rlaher
Topic Starter
I had a virus a few days ago and I thought I got rid of it, but I've been having some problems recently. While browsing in firefox, randomly a "skype.com" tab will open and then suddenly many more of the same exact tabs will continue to open, until my pc crashes. Thanks for the help! Here are my OTL logs:
OTL:
OTL logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Logitech\LWS\LU\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\LWS\LU\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (NetFlixDownloadManager) – C:\Program Files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe ()
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Almico Software)
DRV - (LVUVC) Logitech HD Webcam C310(UVC) – C:\Windows\System32\drivers\LVUVC.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (P17) – C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F4 DC 1F B7 FF 09 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.23s
FF - prefs.js..extensions.enabledItems: {3061A488-48A8-4F6F-9743-F89A57192F45}:1.9.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..network.proxy.autoconfig_url: "/*********************************************************** ** TJHSST Proxy Auto-Configuration Script ** ** For use with TJHSST school databases ** ** Use is restricted to TJHSST students and faculty ONLY. ** ** All other use is prohibited. ** ** Originally contributed by William Yang. ** ** Autogenerated version by Brandon Vargo. ** ************************************************************/ function FindProxyForURL(url, host) { if ( dnsDomainIs(host, \".abc-clio.com\") || dnsDomainIs(host, \"www.accessscience.com\") || dnsDomainIs(host, \".eb.com\") || dnsDomainIs(host, \"library.cqpress.com\") || dnsDomainIs(host, \".earthscape.org\") || dnsDomainIs(host, \"search.ebscohost.com\") || dnsDomainIs(host, \"ehrafworldcultures.yale.edu\") || dnsDomainIs(host, \"infotrac.galegroup.com\") || dnsDomainIs(host, \".grolier.com\") || dnsDomainIs(host, \"jchemed.chem.wisc.edu\") || dnsDomainIs(host, \"www.jstor.org\") || dnsDomainIs(host, \"web.lexis-nexis.com\") || dnsDomainIs(host, \"www.noodletools.com\") || dnsDomainIs(host, \"dictionary.oed.com\") || dnsDomainIs(host, \"poll.orspub.com\") || dnsDomainIs(host, \"proquestk12.com\") || dnsDomainIs(host, \"www.sciencedirect.com\") || dnsDomainIs(host, \"hwwilsonweb.com\") || dnsDomainIs(host, \".nature.com\") || dnsDomainIs(host, \"portal.bigchalk.com\") || dnsDomainIs(host, \".umi.com\") || dnsDomainIs(host, \".culturegrams.com\") || dnsDomainIs(host, \".acs.org\") || dnsDomainIs(host, \".opticsinfobase.org\") || dnsDomainIs(host, \"www.worldbookonline.com\") || dnsDomainIs(host, \".tumblebooks.com\") || dnsDomainIs(host, \".marshallcavendishdigital.com\") ) return \"PROXY local.border.tjhsst.edu:8080\"; else return \"DIRECT\"; }"
FF - prefs.js..network.proxy.backup.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 09:20:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 09:20:08 | 000,000,000 | —D | M]
[2010/11/13 17:03:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2011/05/13 21:05:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions
[2011/03/25 07:11:24 | 000,000,000 | —D | M] (SkipScreen) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions\SkipScreen@SkipScreen
[2011/03/20 22:23:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/10 22:17:09 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/11/16 08:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) –
[2011/04/16 21:20:55 | 000,000,000 | —D | M] (XULRunner) – C:\USERS\RASHAD\APPDATA\LOCAL\{3061A488-48A8-4F6F-9743-F89A57192F45}
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/05/08 09:20:06 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/11/16 08:38:48 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 09:20:07 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.)
O4 - HKCU..\Run: [F.lux] C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2007/01/09 20:32:15 | 000,000,206 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare) - E:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/01/26 17:22:17 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe – [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\configure\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\install\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell - "" = AutoRun
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell\AutoRun\command - "" = E:\autorun.exe – [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/18 19:36:02 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Program Files\SpeedFan
[2011/05/11 06:59:03 | 000,284,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/05/11 06:59:02 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/05/11 06:59:01 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/11 06:59:00 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/03 22:17:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Malwarebytes
[2011/05/03 22:16:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/03 22:16:56 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/03 22:16:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 17:12:17 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2011/04/27 07:51:03 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2011/04/27 07:51:02 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2011/04/27 07:51:01 | 000,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2011/04/27 07:51:01 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2011/04/27 07:50:58 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/27 07:50:57 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/04/22 01:51:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/04/20 16:39:36 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2011/04/20 16:35:34 | 000,000,000 | —D | C] – C:\ProgramData\vmcNetFlix_Data
[2011/04/20 16:33:32 | 000,000,000 | —D | C] – C:\Program Files\Luttmann
[2011/04/20 16:31:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/20 16:31:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
========== Files - Modified Within 30 Days ==========
[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:11:16 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/19 21:11:16 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/19 21:06:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 20:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001UA.job
[2011/05/19 20:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001Core.job
[2011/05/14 15:01:44 | 000,000,969 | —- | M] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:44 | 000,000,045 | —- | M] () – C:\Windows\System32\initdebug.nfo
[2011/05/08 09:20:34 | 000,002,002 | —- | M] () – C:\Users\Rashad\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/03 22:16:59 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:05:30 | 000,011,800 | -HS- | M] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:04:26 | 000,011,808 | -HS- | M] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 19:22:08 | 000,000,120 | —- | M] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/05/03 19:22:08 | 000,000,000 | —- | M] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/05/03 00:16:32 | 000,001,055 | —- | M] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/22 10:32:09 | 000,409,784 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/20 16:27:15 | 000,000,362 | RHS- | M] () – C:\ProgramData\ntuser.pol
========== Files Created - No Company Name ==========
[2011/05/14 15:01:44 | 000,000,969 | —- | C] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:42 | 000,000,045 | —- | C] () – C:\Windows\System32\initdebug.nfo
[2011/05/03 22:16:59 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:02:21 | 000,011,808 | -HS- | C] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:02:21 | 000,011,800 | -HS- | C] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 00:08:53 | 000,001,055 | —- | C] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/20 16:27:15 | 000,000,362 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/04/16 21:20:56 | 000,000,120 | —- | C] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/04/16 21:20:56 | 000,000,000 | —- | C] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/04/15 22:15:47 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/02/09 20:56:30 | 000,000,410 | —- | C] () – C:\Windows\brwmark.ini
[2011/02/09 20:56:30 | 000,000,052 | —- | C] () – C:\Windows\BRPP2KA.INI
[2011/01/24 23:23:29 | 000,000,098 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/11/13 19:36:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/13 17:02:54 | 000,166,912 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2010/11/13 17:02:54 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/11/10 03:45:32 | 000,102,744 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2010/05/07 19:46:36 | 000,014,168 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2010/05/07 19:43:30 | 000,025,824 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/16 07:50:54 | 000,003,930 | —- | C] () – C:\Windows\System32\ludap17.ini
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,409,784 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/11/13 07:07:24 | 000,002,177 | —- | C] () – C:\Windows\P17EP.ini
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/12/04 06:20:30 | 000,001,489 | —- | C] () – C:\Windows\P17EP51.ini
[2007/06/07 06:25:42 | 000,001,578 | —- | C] () – C:\Windows\P17EPLS.ini
[2005/03/08 07:17:00 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2011/01/18 16:37:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\.Tribler
[2011/04/15 22:15:41 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\GetRightToGo
[2010/11/13 17:08:11 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Leadertech
[2011/01/27 16:40:55 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\LolClient
[2011/01/26 20:54:15 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Soluto
[2011/05/19 21:15:50 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2011/04/20 16:39:36 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2010/11/13 22:00:31 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\VOWSoft
[2011/03/13 08:42:21 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 21:06:13 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/13 17:02:09 | 000,000,221 | -HS- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-19 02:38:19
< End of report >
Extra:
OTL Extras logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3A9D04F7-80CA-4755-97EC-6025B515A6B8}" = League of Legends
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7ADB1002-9FAC-4EF0-8EC0-57A0D7CB5355}" = Aurora
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{AE1E2901-7405-4568-B8D8-87958E63C7D0}" = Soluto
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C79743A0-BE17-4A80-9A1B-FAF9E8E31C41}" = Vista Media Center vmcNetFlix Add-In x86
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8843212-F0FC-4C3B-BFF3-D51829CB4F19}" = iTunes
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AudioCS" = Creative Audio Control Panel
"AVCWare iPod to iPod/Computer/iTunes Transfer" = AVCWare iPod to iPod/Computer/iTunes Transfer
"AviSynth" = AviSynth 2.5
"CCleaner" = CCleaner
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Cucusoft iPod Video Converter_is1" = Cucusoft iPod Video Converter 8.08
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EphPod" = EphPod
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"ImgBurn" = ImgBurn
"Jack Claw_is1" = Jack Claw
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 11200" = Shadowgrounds: Survivor
"Steam App 240" = Counter-Strike: Source
"Steam App 2500" = Shadowgrounds
"Steam App 2505" = Shadowgrounds Editor
"Steam App 3480" = Peggle Deluxe
"Steam App 35700" = Trine
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 42910" = Magicka
"Steam App 440" = Team Fortress 2
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Tribler" = Tribler (remove only)
"uTorrent" = µTorrent
"Videora iPod Converter" = Videora iPod Converter 6
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.5
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Flux" = F.lux
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
OTL:
OTL logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Soluto\SolutoService.exe (Soluto)
PRC - C:\Program Files\Soluto\Soluto.exe (Soluto)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Logitech\LWS\LU\LogitechUpdate.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\LWS\LU\LULnchr.exe (Logitech, Inc.)
PRC - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe ()
PRC - C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Users\Rashad\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SolutoService) – C:\Program Files\Soluto\SolutoService.exe (Soluto)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (DAUpdaterSvc) – C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (NetFlixDownloadManager) – C:\Program Files\Luttmann\vmcNetFlix\NetFlixDownloadManager.exe ()
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (Soluto) – C:\Windows\system32\DRIVERS\Soluto.sys (Soluto LTD.)
DRV - (speedfan) – C:\Windows\system32\speedfan.sys (Almico Software)
DRV - (LVUVC) Logitech HD Webcam C310(UVC) – C:\Windows\System32\drivers\LVUVC.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (P17) – C:\Windows\System32\drivers\P17.sys (Creative Technology Ltd.)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (mcdbus) – C:\Windows\System32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (giveio) – C:\Windows\system32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F4 DC 1F B7 FF 09 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.23s
FF - prefs.js..extensions.enabledItems: {3061A488-48A8-4F6F-9743-F89A57192F45}:1.9.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.2
FF - prefs.js..network.proxy.autoconfig_url: "/*********************************************************** ** TJHSST Proxy Auto-Configuration Script ** ** For use with TJHSST school databases ** ** Use is restricted to TJHSST students and faculty ONLY. ** ** All other use is prohibited. ** ** Originally contributed by William Yang. ** ** Autogenerated version by Brandon Vargo. ** ************************************************************/ function FindProxyForURL(url, host) { if ( dnsDomainIs(host, \".abc-clio.com\") || dnsDomainIs(host, \"www.accessscience.com\") || dnsDomainIs(host, \".eb.com\") || dnsDomainIs(host, \"library.cqpress.com\") || dnsDomainIs(host, \".earthscape.org\") || dnsDomainIs(host, \"search.ebscohost.com\") || dnsDomainIs(host, \"ehrafworldcultures.yale.edu\") || dnsDomainIs(host, \"infotrac.galegroup.com\") || dnsDomainIs(host, \".grolier.com\") || dnsDomainIs(host, \"jchemed.chem.wisc.edu\") || dnsDomainIs(host, \"www.jstor.org\") || dnsDomainIs(host, \"web.lexis-nexis.com\") || dnsDomainIs(host, \"www.noodletools.com\") || dnsDomainIs(host, \"dictionary.oed.com\") || dnsDomainIs(host, \"poll.orspub.com\") || dnsDomainIs(host, \"proquestk12.com\") || dnsDomainIs(host, \"www.sciencedirect.com\") || dnsDomainIs(host, \"hwwilsonweb.com\") || dnsDomainIs(host, \".nature.com\") || dnsDomainIs(host, \"portal.bigchalk.com\") || dnsDomainIs(host, \".umi.com\") || dnsDomainIs(host, \".culturegrams.com\") || dnsDomainIs(host, \".acs.org\") || dnsDomainIs(host, \".opticsinfobase.org\") || dnsDomainIs(host, \"www.worldbookonline.com\") || dnsDomainIs(host, \".tumblebooks.com\") || dnsDomainIs(host, \".marshallcavendishdigital.com\") ) return \"PROXY local.border.tjhsst.edu:8080\"; else return \"DIRECT\"; }"
FF - prefs.js..network.proxy.backup.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ftp_port: 8080
FF - prefs.js..network.proxy.backup.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.gopher_port: 8080
FF - prefs.js..network.proxy.backup.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.socks_port: 8080
FF - prefs.js..network.proxy.backup.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.backup.ssl_port: 8080
FF - prefs.js..network.proxy.ftp: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.socks_port: 8080
FF - prefs.js..network.proxy.ssl: "local.border.tjhsst.edu"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/08 09:20:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/08 09:20:08 | 000,000,000 | —D | M]
[2010/11/13 17:03:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Extensions
[2011/05/13 21:05:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions
[2011/03/25 07:11:24 | 000,000,000 | —D | M] (SkipScreen) – C:\Users\Rashad\AppData\Roaming\Mozilla\Firefox\Profiles\b3w0wr7d.default\extensions\SkipScreen@SkipScreen
[2011/03/20 22:23:35 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/10 22:17:09 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/11/16 08:38:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) –
[2011/04/16 21:20:55 | 000,000,000 | —D | M] (XULRunner) – C:\USERS\RASHAD\APPDATA\LOCAL\{3061A488-48A8-4F6F-9743-F89A57192F45}
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\RASHAD\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3W0WR7D.DEFAULT\EXTENSIONS\{E4A8A97B-F2ED-450B-B12D-EE082BA24781}.XPI
[2011/05/08 09:20:06 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/11/16 08:38:48 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/05/08 09:20:07 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [P17RunE] C:\Windows\System32\P17RunE.dll (Creative Technology Ltd.)
O4 - HKCU..\Run: [F.lux] C:\Users\Rashad\Local Settings\Apps\F.lux\flux.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Program Files\Soluto\soluto.exe /userinit) - C:\Program Files\Soluto\soluto.exe (Soluto)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2007/01/09 20:32:15 | 000,000,206 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare) - E:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/01/26 17:22:17 | 000,000,052 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe – [2007/01/08 22:32:16 | 001,384,388 | R— | M] (MediaChance)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\configure\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{762bc6a0-ef81-11df-9973-806e6f6e6963}\Shell\install\command - "" = D:\setup.exe – [2006/10/27 07:30:48 | 000,463,152 | R— | M] (Microsoft Corporation)
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell - "" = AutoRun
O33 - MountPoints2\{965fd789-f7ef-11df-8f90-001fd09a9959}\Shell\AutoRun\command - "" = E:\autorun.exe – [2009/07/16 18:13:07 | 001,246,440 | R— | M] (BioWare)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
========== Files/Folders - Created Within 30 Days ==========
[2011/05/18 19:36:02 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\poqexec.exe
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/05/14 15:01:44 | 000,000,000 | —D | C] – C:\Program Files\SpeedFan
[2011/05/11 06:59:03 | 000,284,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2011/05/11 06:59:02 | 000,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2011/05/11 06:59:01 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2011/05/11 06:59:00 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2011/05/03 22:17:04 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Malwarebytes
[2011/05/03 22:16:59 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/05/03 22:16:59 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/05/03 22:16:56 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2011/05/03 22:16:56 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/05/01 17:12:17 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Users\Rashad\Documents\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\StarCraft II
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\ProgramData\Blizzard Entertainment
[2011/05/01 16:55:51 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
[2011/05/01 16:32:53 | 000,000,000 | —D | C] – C:\Program Files\Elaborate Bytes
[2011/04/27 07:51:03 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2011/04/27 07:51:02 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2011/04/27 07:51:01 | 000,146,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\storport.sys
[2011/04/27 07:51:01 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2011/04/27 07:50:58 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2011/04/27 07:50:57 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/04/22 01:51:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/04/20 16:39:36 | 000,000,000 | —D | C] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2011/04/20 16:35:34 | 000,000,000 | —D | C] – C:\ProgramData\vmcNetFlix_Data
[2011/04/20 16:33:32 | 000,000,000 | —D | C] – C:\Program Files\Luttmann
[2011/04/20 16:31:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/04/20 16:31:12 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
========== Files - Modified Within 30 Days ==========
[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:13:25 | 000,014,224 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/19 21:11:16 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/05/19 21:11:16 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/05/19 21:06:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 20:19:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001UA.job
[2011/05/19 20:19:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2132048027-1570888435-1720534292-1001Core.job
[2011/05/14 15:01:44 | 000,000,969 | —- | M] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:44 | 000,000,045 | —- | M] () – C:\Windows\System32\initdebug.nfo
[2011/05/08 09:20:34 | 000,002,002 | —- | M] () – C:\Users\Rashad\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/05/03 22:16:59 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:05:30 | 000,011,800 | -HS- | M] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:04:26 | 000,011,808 | -HS- | M] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 19:22:08 | 000,000,120 | —- | M] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/05/03 19:22:08 | 000,000,000 | —- | M] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/05/03 00:16:32 | 000,001,055 | —- | M] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/22 10:32:09 | 000,409,784 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/04/20 16:27:15 | 000,000,362 | RHS- | M] () – C:\ProgramData\ntuser.pol
========== Files Created - No Company Name ==========
[2011/05/14 15:01:44 | 000,000,969 | —- | C] () – C:\Users\Rashad\Desktop\SpeedFan.lnk
[2011/05/14 15:01:42 | 000,000,045 | —- | C] () – C:\Windows\System32\initdebug.nfo
[2011/05/03 22:16:59 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/05/03 22:02:21 | 000,011,808 | -HS- | C] () – C:\ProgramData\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 22:02:21 | 000,011,800 | -HS- | C] () – C:\Users\Rashad\AppData\Local\r6rj11e15aixlyd2n4gwm4nxoe78r7c3605
[2011/05/03 00:08:53 | 000,001,055 | —- | C] () – C:\Users\Public\Desktop\StarCraft II.lnk
[2011/04/20 16:27:15 | 000,000,362 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/04/16 21:20:56 | 000,000,120 | —- | C] () – C:\Users\Rashad\AppData\Local\Psoqutihol.dat
[2011/04/16 21:20:56 | 000,000,000 | —- | C] () – C:\Users\Rashad\AppData\Local\Jlonul.bin
[2011/04/15 22:15:47 | 000,057,344 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2011/02/09 20:56:30 | 000,000,410 | —- | C] () – C:\Windows\brwmark.ini
[2011/02/09 20:56:30 | 000,000,052 | —- | C] () – C:\Windows\BRPP2KA.INI
[2011/01/24 23:23:29 | 000,000,098 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/11/13 19:56:50 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2010/11/13 19:36:10 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/13 17:02:54 | 000,166,912 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2010/11/13 17:02:54 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/11/10 03:45:32 | 000,102,744 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2010/05/07 19:46:36 | 000,014,168 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2010/05/07 19:43:30 | 000,025,824 | —- | C] () – C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/16 07:50:54 | 000,003,930 | —- | C] () – C:\Windows\System32\ludap17.ini
[2009/07/14 00:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,409,784 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,623,940 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,106,316 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 20:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 19:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/11/13 07:07:24 | 000,002,177 | —- | C] () – C:\Windows\P17EP.ini
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2007/12/04 06:20:30 | 000,001,489 | —- | C] () – C:\Windows\P17EP51.ini
[2007/06/07 06:25:42 | 000,001,578 | —- | C] () – C:\Windows\P17EPLS.ini
[2005/03/08 07:17:00 | 000,000,054 | —- | C] () – C:\Windows\System32\ctzapxx.ini
[1996/04/03 15:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys
========== LOP Check ==========
[2011/01/18 16:37:47 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\.Tribler
[2011/04/15 22:15:41 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\GetRightToGo
[2010/11/13 17:08:11 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Leadertech
[2011/01/27 16:40:55 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\LolClient
[2011/01/26 20:54:15 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\Soluto
[2011/05/19 21:15:50 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\uTorrent
[2011/04/20 16:39:36 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\vmcNetFlix_Data
[2010/11/13 22:00:31 | 000,000,000 | —D | M] – C:\Users\Rashad\AppData\Roaming\VOWSoft
[2011/03/13 08:42:21 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/05/19 21:06:08 | 2616,057,856 | -HS- | M] () – C:\hiberfil.sys
[2011/05/19 21:06:13 | 3488,079,872 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/06/22 19:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/13 21:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/11/13 17:02:09 | 000,000,221 | -HS- | M] () – C:\Users\Rashad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-19 02:38:19
< End of report >
Extra:
OTL Extras logfile created on: 5/19/2011 9:15:09 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Rashad\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 70.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.07 Gb Total Space | 260.35 Gb Free Space | 43.68% Space Free | Partition Type: NTFS
Drive D: | 640.89 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 2.17 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: RASHAD-PC | User Name: Rashad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{17424F35-8B77-4ADF-BC63-BF9B81418539}" = Apple Application Support
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3A9D04F7-80CA-4755-97EC-6025B515A6B8}" = League of Legends
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7ADB1002-9FAC-4EF0-8EC0-57A0D7CB5355}" = Aurora
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{AE1E2901-7405-4568-B8D8-87958E63C7D0}" = Soluto
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C79743A0-BE17-4A80-9A1B-FAF9E8E31C41}" = Vista Media Center vmcNetFlix Add-In x86
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E8843212-F0FC-4C3B-BFF3-D51829CB4F19}" = iTunes
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AudioCS" = Creative Audio Control Panel
"AVCWare iPod to iPod/Computer/iTunes Transfer" = AVCWare iPod to iPod/Computer/iTunes Transfer
"AviSynth" = AviSynth 2.5
"CCleaner" = CCleaner
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Cucusoft iPod Video Converter_is1" = Cucusoft iPod Video Converter 8.08
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EphPod" = EphPod
"Free iPod Video Converter_is1" = Free iPod Video Converter 1.34
"ImgBurn" = ImgBurn
"Jack Claw_is1" = Jack Claw
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"SpeedFan" = SpeedFan (remove only)
"StarCraft II" = StarCraft II
"Steam App 11200" = Shadowgrounds: Survivor
"Steam App 240" = Counter-Strike: Source
"Steam App 2500" = Shadowgrounds
"Steam App 2505" = Shadowgrounds Editor
"Steam App 3480" = Peggle Deluxe
"Steam App 35700" = Trine
"Steam App 380" = Half-Life 2: Episode One
"Steam App 400" = Portal
"Steam App 42910" = Magicka
"Steam App 440" = Team Fortress 2
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Tribler" = Tribler (remove only)
"uTorrent" = µTorrent
"Videora iPod Converter" = Videora iPod Converter 6
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.5
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Flux" = F.lux
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >