2011/04/10 15:44:33 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Start Menu\Programs\AeriaGames
[2011/04/07 19:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Start Menu\Programs\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
[2011/04/06 16:27:07 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Local Settings\Application Data\Identities
[2011/04/06 16:03:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI
[2011/04/05 22:10:27 | 000,000,000 | —D | C] – C:\Program Files\AMD APP
[2011/04/05 22:10:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Catalyst Control Center
[2011/04/05 22:08:14 | 001,112,576 | —- | C] (Advanced Micro Devices, Inc. ) – C:\WINDOWS\System32\ativvamv.dll
[2011/04/05 22:06:45 | 000,000,000 | —D | C] – C:\ATI
[2011/04/03 01:41:44 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\Battlefield Heroes
[2011/04/03 01:24:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EA Games
[2011/04/02 20:07:54 | 000,026,176 | -H– | C] (LogMeIn, Inc.) – C:\WINDOWS\System32\hamachi.sys
[2011/04/01 17:00:15 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Application Data\.minecraft
[2011/03/31 19:22:12 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2011/03/31 19:21:21 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/04/29 23:33:58 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/29 18:56:51 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/28 19:43:55 | 000,140,360 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/04/28 19:43:47 | 000,281,208 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2011/04/28 19:38:14 | 000,266,400 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.ex0
[2011/04/24 15:00:59 | 000,000,146 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Ace of Spades.url
[2011/04/24 14:57:52 | 000,000,782 | —- | M] () – C:\Documents and Settings\doug\Desktop\Shortcut to online.lnk
[2011/04/24 14:55:31 | 000,000,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Brothers in Arms - Hell's Highway.lnk
[2011/04/23 18:52:51 | 000,003,584 | —- | M] () – C:\Documents and Settings\doug\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/20 23:47:26 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2011/04/12 16:21:07 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/04/12 14:13:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/10 16:46:50 | 000,022,328 | —- | M] () – C:\Documents and Settings\doug\Application Data\PnkBstrK.sys
[2011/04/10 16:46:24 | 000,000,273 | —- | M] () – C:\WINDOWS\game.ini
[2011/04/08 22:00:53 | 000,280,914 | —- | M] () – C:\Documents and Settings\doug\My Documents\2011-04-08_21.57.55.png
[2011/04/08 08:28:58 | 000,041,872 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2011/04/07 19:23:17 | 000,000,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\StarCraft II.lnk
[2011/04/07 18:20:34 | 000,210,071 | —- | M] () – C:\Documents and Settings\doug\My Documents\ts3_clientui-win32-12815-2011-04-07 18_20_33.750000.dmp
[2011/04/02 21:52:06 | 001,925,773 | —- | M] () – C:\Documents and Settings\doug\My Documents\bfbc2-20110402-210539.png
[2011/04/01 19:31:56 | 001,532,471 | —- | M] () – C:\Documents and Settings\doug\My Documents\Viper Taxi carp**.mp3
[2011/03/31 19:48:02 | 000,670,783 | —- | M] () – C:\Documents and Settings\doug\Application Data\patch14to13.dat
[2011/03/31 19:47:39 | 000,034,051 | —- | M] () – C:\Documents and Settings\doug\Application Data\downgradetool.zip
[2011/03/31 16:25:02 | 000,852,761 | —- | M] () – C:\Documents and Settings\doug\My Documents\IMG_31032011_172235.png
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/24 14:58:04 | 000,000,782 | —- | C] () – C:\Documents and Settings\doug\Desktop\Shortcut to online.lnk
[2011/04/24 14:55:31 | 000,000,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Brothers in Arms - Hell's Highway.lnk
[2011/04/23 18:52:51 | 000,003,584 | —- | C] () – C:\Documents and Settings\doug\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/22 22:17:31 | 000,650,752 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/04/22 22:17:31 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/04/22 22:17:31 | 000,143,872 | —- | C] () – C:\WINDOWS\System32\xvid.ax
[2011/04/20 23:47:26 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\crash
[2011/04/14 17:21:51 | 000,000,146 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Ace of Spades.url
[2011/04/10 16:46:23 | 000,000,273 | —- | C] () – C:\WINDOWS\game.ini
[2011/04/10 15:15:07 | 795,911,552 | —- | C] () – C:\Documents and Settings\doug\My Documents\grandfantasia_install_20101210.exe
[2011/04/08 22:00:10 | 000,280,914 | —- | C] () – C:\Documents and Settings\doug\My Documents\2011-04-08_21.57.55.png
[2011/04/08 08:28:58 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2011/04/07 18:22:28 | 000,000,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\StarCraft II.lnk
[2011/04/07 18:20:33 | 000,210,071 | —- | C] () – C:\Documents and Settings\doug\My Documents\ts3_clientui-win32-12815-2011-04-07 18_20_33.750000.dmp
[2011/04/05 16:26:55 | 001,925,773 | —- | C] () – C:\Documents and Settings\doug\My Documents\bfbc2-20110402-210539.png
[2011/04/01 19:30:45 | 001,532,471 | —- | C] () – C:\Documents and Settings\doug\My Documents\Viper Taxi carp**.mp3
[2011/03/31 19:48:00 | 000,670,783 | —- | C] () – C:\Documents and Settings\doug\Application Data\patch14to13.dat
[2011/03/31 19:47:38 | 000,034,051 | —- | C] () – C:\Documents and Settings\doug\Application Data\downgradetool.zip
[2011/03/31 16:23:22 | 000,852,761 | —- | C] () – C:\Documents and Settings\doug\My Documents\IMG_31032011_172235.png
[2011/03/21 19:56:22 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\OVDecode.dll
[2011/03/16 22:31:07 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/03/16 14:23:41 | 000,495,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/10 17:02:36 | 000,081,936 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/03/08 20:12:15 | 000,022,328 | —- | C] () – C:\Documents and Settings\doug\Application Data\PnkBstrK.sys
[2011/03/08 19:25:42 | 000,140,360 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/03/08 18:31:40 | 000,281,208 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/03/08 18:31:39 | 002,601,752 | R— | C] () – C:\WINDOWS\System32\pbsvc_moh.exe
[2011/03/08 18:31:39 | 000,075,136 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/03/03 23:42:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/03/03 17:23:42 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/03/02 22:13:08 | 000,009,255 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2011/03/02 22:08:47 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\InstMed.exe
[2011/03/01 15:45:39 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2011/03/01 10:27:51 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2011/03/01 10:27:32 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2011/03/01 10:27:32 | 000,227,586 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2011/03/01 10:27:32 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2011/03/01 09:57:00 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/03/01 09:43:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/03/01 09:38:54 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/03/01 05:31:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/03/01 05:30:01 | 000,099,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 09:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 09:00:00 | 000,432,492 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 09:00:00 | 000,162,155 | RHS- | C] () – C:\WINDOWS\System32\rfxtor.dll
[2004/08/04 09:00:00 | 000,067,448 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 09:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 09:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 09:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2011/03/01 14:44:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2011/03/09 19:39:44 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\DSS
[2011/03/16 00:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/03/04 17:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2011/03/14 17:28:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/28 17:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/03/26 22:42:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2011/03/26 19:57:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/03/15 16:10:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Saitek
[2011/03/04 20:46:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/22 16:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\.minecraft
[2011/03/01 14:45:03 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Avanquest
[2011/03/11 21:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Command & Conquer 3 Kane's Wrath
[2011/03/10 14:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\iolo
[2011/03/16 13:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Need for Speed World
[2011/03/11 15:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Petroglyph
[2011/03/21 19:32:15 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\The Creative Assembly
[2011/03/26 23:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\TS3Client
[2011/04/29 18:54:07 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\uTorrent
[2011/03/02 21:50:40 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\wargaming.net
[2011/03/12 01:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\XRay Engine

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/03/01 09:41:24 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/03/01 16:20:37 | 000,000,332 | RHS- | M] () – C:\boot.ini
[2011/03/01 09:41:24 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/03/01 09:41:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/03/02 22:06:53 | 000,000,090 | —- | M] () – C:\LogiSetup.log
[2011/03/10 15:11:46 | 000,007,330 | —- | M] () – C:\LU4.log
[2011/03/01 09:41:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 09:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2011/03/01 13:14:23 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/04/29 18:56:47 | 3488,718,848 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/03/01 09:41:02 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 09:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 07:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/03/01 05:29:30 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2011/03/01 05:29:30 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2011/03/01 05:29:30 | 000,917,504 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/03/01 13:18:32 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/01 09:45:31 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\doug\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/03/01 09:45:30 | 000,000,079 | —- | M] () – C:\Documents and Settings\doug\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-04 02:58:39

< End of report >


Extras.txt

OTL Extras logfile created on: 29/04/2011 11:44:50 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\doug\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 85.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 94.00% Paging File free
Paging file location(s): Reg Error: Value error.

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 15.19 Gb Free Space | 20.39% Space Free | Partition Type: NTFS
Drive D: | 931.50 Gb Total Space | 869.14 Gb Free Space | 93.31% Space Free | Partition Type: NTFS
Drive H: | 0.00 Mb Total Space | 0.00 Mb Free Space | NAN% Space Free | Partition Type: CDFS

Computer Name: DOUG-59FE20CAF4 | User Name: doug | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 4.0 Beta 12\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"58107:TCP" = 58107:TCP:*:Enabled:Pando Media Booster
"58107:UDP" = 58107:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"1261:TCP" = 1261:TCP:*:Enabled:vcnth
"58107:TCP" = 58107:TCP:*:Enabled:Pando Media Booster
"58107:UDP" = 58107:UDP:*:Enabled:Pando Media Booster
"1057:TCP" = 1057:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"D:\Games\Combat Arms\CombatArms.exe" = D:\Games\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"D:\Games\Combat Arms\Engine.exe" = D:\Games\Combat Arms\Engine.exe:*Enabled:Engine.exe – (Nexon)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"D:\Games\World_of_Tanks_closed_Beta\WorldOfTanks.exe" = D:\Games\World_of_Tanks_closed_Beta\WorldOfTanks.exe:*:Enabled:World of Tanks – (Wargaming.net)
"D:\Games\Medal Of Honor\MP\MoHMPGame.exe" = D:\Games\Medal Of Honor\MP\MoHMPGame.exe:*:Enabled:Medal of Honor: Multiplayer – (EA Digital Illusions CE AB)
"D:\Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe" = D:\Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (CLI) – (GSC Game World)
"D:\Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe" = D:\Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (SRV) – (GSC Game World)
"D:\Games\Star Wars\GameData\sweaw.exe" = D:\Games\Star Wars\GameData\sweaw.exe:*:Enabled:Star Wars™: Empire at War™ – (Lucasfilm Entertainment Company, Ltd.)
"D:\Games\Star Wars FOC\swfoc.exe" = D:\Games\Star Wars FOC\swfoc.exe:*:Enabled:Star Wars®: Empire at War™: Forces of Corruption™ – (Lucasfilm Entertainment Company, Ltd.)
"C:\Program Files\Electronic Arts\Command & Conquer 3 Kane's Wrath\RetailExe\1.0\cnc3ep1.dat" = C:\Program Files\Electronic Arts\Command & Conquer 3 Kane's Wrath\RetailExe\1.0\cnc3ep1.dat:*:Enabled:Command & Conquer™ 3: Kane's Wrath – (Electronic Arts Inc.)
"C:\Program Files\Electronic Arts\Medal of Honor\Binaries\moh.exe" = C:\Program Files\Electronic Arts\Medal of Honor\Binaries\moh.exe:*:Enabled:Medal of Honor™
"C:\Program Files\Electronic Arts\Medal of Honor\MP\mohmpgame.exe" = C:\Program Files\Electronic Arts\Medal of Honor\MP\mohmpgame.exe:*:Enabled:Medal of Honor: Multiplayer
"D:\Games\World_of_Tanks_closed_Beta\WOTLauncher.exe" = D:\Games\World_of_Tanks_closed_Beta\WOTLauncher.exe:*:Enabled:World of Tanks Launcher – (Wargaming.net)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"D:\Games\Bad Company 2\BFBC2Updater.exe" = D:\Games\Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2 – (EA Digital Illusions CE AB)
"D:\Games\Bad Company 2\BFBC2Game.exe" = D:\Games\Bad Company 2\BFBC2Game.exe:*:Enabled:Battlefield: Bad Company™ 2 – (EA Digital Illusions CE AB)
"C:\Program Files\Steam\steamapps\common\napoleon total war\Napoleon.exe" = C:\Program Files\Steam\steamapps\common\napoleon total war\Napoleon.exe:*:Enabled:Napoleon: Total War – (The Creative Assembly Ltd)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player – (Veoh Networks)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"D:\Games\Combat Arms\CombatArms.exe" = D:\Games\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe – (Nexon)
"D:\Games\Combat Arms\NMService.exe" = D:\Games\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – (Nexon Corp.)
"D:\Games\Combat Arms\Engine.exe" = D:\Games\Combat Arms\Engine.exe:*:Enabled:Combat Arms – (Nexon)
"C:\Documents and Settings\doug\My Documents\Downloads\Minecraft.exe" = C:\Documents and Settings\doug\My Documents\Downloads\Minecraft.exe:*:Enabled:Minecraft – ()
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"D:\Games\StarCraft II\StarCraft II.exe" = D:\Games\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher – (Blizzard Entertainment)
"D:\Games\StarCraft II\Versions\Base18092\SC2.exe" = D:\Games\StarCraft II\Versions\Base18092\SC2.exe:*:Enabled:StarCraft II – (Blizzard Entertainment, Inc.)
"D:\Games\ET QW\etqw.exe" = D:\Games\ET QW\etqw.exe:*:Enabled:Enemy Territory - QUAKE Wars™ – (Splash Damage, Ltd.)
"D:\Games\ET QW\etqwded.exe" = D:\Games\ET QW\etqwded.exe:*:Enabled:etqwded.exe – (Splash Damage, Ltd.)
"D:\Games\Ace Of Spades\server.exe" = D:\Games\Ace Of Spades\server.exe:*:Enabled:server – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0CB3C2C3-B85A-54BD-7505-E23F9B4990DA}" = Catalyst Control Center Graphics Previews Common
"{0D62121B-0361-47CD-8712-5B2F5D8D1C9C}" = Smart Technology Programming Software [removed]
"{11E94FDB-C895-45F1-B756-1C9B8C36C8F1}" = Microsoft IntelliType Pro 7.1
"{174EFB0F-7B99-BBAA-A088-BC4299C27F29}" = ccc-utility
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1B343C8C-F170-4829-8481-E163317C5830}" = iTunes
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1" = World of Tanks Closed Beta v.0.6.2.7
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{406FB8A4-F539-48A9-809C-F94706F9C9F6}_is1" = S.T.A.L.K.E.R. - Call of Pripyat [v1.6.02]
"{415030B8-3E8B-462A-8C03-41D95AA3AB3B}" = Medal of Honor ™
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{636E72A3-14A0-2E69-83A7-7E7355D8DEB4}" = Catalyst Control Center
"{6592FDEC-2C1A-413A-9985-25FEC2F0848D}" = Star Wars Empire at War Forces of Corruption
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{814190C4-C3CD-D4B5-5BAF-269594A040C8}" = ATI AVIVO Codecs
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8AC75150-2CC4-4C37-A795-A4F1A3EA188F}" = Ace of Spades
"{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}" = Battlefield Heroes
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99AE7207-8612-4DBA-A8F8-BAE5C633390D}" = Star Wars Empire at War
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB2}" = Paint.NET v3.5.8
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A29549FD-65F3-440C-A552-6B8114CF319D}" = Skype Toolbars
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A808BAF0-FC27-A3FB-82AB-A34155EF4E1E}" = ATI Catalyst Install Manager
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - QUAKE Wars™
"{BA3A1639-A2BA-4DEE-C492-1DA0835D5CC1}" = Catalyst Control Center InstallProxy
"{BBD3F66B-1180-4785-B679-3F91572CD3B4}_is1" = iolo technologies' System Mechanic Professional
"{BF45F502-D3F2-4E7C-91D8-9AA5A8141D08}" = Labtec WebCam Software
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CC2422C9-F7B5-4175-B295-5EC2283AA674}" = Command & Conquer™ 3: Kane's Wrath
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6D425D2-803F-40E8-9D65-3DC00D577C11}" = NavyFIELD NorthAmerica
"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2
"{DDEDAF6C-488E-4CDA-8276-1CCF5F3C5C32}" = Command & Conquer 3
"{E239F8B2-AE00-467D-9F05-47C8E1FAAFA7}" = WD Align - Powered by Acronis
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF085502-798E-A616-24A3-776CF6DEFB0F}" = CCC Help English
"{FF3D660E-E5CC-47FD-8050-1B4DE3BA81A9}" = Dual-Core Optimizer
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface
"Brothers in Arms - Hell's Highway" = Brothers in Arms: Hell's Highway
"Combat Arms" = Combat Arms
"Dynasty Warriors Online" = Dynasty Warriors Online
"Grand Fantasia" = Grand Fantasia
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{B7A585C8-CE4E-4150-84C6-A13C3CB1379F}" = Enemy Territory - QUAKE Wars™
"Liveupdate4_is1" = Liveupdate4
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.14)" = Mozilla Firefox (3.6.14)
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PunkBusterSvc" = PunkBuster Services
"QcDrv" = Labtec® Camera Driver
"StarCraft II" = StarCraft II
"Steam App 34030" = Napoleon: Total War
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"uTorrent" = µTorrent
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.8
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"Xfire" = Xfire (remove only)
"Xvid Video Codec 1.3.1" = Xvid Video Codec

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 08/04/2011 3:36:51 PM | Computer Name = DOUG-59FE20CAF4 | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(BZDN2072447833-QkxaMDAwMjlEP3UwMkI1e0U4a29dRkJCODlFW0E5._bzdn._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 08/04/2011 3:47:53 PM | Computer Name = DOUG-59FE20CAF4 | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(BZDN1437337489-QkxaMDAwMjlEP3UwMkI1e0U4a29dRkJCODlFW0E5._bzdn._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 13/04/2011 3:12:56 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application dwonline.bin, version 2.0.0.0, faulting module
dwonline.bin, version 2.0.0.0, fault address 0x0046d61e.

Error - 13/04/2011 3:13:29 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application dwonline.bin, version 2.0.0.0, faulting module
dwonline.bin, version 2.0.0.0, fault address 0x0046d61e.

Error - 13/04/2011 6:34:01 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application client.exe, version 0.0.0.0, faulting module
client.exe, version 0.0.0.0, fault address 0x0002a960.

Error - 19/04/2011 3:31:20 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.1.0.112, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 19/04/2011 3:31:24 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.1.0.112, faulting module
skype.exe, version 5.1.0.112, fault address 0x00a224dc.

Error - 19/04/2011 10:19:12 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.1.0.112, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 19/04/2011 10:19:17 PM | Computer Name = DOUG-59FE20CAF4 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 5.1.0.112, faulting module
skype.exe, version 5.1.0.112, fault address 0x00a224dc.

Error - 24/04/2011 1:46:04 PM | Computer Name = DOUG-59FE20CAF4 | Source = MsiInstaller | ID = 1013
Description = Product: NVIDIA PhysX v8.04.25 – Installation terminated

[ System Events ]
Error - 29/04/2011 5:58:06 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7023
Description = The Microsoft Center service terminated with the following error:
%%1114

Error - 29/04/2011 5:59:31 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7034
Description = The iolo FileInfoList Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 29/04/2011 5:59:31 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7034
Description = The iolo System Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 29/04/2011 5:59:33 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.

Error - 29/04/2011 5:59:47 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 29/04/2011 5:59:51 PM | Computer Name = DOUG-59FE20CAF4 | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).


< End of report >
Hi there what error do you get when you try to update ?

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    NetSvcs: kurlbf - C:\WINDOWS\system32\rfxtor.dll ()

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan


[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
OTL.txt

OTL logfile created on: 30/04/2011 7:41:55 PM - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\doug\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
6.00 Gb Paging File | 6.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): Reg Error: Value error.

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 18.05 Gb Free Space | 24.22% Space Free | Partition Type: NTFS
Drive D: | 931.50 Gb Total Space | 869.15 Gb Free Space | 93.31% Space Free | Partition Type: NTFS
Drive H: | 5.40 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DOUG-59FE20CAF4 | User Name: doug | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\doug\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox 4.0 Beta 12\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
PRC - C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\Video\LogiTray.exe (Labtec Inc.)
PRC - C:\Program Files\Logitech\Video\FxSvr2.exe (Labtec Inc.)
PRC - C:\WINDOWS\system32\LVCOMSX.EXE (Labtec Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\doug\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_a35e6b9.dll ()
SRV - (ioloSystemService) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)
SRV - (ioloFileInfoList) – C:\Program Files\iolo\Common\Lib\ioloServiceManager.exe (iolo technologies, LLC)


========== Driver Services (SafeList) ==========

DRV - (PnkBstrK) – C:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (AtiHDAudioService) – C:\WINDOWS\system32\drivers\AtihdXP3.sys (ATI Technologies, Inc.)
DRV - (SaiNtBus) – C:\WINDOWS\system32\drivers\SaiBus.sys (Saitek)
DRV - (SaiMini) – C:\WINDOWS\system32\drivers\SaiMini.sys (Saitek)
DRV - (SaiK0CCB) – C:\WINDOWS\system32\drivers\SaiK0CCB.sys (Saitek)
DRV - (SaiU0CCB) – C:\WINDOWS\system32\drivers\SaiU0CCB.sys (Saitek)
DRV - (Tcpip6) – C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (FLASHSYS) – C:\Program Files\MSI\Live Update 4\LU4\FlashSys.sys ()
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (AmdLLD) – C:\WINDOWS\system32\drivers\AmdLLD.sys (AMD, Inc.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (FileDisk) – C:\WINDOWS\System32\drivers\filedisk.sys (iolo technologies, LLC (based on original work by Bo Brantén))
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (PID_0928) Labtec WebCam(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Labtec Inc.)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Labtec Inc.)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/04 20:46:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/09 20:22:07 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 12\components [2011/04/16 21:19:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugins [2011/04/22 22:19:08 | 000,000,000 | —D | M]

[2011/04/22 22:42:37 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\doug\Application Data\Mozilla\Extensions
[2011/04/26 17:00:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\extensions
[2011/04/02 23:19:54 | 000,000,000 | —D | M] (Battlefield Heroes Updater) – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\extensions\[removed]
[2011/04/26 16:57:10 | 000,001,732 | —- | M] () – C:\Documents and Settings\doug\Application Data\Mozilla\Firefox\Profiles\ovmgjukp.default\searchplugins\zip2-search.xml
[2011/03/03 23:17:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
() (No name found) – C:\DOCUMENTS AND SETTINGS\DOUG\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OVMGJUKP.DEFAULT\EXTENSIONS\[removed]
[2011/03/28 16:36:10 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/28 16:36:26 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\MOZILLA FIREFOX 4.0 BETA 12\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/03/03 23:53:33 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION

O1 HOSTS File: ([2011/04/30 19:36:40 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe (Labtec Inc.)
O4 - HKLM..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe (Labtec Inc.)
O4 - HKLM..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE (Labtec Inc.)
O4 - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/03/01 09:41:24 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/02/09 22:55:59 | 000,423,304 | R— | M] (Electronic Arts) - H:\AutoRun.exe – [ CDFS ]
O32 - AutoRun File - [2010/02/10 03:21:09 | 000,000,000 | R–D | M] - H:\Autorun – [ CDFS ]
O32 - AutoRun File - [2010/01/31 05:21:13 | 000,367,686 | R— | M] () - H:\Autorun.ico – [ CDFS ]
O32 - AutoRun File - [2010/02/09 23:55:03 | 009,965,568 | R— | M] () - H:\autorun.dat – [ CDFS ]
O32 - AutoRun File - [2010/02/09 23:54:55 | 000,000,155 | R— | M] () - H:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/30 19:36:38 | 000,000,000 | —D | C] – C:\_OTL
[2011/04/25 22:40:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/04/25 22:40:39 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/04/24 15:00:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ace of Spades
[2011/04/24 14:55:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ubisoft
[2011/04/22 22:17:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Xvid
[2011/04/22 22:17:30 | 000,000,000 | —D | C] – C:\Program Files\Xvid
[2011/04/14 18:54:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DirectX
[2011/04/12 17:00:08 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\AeriaGames
[2011/04/10 16:49:49 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\id Software
[2011/04/10 16:49:11 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Local Settings\Application Data\id Software
[2011/04/10 16:46:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\id Software
[2011/04/10 16:30:50 | 000,000,000 | -HSD | C] – C:\WINDOWS\ftpcache
[2011/04/10 15:44:33 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Start Menu\Programs\AeriaGames
[2011/04/07 19:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Start Menu\Programs\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\StarCraft II
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/04/07 18:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Blizzard Entertainment
[2011/04/06 16:27:07 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Local Settings\Application Data\Identities
[2011/04/06 16:03:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ATI
[2011/04/05 22:10:27 | 000,000,000 | —D | C] – C:\Program Files\AMD APP
[2011/04/05 22:10:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Catalyst Control Center
[2011/04/05 22:06:45 | 000,000,000 | —D | C] – C:\ATI
[2011/04/03 01:41:44 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\My Documents\Battlefield Heroes
[2011/04/03 01:24:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EA Games
[2011/04/02 20:07:54 | 000,026,176 | -H– | C] (LogMeIn, Inc.) – C:\WINDOWS\System32\hamachi.sys
[2011/04/01 17:00:15 | 000,000,000 | —D | C] – C:\Documents and Settings\doug\Application Data\.minecraft

========== Files - Modified Within 30 Days ==========

[2011/04/30 19:39:45 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/30 19:39:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/30 19:36:40 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\etc\Hosts
[2011/04/30 17:30:19 | 000,140,360 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/04/30 17:30:15 | 000,281,208 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.xtr
[2011/04/28 19:43:47 | 000,281,208 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.ex0
[2011/04/24 15:00:59 | 000,000,146 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play Ace of Spades.url
[2011/04/24 14:57:52 | 000,000,782 | —- | M] () – C:\Documents and Settings\doug\Desktop\Shortcut to online.lnk
[2011/04/24 14:55:31 | 000,000,717 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Brothers in Arms - Hell's Highway.lnk
[2011/04/23 18:52:51 | 000,003,584 | —- | M] () – C:\Documents and Settings\doug\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/20 23:47:26 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2011/04/12 16:21:07 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2011/04/12 14:13:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/10 16:46:50 | 000,022,328 | —- | M] () – C:\Documents and Settings\doug\Application Data\PnkBstrK.sys
[2011/04/10 16:46:24 | 000,000,273 | —- | M] () – C:\WINDOWS\game.ini
[2011/04/08 22:00:53 | 000,280,914 | —- | M] () – C:\Documents and Settings\doug\My Documents\2011-04-08_21.57.55.png
[2011/04/08 08:28:58 | 000,041,872 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2011/04/07 19:23:17 | 000,000,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\StarCraft II.lnk
[2011/04/07 18:20:34 | 000,210,071 | —- | M] () – C:\Documents and Settings\doug\My Documents\ts3_clientui-win32-12815-2011-04-07 18_20_33.750000.dmp
[2011/04/02 21:52:06 | 001,925,773 | —- | M] () – C:\Documents and Settings\doug\My Documents\bfbc2-20110402-210539.png
[2011/04/01 19:31:56 | 001,532,471 | —- | M] () – C:\Documents and Settings\doug\My Documents\Viper Taxi carp**.mp3
[2011/03/31 19:48:02 | 000,670,783 | —- | M] () – C:\Documents and Settings\doug\Application Data\patch14to13.dat
[2011/03/31 19:47:39 | 000,034,051 | —- | M] () – C:\Documents and Settings\doug\Application Data\downgradetool.zip

========== Files Created - No Company Name ==========

[2011/04/24 14:58:04 | 000,000,782 | —- | C] () – C:\Documents and Settings\doug\Desktop\Shortcut to online.lnk
[2011/04/24 14:55:31 | 000,000,717 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Brothers in Arms - Hell's Highway.lnk
[2011/04/23 18:52:51 | 000,003,584 | —- | C] () – C:\Documents and Settings\doug\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/22 22:17:31 | 000,650,752 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/04/22 22:17:31 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/04/22 22:17:31 | 000,143,872 | —- | C] () – C:\WINDOWS\System32\xvid.ax
[2011/04/20 23:47:26 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\crash
[2011/04/14 17:21:51 | 000,000,146 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play Ace of Spades.url
[2011/04/10 16:46:23 | 000,000,273 | —- | C] () – C:\WINDOWS\game.ini
[2011/04/10 15:15:07 | 795,911,552 | —- | C] () – C:\Documents and Settings\doug\My Documents\grandfantasia_install_20101210.exe
[2011/04/08 22:00:10 | 000,280,914 | —- | C] () – C:\Documents and Settings\doug\My Documents\2011-04-08_21.57.55.png
[2011/04/08 08:28:58 | 000,041,872 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2011/04/07 18:22:28 | 000,000,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\StarCraft II.lnk
[2011/04/07 18:20:33 | 000,210,071 | —- | C] () – C:\Documents and Settings\doug\My Documents\ts3_clientui-win32-12815-2011-04-07 18_20_33.750000.dmp
[2011/04/05 16:26:55 | 001,925,773 | —- | C] () – C:\Documents and Settings\doug\My Documents\bfbc2-20110402-210539.png
[2011/04/01 19:30:45 | 001,532,471 | —- | C] () – C:\Documents and Settings\doug\My Documents\Viper Taxi carp**.mp3
[2011/03/31 19:48:00 | 000,670,783 | —- | C] () – C:\Documents and Settings\doug\Application Data\patch14to13.dat
[2011/03/31 19:47:38 | 000,034,051 | —- | C] () – C:\Documents and Settings\doug\Application Data\downgradetool.zip
[2011/03/21 19:56:22 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\OVDecode.dll
[2011/03/16 22:31:07 | 002,434,856 | —- | C] () – C:\WINDOWS\System32\pbsvc_bc2.exe
[2011/03/16 14:23:41 | 000,495,536 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/03/10 17:02:36 | 000,081,936 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2011/03/08 20:12:15 | 000,022,328 | —- | C] () – C:\Documents and Settings\doug\Application Data\PnkBstrK.sys
[2011/03/08 19:25:42 | 000,140,360 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/03/08 18:31:40 | 000,281,208 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/03/08 18:31:39 | 002,601,752 | R— | C] () – C:\WINDOWS\System32\pbsvc_moh.exe
[2011/03/08 18:31:39 | 000,075,136 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/03/03 23:42:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/03/03 17:23:42 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/03/02 22:13:08 | 000,009,255 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2011/03/02 22:08:47 | 000,053,248 | R— | C] () – C:\WINDOWS\System32\InstMed.exe
[2011/03/01 15:45:39 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2011/03/01 10:27:51 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2011/03/01 10:27:32 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2011/03/01 10:27:32 | 000,227,586 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2011/03/01 10:27:32 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2011/03/01 09:57:00 | 000,049,152 | R— | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/03/01 09:43:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/03/01 09:38:54 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/03/01 05:31:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/03/01 05:30:01 | 000,099,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2004/08/04 09:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 09:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 09:00:00 | 000,432,492 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 09:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 09:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 09:00:00 | 000,067,448 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 09:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 09:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 09:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 09:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 09:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 09:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2011/03/01 14:44:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2011/03/09 19:39:44 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\DSS
[2011/03/16 00:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/03/04 17:07:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2011/03/14 17:28:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/03/28 17:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/03/26 22:42:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2011/03/26 19:57:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/03/15 16:10:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Saitek
[2011/03/04 20:46:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/22 16:56:11 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\.minecraft
[2011/03/01 14:45:03 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Avanquest
[2011/03/11 21:33:19 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Command & Conquer 3 Kane's Wrath
[2011/03/10 14:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\iolo
[2011/03/16 13:53:44 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Need for Speed World
[2011/03/11 15:48:06 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\Petroglyph
[2011/03/21 19:32:15 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\The Creative Assembly
[2011/03/26 23:06:51 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\TS3Client
[2011/04/29 18:54:07 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\uTorrent
[2011/03/02 21:50:40 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\wargaming.net
[2011/03/12 01:06:39 | 000,000,000 | —D | M] – C:\Documents and Settings\doug\Application Data\XRay Engine

========== Purity Check ==========



< End of report >


aswMBR.txt

aswMBR version 0.9.5 Copyright© 2011 AVAST Software
Run date: 2011-04-30 19:44:50
—————————–
19:44:50.703 OS Version: Windows 5.1.2600 Service Pack 3
19:44:50.703 Number of processors: 4 586 0x503
19:44:50.703 ComputerName: DOUG-59FE20CAF4 UserName: doug
19:44:51.109 Initialize success
19:44:55.015 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:44:55.015 Disk 0 Vendor: WDC_WD10EARS-003BB1 80.00A80 Size: 953869MB BusType: 3
19:44:55.015 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-11
19:44:55.015 Disk 1 Vendor: ST380011A 8.01 Size: 76319MB BusType: 3
19:44:57.015 Disk 1 MBR read successfully
19:44:57.015 Disk 1 MBR scan
19:44:57.015 Disk 1 MBR hidden
19:44:59.015 Disk 1 scanning sectors +156280320
19:44:59.031 Disk 1 scanning C:\WINDOWS\system32\drivers
19:44:59.062 Service scanning
19:44:59.875 Disk 1 trace - called modules:
19:44:59.890 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys amdide.sys PCIIDEX.SYS
19:44:59.890 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x8abedab8]
19:44:59.890 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000073[0x8ac92c80]
19:44:59.890 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-11[0x8ac73d98]
19:44:59.890 Scan finished successfully
19:45:03.890 Disk 1 MBR has been saved successfully to "C:\Documents and Settings\doug\My Documents\Downloads\MBR.dat"
19:45:03.906 The log file has been saved successfully to "C:\Documents and Settings\doug\My Documents\Downloads\aswMBR.txt"


Here you go, need anything else?
I can get to the sites now adn it used to come up saying server not found. Thanks for the help and i never got a chance to get anti-virus before it stopped letting me on sites that give antivirus. Do you Know any good free anti-virus's that will hold me over till i can buy one?
There are three or four to choose from : My biased recommendation is Avast closely followed by MSE

Lets check for orphans now

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Thanks and here is the log Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6484 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 01/05/2011 12:58:20 PM mbam-log-2011-05-01 (12-58-20).txt Scan type: Quick scan Objects scanned: 151454 Time elapsed: 3 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\doug\my documents\downloads\xvidsetup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
None really, know any programs that would make a quad core run faster? And my shut down takes forever but nothing that's really that big of a deal And thanks for teh help, I'm glad that problem is finally over.
How about a little TLC :)

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check

[external image: Posted Image]


Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

[external image: Posted Image] Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update


To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI