This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot load anti virus software

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think I have a problem as I cannot load any antivirus software. I used to have AVAST but accidentally removed it then couldn't re-download even though I removed it entirely from my program files and re-booted.
I scanned using OTL and the logs are posted below. Any help you can offer would be much appreciated. Thank you.
OTL logfile created on: 14/05/2011 18:32:50 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kath\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 529.00 Mb Available Physical Memory | 52.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 58.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 0.91 Gb Free Space | 2.43% Space Free | Partition Type: NTFS
Drive D: | 31.25 Gb Total Space | 30.09 Gb Free Space | 96.29% Space Free | Partition Type: NTFS
Drive E: | 6.01 Gb Total Space | 2.86 Gb Free Space | 47.53% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: BLUEROOM | User Name: Kath | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kath\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools Security\Alert.exe (PC Tool)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\atwtusb.exe (Aiptek)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe (hp)
PRC - C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe ()
PRC - C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe (Netropa Corp.)
PRC - C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
PRC - C:\Program Files\Netropa\Onscreen Display\osd.exe (Netropa Corp.)
PRC - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe ()
PRC - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Browser Mouse\Browser Mouse\1.0\LwbWheel.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Kath\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\PC Tools Security\PCTGMhk.dll (PC Tools)
MOD - C:\WINDOWS\system32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dciman32.dll (Microsoft Corporation)
MOD - C:\Program Files\Netropa\Multimedia Keyboard\Nhkdll.dll (Netropa Corp.)
MOD - C:\WINDOWS\system32\nview.dll ()
MOD - C:\Program Files\Browser Mouse\Browser Mouse\1.0\MouseDll.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (ACDaemon) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (nhksrv) – C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe ()
SRV - (EPSONStatusAgent2) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (iadusb) – C:\WINDOWS\system32\drivers\glauiad.sys (Conexant Systems Inc.)
DRV - (WPN111) – C:\WINDOWS\system32\drivers\WPN111.sys (NETGEAR, Inc.)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (aiptektp) – C:\WINDOWS\system32\drivers\aiptektp.sys (AIPTEK International Inc.)
DRV - (pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (nvcap) nVidia WDM Video Capture (universal) – C:\WINDOWS\system32\drivers\NVCAP.SYS (NVIDIA Corporation)
DRV - (NVXBAR) – C:\WINDOWS\system32\drivers\NVXBAR.SYS (NVIDIA Corporation)
DRV - (msikbd2k) – C:\WINDOWS\system32\drivers\Msikbd2k.sys (Netropa Corporation)
DRV - (cmpci) C-Media PCI Audio Driver (WDM) – C:\WINDOWS\system32\drivers\cmaudio.sys (C-Media Inc)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ham50) – C:\WINDOWS\system32\drivers\CTXH51.sys (Intel Corporation)
DRV - (DOSMEMIO) – C:\WINDOWS\system32\MEMIO.SYS ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.stonebridgeclub.co.uk/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..network.proxy.no_proxies_on: "127.0.0.1"

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/13 14:31:47 | 000,000,000 | —D | M]

[2008/03/25 15:24:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kath\Application Data\Mozilla\Firefox\Profiles\wnefrt56.default\extensions
[2008/03/25 15:24:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kath\Application Data\Mozilla\Firefox\Profiles\wnefrt56.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/03/25 15:24:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kath\Application Data\Mozilla\Firefox\Profiles\wnefrt56.default\extensions\staged-xpis
[2008/04/08 23:19:07 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/03/25 15:16:52 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\[removed]
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\[removed]
File not found (No name found) – C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD

O1 HOSTS File: ([2001/08/18 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [atwtusb] C:\WINDOWS\System32\atwtusb.exe (Aiptek)
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [DMHotKey] File not found
O4 - HKLM..\Run: [HPpromo psc 2175] C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqWRG.exe (hp)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Security\pctsGui.exe (PC Tools)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\LwbWheel.exe ()
O4 - HKLM..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe (Netropa Corp.)
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Microsoft Works Update Detection] File not found
O4 - HKLM..\RunOnce: [DELDIR0.EXE] C:\Documents and Settings\Kath\Local Settings\Temp\DELDIR0.EXE (Network Associates Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O12 - Plugin for: .p - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab (Reg Error: Key error.)
O16 - DPF: {3B5E9B23-7537-4601-A9E8-FA0D956DEA16} http://www.couponreport.net/ftp/v3123/csauie1.cab (Reg Error: Key error.)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo…otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…ows-i586-jc.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8038.2807407407 (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} http://asp03.photoprintit.de/microsite/128…IPSUploader.cab (IPSUploader Control)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Kath\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kath\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/02/17 16:41:53 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\WINDOWS\System32\lhacm.acm (Microsoft Corporation)
Drivers32: MSACM.NSPAC - C:\WINDOWS\System32\nspac32.acm (Netscape Communications)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.SP50 - SP5X_32.DLL File not found
Drivers32: VIDC.SP51 - SP5X_32.DLL File not found
Drivers32: VIDC.SP52 - SP5X_32.DLL File not found
Drivers32: VIDC.SP53 - SP5X_32.DLL File not found
Drivers32: VIDC.SP54 - SP5X_32.DLL File not found
Drivers32: VIDC.SP55 - SP5X_32.DLL File not found
Drivers32: VIDC.SP56 - SP5X_32.DLL File not found
Drivers32: VIDC.SP57 - SP5X_32.DLL File not found
Drivers32: VIDC.SP58 - SP5X_32.DLL File not found
Drivers32: VIDC.VDOM - C:\WINDOWS\System32\vdowave.drv (VDOnet LTD..)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (60249199932866560)

========== Files/Folders - Created Within 30 Days ==========

[2011/05/14 18:29:54 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kath\Desktop\OTL.exe
[2011/05/12 13:39:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\c9325f
[2011/05/10 14:27:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/05/10 14:24:59 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/10 14:23:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/10 14:14:46 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/10 14:03:54 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2011/05/10 14:01:13 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/29 19:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Share-to-Web Upload Folder
[2011/04/20 17:11:15 | 000,656,320 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctEFA.sys
[2011/04/20 17:11:15 | 000,338,880 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/04/20 17:11:14 | 000,249,616 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctgntdi.sys
[2011/04/20 17:11:07 | 000,239,168 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTCore.sys
[2011/04/20 17:11:07 | 000,160,448 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTAppEvent.sys
[2011/04/20 17:11:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/04/20 17:10:53 | 000,070,536 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctplsg.sys
[2011/04/20 17:10:39 | 000,000,000 | —D | C] – C:\Program Files\PC Tools Security
[2011/04/20 17:10:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2011/04/20 17:10:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Kath\Application Data\PC Tools
[2011/04/20 17:10:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System\*.tmp files -> C:\WINDOWS\System\*.tmp -> ]
[1 C:\Documents and Settings\Kath\My Documents\*.tmp files -> C:\Documents and Settings\Kath\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/14 18:29:54 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kath\Desktop\OTL.exe
[2011/05/14 18:26:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/14 17:26:09 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/14 16:43:38 | 000,000,245 | —- | M] () – C:\WINDOWS\Msiosd.ini
[2011/05/14 16:41:13 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3088433937-3562983710-4194836640-1006.job
[2011/05/14 16:41:11 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3088433937-3562983710-4194836640-1008.job
[2011/05/14 16:41:11 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3088433937-3562983710-4194836640-1007.job
[2011/05/14 16:40:56 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/14 16:40:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/14 16:40:47 | 1073,270,784 | -HS- | M] () – C:\hiberfil.sys
[2011/05/12 22:08:13 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2011/05/10 14:27:29 | 000,001,546 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/10 14:04:17 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/05/10 14:04:17 | 000,001,854 | —- | M] () – C:\Documents and Settings\Kath\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/05/06 16:22:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/04/20 17:11:42 | 000,732,992 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/04/20 17:11:05 | 000,001,668 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2011/04/19 21:24:06 | 000,000,208 | —- | M] () – C:\Documents and Settings\Kath\My Documents\spider.sav
[2011/04/17 13:45:00 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3088433937-3562983710-4194836640-1008.job
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[15 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\System\*.tmp files -> C:\WINDOWS\System\*.tmp -> ]
[1 C:\Documents and Settings\Kath\My Documents\*.tmp files -> C:\Documents and Settings\Kath\My Documents\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/05/10 14:27:29 | 000,001,546 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/05/10 14:04:17 | 000,001,854 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Safari.lnk
[2011/05/10 14:04:17 | 000,001,854 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/05/10 14:04:17 | 000,001,854 | —- | C] () – C:\Documents and Settings\Kath\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/04/20 17:11:17 | 000,732,992 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/04/20 17:11:05 | 000,001,668 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2010/10/21 11:07:30 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/09 09:35:58 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2010/07/18 21:56:39 | 000,001,839 | —- | C] () – C:\WINDOWS\System32\Kath_KBD.ini
[2010/07/18 21:56:39 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\MagicKBD.INI
[2010/07/18 21:56:33 | 000,003,425 | —- | C] () – C:\WINDOWS\System32\KBDR.INI
[2010/07/18 21:56:33 | 000,002,741 | —- | C] () – C:\WINDOWS\System32\KBDD.INI
[2010/07/18 21:56:33 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDO.INI
[2010/07/18 21:56:33 | 000,002,699 | —- | C] () – C:\WINDOWS\System32\KBDC.INI
[2010/07/18 21:56:33 | 000,002,606 | —- | C] () – C:\WINDOWS\System32\KBDB.INI
[2010/07/18 21:56:33 | 000,002,236 | —- | C] () – C:\WINDOWS\System32\KBDQ.INI
[2010/07/18 21:56:33 | 000,001,956 | —- | C] () – C:\WINDOWS\System32\KBDE.INI
[2010/07/18 21:56:33 | 000,001,885 | —- | C] () – C:\WINDOWS\System32\KBDP.INI
[2010/07/18 21:56:33 | 000,001,857 | —- | C] () – C:\WINDOWS\System32\KBDUU.INI
[2010/07/18 21:56:33 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDG.INI
[2010/07/18 21:56:33 | 000,001,835 | —- | C] () – C:\WINDOWS\System32\KBDA.INI
[2010/07/18 21:56:33 | 000,001,834 | —- | C] () – C:\WINDOWS\System32\KBDU.INI
[2010/07/18 21:56:33 | 000,001,819 | —- | C] () – C:\WINDOWS\System32\KBDN.INI
[2010/07/18 21:56:33 | 000,001,699 | —- | C] () – C:\WINDOWS\System32\KBDT.INI
[2010/07/18 21:56:33 | 000,001,697 | —- | C] () – C:\WINDOWS\System32\KBDV.INI
[2010/07/18 21:56:33 | 000,001,522 | —- | C] () – C:\WINDOWS\System32\KBDS.INI
[2010/07/18 21:56:33 | 000,001,476 | —- | C] () – C:\WINDOWS\System32\KBDF.INI
[2010/07/18 21:40:03 | 000,004,300 | —- | C] () – C:\WINDOWS\System32\MEMIO.SYS
[2010/07/18 21:39:55 | 000,000,135 | R— | C] () – C:\WINDOWS\System32\lngEng.ini
[2010/07/18 21:39:55 | 000,000,117 | —- | C] () – C:\WINDOWS\System32\lngKor.ini
[2010/03/13 00:41:31 | 000,017,408 | —- | C] () – C:\Documents and Settings\Kath\Local Settings\Application Data\WebpageIcons.db
[2010/01/14 19:13:26 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/04/20 16:51:54 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/08/11 15:25:37 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2008/08/06 17:10:53 | 000,149,392 | —- | C] () – C:\WINDOWS\System32\drivers\ar5523.bin
[2008/07/04 14:16:52 | 000,000,000 | —- | C] () – C:\WINDOWS\netscape.INI
[2008/05/25 16:01:38 | 000,651,264 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2008/05/25 16:01:38 | 000,192,512 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2008/05/25 16:01:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2008/02/26 11:32:07 | 000,000,048 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/10/26 18:15:54 | 000,000,004 | —- | C] () – C:\WINDOWS\jknradee.sys
[2007/10/18 20:35:30 | 000,001,356 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/06/08 15:11:49 | 000,019,220 | —- | C] () – C:\WINDOWS\wwdslcfg.ini
[2007/02/26 16:49:12 | 006,139,774 | —- | C] () – C:\WINDOWS\imagine digital freedom.dat
[2007/02/25 17:31:14 | 000,000,064 | —- | C] () – C:\WINDOWS\winmail1.dat
[2007/02/25 17:31:14 | 000,000,028 | —- | C] () – C:\WINDOWS\winafn.dat
[2007/02/25 16:17:11 | 002,067,140 | R— | C] () – C:\WINDOWS\System32\avcodec.dll
[2007/01/26 00:51:46 | 000,007,207 | R— | C] () – C:\WINDOWS\Disktool.INI
[2007/01/26 00:51:46 | 000,006,399 | R— | C] () – C:\WINDOWS\fwupgrade.ini
[2007/01/26 00:51:46 | 000,003,677 | R— | C] () – C:\WINDOWS\SoundCon.INI
[2006/10/02 14:57:13 | 000,016,896 | —- | C] () – C:\WINDOWS\GpUnInst.exe
[2006/07/15 19:48:39 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2006/06/18 21:09:04 | 000,067,897 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/06/18 21:08:33 | 000,232,960 | —- | C] () – C:\WINDOWS\System32\cpmsjava.dll
[2006/06/18 21:08:33 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ifl_jpeg.dll
[2006/06/18 21:08:33 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\ifl.dll
[2006/06/18 21:08:33 | 000,060,928 | —- | C] () – C:\WINDOWS\System32\ifl_png.dll
[2006/06/18 21:08:33 | 000,038,400 | —- | C] () – C:\WINDOWS\System32\ifl_libz.dll
[2006/06/18 21:08:33 | 000,025,088 | —- | C] () – C:\WINDOWS\System32\ifl_gif.dll
[2006/06/18 21:08:33 | 000,023,040 | —- | C] () – C:\WINDOWS\System32\ifl_sgi.dll
[2006/06/18 21:08:32 | 000,697,344 | —- | C] () – C:\WINDOWS\System32\cp_main.dll
[2006/06/18 21:08:32 | 000,285,184 | —- | C] () – C:\WINDOWS\System32\cp_graphicslarge8.dll
[2006/06/18 21:08:32 | 000,285,184 | —- | C] () – C:\WINDOWS\System32\cp_graphicslarge16.dll
[2006/06/18 21:08:32 | 000,247,808 | —- | C] () – C:\WINDOWS\System32\cp_javascript.dll
[2006/06/18 21:08:32 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\cp_graphicsmed8.dll
[2006/06/18 21:08:32 | 000,167,936 | —- | C] () – C:\WINDOWS\System32\cp_graphicsmed16.dll
[2006/06/18 21:08:32 | 000,133,120 | —- | C] () – C:\WINDOWS\System32\cp_vrml1to2.dll
[2006/06/18 21:08:32 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\cp_basic.dll
[2006/06/18 21:08:32 | 000,057,856 | —- | C] () – C:\WINDOWS\System32\cp_graphicssmall8.dll
[2006/06/18 21:08:32 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\cp_graphicssmall16.dll
[2006/06/18 21:08:32 | 000,052,736 | —- | C] () – C:\WINDOWS\System32\cp_glrenderer.dll
[2006/06/18 21:08:32 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\cpimg10.dll
[2006/06/18 21:08:32 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\cp_tessellator.dll
[2006/06/18 21:08:32 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\cp_graphicspos.dll
[2006/06/18 21:08:32 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\cp_renderer.dll
[2006/06/18 21:04:40 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\SX83P32.DLL
[2006/06/18 21:04:33 | 000,634,057 | —- | C] () – C:\WINDOWS\cd32405.exe
[2006/06/18 20:59:07 | 000,000,078 | -H– | C] () – C:\WINDOWS\System32\014132.SYS
[2006/06/18 20:51:40 | 000,000,932 | —- | C] () – C:\WINDOWS\hmpro5.ini
[2006/06/18 20:50:47 | 000,003,321 | —- | C] () – C:\WINDOWS\sqkp40.ini
[2006/06/18 20:50:46 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\regsvrdc.exe
[2006/06/18 20:50:45 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\dtctrace.dll
[2006/06/18 20:50:43 | 000,029,008 | —- | C] () – C:\WINDOWS\System32\helphelp.dll
[2006/06/18 20:50:43 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\kwimage.dll
[2005/10/10 22:49:00 | 000,573,440 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/10/10 22:49:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/10/10 22:49:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2005/10/08 13:00:22 | 000,038,028 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2005/10/08 13:00:22 | 000,027,030 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2005/10/08 13:00:22 | 000,000,022 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2004/12/24 02:15:15 | 000,000,107 | —- | C] () – C:\WINDOWS\WEBLINK.INI
[2004/12/15 12:54:38 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/12/15 12:07:20 | 000,006,048 | —- | C] () – C:\WINDOWS\System32\mcc16.dll
[2004/12/15 11:33:39 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/11/07 16:47:11 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/09/16 14:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\ADFUUD.SYS
[2004/09/12 18:36:12 | 000,000,000 | —- | C] () – C:\WINDOWS\OpPrintServer.INI
[2004/09/12 17:38:23 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/06/27 23:01:40 | 000,000,029 | —- | C] () – C:\WINDOWS\viewer.ini
[2004/06/27 22:50:53 | 000,001,545 | —- | C] () – C:\WINDOWS\cssslang.ini
[2004/06/27 22:50:53 | 000,000,669 | —- | C] () – C:\WINDOWS\Id007.ini
[2004/06/27 22:50:53 | 000,000,062 | —- | C] () – C:\WINDOWS\csss.ini
[2004/06/27 22:49:28 | 000,000,071 | —- | C] () – C:\WINDOWS\RmFile.ini
[2004/06/27 22:49:27 | 000,000,010 | —- | C] () – C:\WINDOWS\System32\MprExe.Ini
[2004/06/27 22:49:26 | 000,000,093 | —- | C] () – C:\WINDOWS\Info.Com
[2004/06/27 22:49:16 | 000,053,728 | —- | C] () – C:\WINDOWS\rmfile.exe
[2004/06/27 22:49:16 | 000,043,664 | —- | C] () – C:\WINDOWS\addrun.exe
[2004/06/27 22:42:37 | 000,073,728 | —- | C] () – C:\WINDOWS\RmTablet.exe
[2004/06/27 22:42:37 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\tblmouse.exe
[2004/06/27 22:42:37 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\Funckey.dll
[2004/06/27 22:42:37 | 000,003,281 | —- | C] () – C:\WINDOWS\aiptbl.ini
[2004/03/26 15:55:28 | 000,021,007 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2004/03/26 15:55:28 | 000,016,622 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2004/03/24 18:28:47 | 000,104,250 | —- | C] () – C:\WINDOWS\Picasa Uninstaller.exe
[2003/12/25 12:44:35 | 000,000,182 | —- | C] () – C:\WINDOWS\TEXTWARE.INI
[2003/12/25 12:43:41 | 000,007,008 | —- | C] () – C:\WINDOWS\System32\Setupkit.dll
[2003/12/16 01:08:29 | 000,000,022 | —- | C] () – C:\WINDOWS\autorun.INI
[2003/12/03 01:17:36 | 000,000,074 | —- | C] () – C:\WINDOWS\Q-PLUS.INI
[2003/11/20 21:33:03 | 000,000,028 | —- | C] () – C:\WINDOWS\NwMillnm.INI
[2003/11/20 18:40:21 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2003/11/04 20:54:25 | 000,000,050 | —- | C] () – C:\WINDOWS\HGSPEECH.INI
[2003/11/04 20:54:12 | 000,000,092 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2003/11/04 13:05:13 | 000,086,304 | —- | C] () – C:\WINDOWS\RHVIDEO.DLL
[2003/03/09 22:31:04 | 000,561,152 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/01/18 18:27:16 | 000,000,000 | —- | C] () – C:\WINDOWS\BCD.INI
[2002/12/01 11:26:01 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\msiosd32.dll
[2002/12/01 11:26:01 | 000,000,245 | —- | C] () – C:\WINDOWS\Msiosd.ini
[2002/10/17 19:28:28 | 000,091,136 | —- | C] () – C:\WINDOWS\UnCasino5.exe
[2002/09/12 19:54:01 | 000,030,720 | —- | C] () – C:\Documents and Settings\Kath\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002/07/25 23:14:00 | 000,003,247 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2002/06/08 15:15:49 | 000,184,872 | —- | C] () – C:\WINDOWS\SETUP1.EXE
[2002/05/30 17:08:58 | 000,014,153 | —- | C] () – C:\WINDOWS\_MSRSTRT.EXE
[2002/04/26 12:08:37 | 000,000,223 | —- | C] () – C:\WINDOWS\HP PrecisionScan Pro.INI
[2002/04/25 18:42:06 | 000,002,124 | —- | C] () – C:\WINDOWS\PhotoImpression.ini
[2002/04/18 15:38:57 | 000,000,991 | —- | C] () – C:\WINDOWS\ACROREAD.INI
[2002/04/18 15:38:57 | 000,000,027 | —- | C] () – C:\WINDOWS\ACROGRAF.INI
[2002/04/18 15:37:37 | 000,000,286 | —- | C] () – C:\WINDOWS\SCANFX.INI
[2002/04/18 15:37:24 | 000,399,350 | —- | C] () – C:\WINDOWS\ACCUGLD5.DLL
[2002/04/18 15:37:24 | 000,026,233 | —- | C] () – C:\WINDOWS\ACCUIFGL.DLL
[2002/04/15 15:15:43 | 000,000,306 | —- | C] () – C:\WINDOWS\QTW.INI
[2002/04/14 17:44:23 | 000,003,773 | —- | C] () – C:\WINDOWS\Ulead32.ini
[2002/04/13 17:41:58 | 000,001,477 | —- | C] () – C:\WINDOWS\btclick.ini
[2002/03/01 01:04:04 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2002/03/01 01:04:03 | 000,352,330 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2002/03/01 01:04:02 | 000,507,976 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2002/02/18 11:38:22 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/02/17 18:58:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2002/02/17 18:35:11 | 000,000,020 | —- | C] () – C:\WINDOWS\InfModM.ini
[2002/02/17 18:33:53 | 000,000,029 | —- | C] () – C:\WINDOWS\wgedit.ini
[2002/02/17 18:04:11 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2002/02/17 17:11:22 | 000,000,025 | —- | C] () – C:\WINDOWS\mixerdef.ini
[2002/02/17 17:10:09 | 000,122,880 | —- | C] () – C:\WINDOWS\cmuninst.exe
[2002/02/17 17:10:09 | 000,122,880 | —- | C] () – C:\WINDOWS\cmuninst.dat
[2002/02/17 17:10:02 | 000,000,199 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2002/02/17 17:10:02 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2002/02/17 16:49:00 | 000,000,873 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/02/17 16:44:44 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2002/02/17 16:39:01 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2002/02/17 08:33:05 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2002/02/17 08:32:08 | 000,348,992 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2002/02/17 07:26:54 | 000,000,734 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2002/02/17 07:26:07 | 000,426,070 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2002/02/17 07:26:07 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2002/02/17 07:26:07 | 000,065,080 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2002/02/17 07:26:07 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2002/02/17 07:26:07 | 000,004,518 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2002/02/17 07:26:03 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2002/02/17 07:26:01 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/02/17 07:25:51 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2002/02/17 07:25:50 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2002/02/17 07:25:39 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2002/02/17 07:25:18 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/01/24 07:31:18 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\prntfix.exe
[2000/09/14 03:03:00 | 000,000,145 | —- | C] () – C:\WINDOWS\System32\EBPPORT.DAT
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\WINDOWS\System32\Lffpx7.dll
[1999/01/22 11:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/06/11 13:08:06 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\Lfkodak.dll

========== LOP Check ==========

[2011/03/16 11:33:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/05/12 13:39:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\c9325f
[2009/10/07 17:42:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2011/03/05 17:13:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\lAbJiBa06304
[2011/05/14 17:08:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/03/12 20:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/02 12:47:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/11/06 20:03:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/26 13:34:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2002/04/25 20:34:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\ACD Systems
[2009/10/06 18:34:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2003/08/20 15:05:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Greenpoint
[2002/02/17 18:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\InterTrust
[2008/07/03 18:18:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Leadertech
[2005/12/26 12:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Musicmatch
[2010/03/18 20:07:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\PacificPoker
[2005/10/08 23:55:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Panasonic
[2009/07/27 12:55:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Samsung
[2006/09/01 18:21:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Serif
[2011/05/06 01:06:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Kath\Application Data\Spotify
[2005/02/05 22:26:55 | 000,000,340 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2170 series#1080313789.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2002/02/17 16:41:53 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2002/02/17 17:00:01 | 000,000,193 | RHS- | M] () – C:\BOOT.BAK
[2010/08/09 10:16:00 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2001/08/18 13:00:00 | 000,237,728 | RHS- | M] () – C:\cmldr
[2002/02/17 16:41:53 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/27 12:48:43 | 000,000,000 | —- | M] () – C:\conmgr.log
[2006/07/19 15:48:50 | 000,000,024 | —- | M] () – C:\DUKE3D.BAT
[2011/03/05 17:49:57 | 001,228,854 | —- | M] () – C:\fsqwr.bmp
[2011/05/14 16:40:47 | 1073,270,784 | -HS- | M] () – C:\hiberfil.sys
[2011/05/12 22:08:13 | 000,000,488 | —- | M] () – C:\hpfr5550.xml
[2004/11/29 00:01:21 | 000,076,309 | —- | M] () – C:\hpo14C.tmp.jpg
[2004/05/08 20:35:29 | 000,000,934 | -H– | M] () – C:\hpothb07.dat
[2004/05/08 20:35:29 | 000,001,749 | -H– | M] () – C:\hpothb07.tif
[2006/07/19 16:39:51 | 000,000,066 | —- | M] () – C:\ICSYSINF.log
[2004/11/29 00:01:22 | 000,024,648 | —- | M] () – C:\IM_A0001.JPG
[2002/02/17 16:41:53 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2002/02/17 17:49:00 | 000,000,321 | -H– | M] () – C:\IPH.PH
[2010/10/05 15:42:52 | 000,000,000 | —- | M] () – C:\Log.txt
[2002/02/17 16:41:53 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/12/24 00:10:17 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/10/07 15:52:58 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/05/14 16:40:42 | 402,653,184 | -HS- | M] () – C:\pagefile.sys
[2010/07/18 21:40:07 | 000,000,173 | —- | M] () – C:\Setup.log
[2004/04/20 20:26:43 | 000,015,360 | -HS- | M] () – C:\Thumbs.db
[2003/11/13 18:52:01 | 000,000,727 | —- | M] () – C:\twacker.log
[1 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2002/02/17 16:41:17 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2000/12/22 23:58:24 | 000,009,748 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint.dll
[2000/12/22 23:58:24 | 000,009,748 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2007/02/26 16:49:10 | 001,744,896 | —- | M] (TopThinks, INC.) – C:\WINDOWS\imagine digital freedom.scr
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/06/30 21:38:03 | 000,001,746 | -H– | M] () – C:\Documents and Settings\Kath\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2002/02/17 08:30:37 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2002/02/17 08:30:37 | 000,606,208 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2002/02/17 08:30:36 | 000,393,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/10/07 16:02:29 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2004/12/24 00:42:16 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Kath\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2002/02/17 16:46:49 | 000,000,079 | —- | M] () – C:\Documents and Settings\Kath\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011/05/14 18:29:54 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kath\Desktop\OTL.exe
[2010/12/16 09:19:52 | 000,513,032 | —- | M] () – C:\Documents and Settings\Kath\Desktop\sdasetup[1].exe
[2011/03/16 01:19:09 | 016,303,111 | —- | M] () – C:\Documents and Settings\Kath\Desktop\Zattoo-4.0.5.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-11 16:34:35

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >

OTL Extras logfile created on: 14/05/2011 18:32:50 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Kath\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 529.00 Mb Available Physical Memory | 52.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 58.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 0.91 Gb Free Space | 2.43% Space Free | Partition Type: NTFS
Drive D: | 31.25 Gb Total Space | 30.09 Gb Free Space | 96.29% Space Free | Partition Type: NTFS
Drive E: | 6.01 Gb Total Space | 2.86 Gb Free Space | 47.53% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: BLUEROOM | User Name: Kath | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ALDI Print Software] – "C:\Program Files\ALDI\ALDI Print Software\ALDI Print Software.exe" "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SoftQuad\HoTMetaL Personal Server\hmps.exe" = C:\Program Files\SoftQuad\HoTMetaL Personal Server\hmps.exe:*:Enabled:HoTMetaL Personal Server – (SoftQuad Inc.)
"C:\Program Files\WS_FTP\WS_FTP95.exe" = C:\Program Files\WS_FTP\WS_FTP95.exe:*:Enabled:WS_FTP 95 – (Ipswitch, Inc. 81 Hartwell Ave. Lexington, MA 02173)
"C:\Program Files\Kontiki\KService.exe" = C:\Program Files\Kontiki\KService.exe:*:Enabled:Delivery Manager Service
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01400202-823E-46CD-A70E-BEE818F97169}" = Microsoft Encarta Encyclopedia Standard - WE 2002
"{0208A7E3-0D30-11D4-A1FC-00508B9D1BA2}" = Smart Office Keyboard
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0AB149EB-2AE0-466C-9BA4-3A718CF06432}" = Informations about your PC
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{18472E28-FCA0-421F-BDAC-AC65012E29F2}" = ArcSoft MediaImpression
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 10
"{2C2A6871-98A5-4840-86C5-7D56B5FFD69E}" = HPpromotions
"{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}" = LUMIX Simple Viewer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{41888B21-922B-4241-4594-EF1E6828A72B}" = BBC iPlayer Desktop
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{582E9125-32B6-4CBA-AB48-3E33CE3DB389}" = NETGEAR RangeMax™ Wireless USB 2.0 Adapter WPN111
"{5A8D3524-79DB-11D5-99D1-00010256D40E}" = SD Viewer for DSC
"{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}" = MP3 Player Utilities 1.47
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{638EBB3E-04BC-40DB-9176-DDEC2C5CB2BC}" = ArcSoft MediaConverter 2.5
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B36DEBF-27D0-4B1E-858D-D397091C6C7D}" = HP Precisionscan Pro 3.1
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E106A57-A17E-431D-B48F-175E42EB9F74}" = imagine digital freedom - Samsung
"{8E263CF8-3864-4041-9AFF-5DF8CDACFB3E}" = Serif PagePlus 9.0 Resource CD-ROM
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{93FB47FB-4FDF-4131-B5FD-7A37883868E7}" = hp psc 2170 series
"{948A3F91-22EE-4E24-B4E0-BADB972357F4}" = ArcSoft Print Creations
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A9DBEBC-C800-4776-A970-D76D6AA405B1}" = PHOTOfunSTUDIO -viewer-
"{9E397B40-13F7-4CA2-9943-ADB29ACBBFDF}" = ArcSoft Software Suite
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}" = Microsoft Works 6.0
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A7581D39-EA20-4883-A480-80C21047052B}" = Easy Network Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}" = ArcSoft Camera Suite 1.3
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BCA541B4-00B4-4D20-B38D-6623BF2F68BF}" = Serif PagePlus 9.0
"{BD3DCAB0-3FE5-44FB-90DA-EFB0A2CD1387}" = Works Synchronization
"{BD723E53-A42C-4702-AA04-1D74A0311590}" = Magic Keyboard
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C3A439E4-7303-491F-A678-CEA36A87D517}" = Microsoft Works Suite Add-in for Microsoft Word
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C769A271-7E1C-48F9-B331-474600DD4C06}" = Microsoft Picture It! Photo 2002
"{C833C7B6-1140-471D-932B-391B5CA66D7D}" = Digital Video
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECFDD53-35DB-4235-9363-7964A0C88E0E}" = Samsung PC Studio
"{D666E437-158C-43D0-AC69-F67F6C5EC2B8}" = Trellix Web Express Site Building
"{DC19E750-988B-4005-A355-85EF66055EFE}" = Works Suite OS Pack
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F7F2DC0A-C22E-49AD-AD37-797309A54E7B}" = Microsoft AutoRoute 2002
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALDI Print Software" = ALDI Print Software
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"BCD98" = Britannica CD 98
"Browser Mouse Browser Mouse" = Browser Mouse Browser Mouse 1.0
"C-1.0W95E" = C-1.0W95E
"CADIX Signature Screen Saver 2.0" = CADIX Signature Screen Saver 2.0
"CCleaner" = CCleaner (remove only)
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Counting_at_Bridge" = Counting at Bridge
"EPSON Printer and Utilities" = EPSON Printer Software
"ffdshow_is1" = ffdshow v1.1.3489 [2010-06-28]
"Free Media Player" = Free Media Player 0.1
"GameSpy Arcade" = GameSpy Arcade
"GraphicsPlus 1.0" = GraphicsPlus 1.0
"HoTMetaL Personal Server 1.2" = SoftQuad HoTMetaL Personal Server 1.2
"HoTMetaLPRO5" = SoftQuad HoTMetaL PRO 5.0
"hp instant support" = hp instant support
"HP Photo Printing Software" = HP Photo Printing Software
"HP PSC 2170 Series" = HP Photo and Imaging 2.0 - hp psc 2170 series
"hp psc 2170 series_Driver" = hp psc 2170 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"MediaShow" = Medi@Show
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MT882" = MT882
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Pacific Poker" = Pacific Poker
"PCI Audio Driver" = PCI Audio Driver
"PhotoBox" = PhotoBox 3.2.5
"Picasa" = Picasa
"Picasa2" = Picasa 2
"QuicktimePluginDeinstallKey" = Quicktime Browser Plug-In
"RealAlt_is1" = Real Alternative 2.0.2 Lite
"RealPlayer 12.0" = RealPlayer
"Rmtablet" = Grafik-Pad MD 41217
"ScoreBridge_is1" = ScoreBridge
"Shockwave" = Shockwave
"Sims" = Sims
"SoftQuad HoTMetaL Site Maker Database" = SoftQuad HoTMetaL Site Maker Database
"Spotify" = Spotify
"Spyware Doctor" = Spyware Doctor with AntiVirus 8.0
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TNT FRE" = Think & Talk French
"VideoLive Mail" = VideoLive Mail 4.0
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"Vodafone 804SS USB driver" = Vodafone 804SS USB driver Software
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2002Setup" = Microsoft Works 2002 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Zattoo4" = Zattoo4 4.0.4

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/05/2011 18:50:01 | Computer Name = BLUEROOM | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 10.0.6866.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 10/05/2011 18:50:22 | Computer Name = BLUEROOM | Source = Microsoft Office 10 | ID = 2001
Description = Rejected Safe Mode action : Microsoft Word.

Error - 12/05/2011 08:40:00 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application psc93_2121.exe, version 0.0.0.0, faulting module
psc93_2121.exe, version 0.0.0.0, fault address 0x00004642.

Error - 12/05/2011 08:40:04 | Computer Name = BLUEROOM | Source = Application Error | ID = 1001
Description = Fault bucket -1854704119.

Error - 12/05/2011 08:40:25 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.17096, faulting
module nview.dll, version 0.0.0.0, fault address 0x000090af.

Error - 12/05/2011 08:43:55 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application offprov.exe, version 9.0.0.2521, faulting module
nview.dll, version 0.0.0.0, fault address 0x000090af.

Error - 12/05/2011 08:44:27 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.17096, faulting
module nview.dll, version 0.0.0.0, fault address 0x000090af.

Error - 12/05/2011 08:44:34 | Computer Name = BLUEROOM | Source = Application Error | ID = 1001
Description = Fault bucket -1854698283.

Error - 12/05/2011 09:00:13 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module , version 0.0.0.0, fault address 0x00000000.

Error - 14/05/2011 11:43:53 | Computer Name = BLUEROOM | Source = Application Error | ID = 1000
Description = Faulting application flashutil10p_activex.exe, version 10.2.159.1,
faulting module nview.dll, version 0.0.0.0, fault address 0x000090af.

[ System Events ]
Error - 12/05/2011 16:28:16 | Computer Name = BLUEROOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 0010DC32E52A has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 12/05/2011 16:28:34 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM Video Capture (universal) service failed to start due
to the following error: %%1058

Error - 12/05/2011 16:28:34 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM A/V Crossbar service failed to start due to the following
error: %%1058

Error - 12/05/2011 16:53:42 | Computer Name = BLUEROOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 0010DC32E52A has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 13/05/2011 07:33:23 | Computer Name = BLUEROOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 0010DC32E52A has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 13/05/2011 07:34:08 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM Video Capture (universal) service failed to start due
to the following error: %%1058

Error - 13/05/2011 07:34:08 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM A/V Crossbar service failed to start due to the following
error: %%1058

Error - 14/05/2011 11:40:56 | Computer Name = BLUEROOM | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.2 for the Network Card with network
address 0010DC32E52A has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).

Error - 14/05/2011 11:41:53 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM Video Capture (universal) service failed to start due
to the following error: %%1058

Error - 14/05/2011 11:41:53 | Computer Name = BLUEROOM | Source = Service Control Manager | ID = 7000
Description = The nVidia WDM A/V Crossbar service failed to start due to the following
error: %%1058


< End of report >
Hi trojanbridge,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes

:OTL
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [DMHotKey] File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKCU..\Run: [Microsoft Works Update Detection] File not found
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab (Reg Error: Key error.)
O16 - DPF: {3B5E9B23-7537-4601-A9E8-FA0D956DEA16} http://www.couponreport.net/ftp/v3123/csauie1.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…8038.2807407407 (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7f2f462b-83ae-11dc-bebc-00038a000015}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -a 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI