Sorry….I ran OTL as instructed but the logs came up before I had a chance to reboot. I rebooted after that. No log came up after reboot. When i rebooted CTMBHA.dll error is still coming up.
here are the logs
OTL logfile created on: 5/28/2011 4:10:02 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.08 Mb Total Physical Memory | 396.08 Mb Available Physical Memory | 38.75% Memory free
2.40 Gb Paging File | 1.89 Gb Available in Paging File | 78.57% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.49 Gb Total Space | 34.61 Gb Free Space | 46.47% Space Free | Partition Type: NTFS
Drive D: | 551.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 557.95 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: HOME | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/28 16:09:35 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
PRC - [2011/01/20 04:20:12 | 001,305,408 | —- | M] (DT Soft Ltd) – C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2010/07/09 09:58:29 | 002,048,352 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/08/27 09:59:03 | 000,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/27 09:59:02 | 000,693,016 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/08/27 09:58:59 | 000,595,736 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/27 09:58:57 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/08/27 09:58:51 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2008/12/20 18:59:23 | 000,382,384 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jucheck.exe
PRC - [2008/10/01 00:00:03 | 000,026,112 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\realplay.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2005/10/05 03:12:00 | 000,094,208 | —- | M] () – C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2005/09/15 09:47:22 | 000,057,344 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
PRC - [2005/09/08 05:20:00 | 000,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2005/06/10 10:44:02 | 000,618,496 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
PRC - [2005/03/23 00:20:44 | 000,339,968 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [1997/08/19 00:00:00 | 000,051,984 | —- | M] () – C:\Program Files\Microsoft Office\Office\OSA.EXE
========== Modules (SafeList) ==========
MOD - [2011/05/28 16:09:35 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
MOD - [2010/08/23 11:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/04/18 04:12:30 | 001,181,328 | —- | M] (Lavasoft) [On_Demand | Stopped] – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service)
SRV - [2009/08/27 09:58:57 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc)
SRV - [2009/08/27 09:58:51 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd)
SRV - [2008/09/30 23:54:31 | 000,069,632 | —- | M] (Creative Labs) [On_Demand | Stopped] – C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe – (Creative Labs Licensing Service)
SRV - [2007/03/07 15:47:46 | 000,076,848 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
========== Driver Services (SafeList) ==========
DRV - [2011/05/11 00:25:51 | 000,218,688 | —- | M] (DT Soft Ltd) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\dtsoftbus01.sys – (dtsoftbus01)
DRV - [2011/05/10 14:02:38 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/01/05 08:56:06 | 000,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] – C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\SASENUM.SYS – (SASENUM)
DRV - [2010/01/05 08:56:04 | 000,009,968 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\sasdifsv.sys – (SASDIFSV)
DRV - [2010/01/05 08:56:02 | 000,074,480 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2009/09/23 07:55:23 | 000,064,288 | —- | M] (Lavasoft AB) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd)
DRV - [2009/08/27 09:59:03 | 000,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/08/27 09:59:03 | 000,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2009/05/19 09:23:30 | 000,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2008/10/01 00:00:06 | 000,008,552 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM)
DRV - [2007/02/25 12:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 16:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2005/09/08 05:20:00 | 000,094,332 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2005/09/08 05:20:00 | 000,087,036 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2005/09/08 05:20:00 | 000,086,524 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2005/09/08 05:20:00 | 000,025,628 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2005/09/08 05:20:00 | 000,014,684 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2005/09/08 05:20:00 | 000,006,364 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2005/09/08 05:20:00 | 000,002,496 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\system32\DLA\DLADResN.SYS – (DLADResN)
DRV - [2005/08/25 12:16:52 | 000,005,628 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2005/08/25 12:16:16 | 000,022,684 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\system32\drivers\DLARTL_N.SYS – (DLARTL_N)
DRV - [2005/08/04 04:10:18 | 001,273,344 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/06/06 21:40:48 | 000,180,736 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA) High Definition Audio Driver (WDM)
DRV - [2005/05/25 22:34:00 | 000,158,464 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CTUSFSYN.SYS – (CTUSFSYN)
DRV - [2005/03/25 16:11:00 | 001,350,272 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\sigfilt.sys – (sigfilt)
DRV - [2005/01/11 00:15:00 | 000,138,752 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CTSFM2K.SYS – (ctsfm2k)
DRV - [2005/01/11 00:15:00 | 000,106,496 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\CTOSS2K.SYS – (ossrv)
DRV - [2004/12/23 01:58:00 | 000,008,704 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\PFModNT.sys – (PfModNT)
DRV - [2003/11/17 21:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 21:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 21:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2001/08/17 12:19:20 | 000,096,256 | —- | M] (Copyright © Creative Technology Ltd. 1994-2001) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ctlsb16.sys – (ctlsb16) Creative SB16/AWE32/AWE64 Driver (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q;=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl;…&channel;=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.mediacomtoday.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.msn.com/sphome.aspx
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074
[2009/08/14 17:58:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2009/08/14 17:58:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions\[removed]
O1 HOSTS File: ([2011/05/17 14:34:31 | 000,434,425 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14955 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [MBDef] C:\WINDOWS\MBDEF.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [MBMon] C:\WINDOWS\System32\CTMBHA.DLL ()
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VoiceCenter] C:\Program Files\Creative\VoiceCenter\AndreaVC.exe (Andrea Electronics Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [oimutlua] File not found
O4 - HKCU..\Run: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE ()
O4 - Startup: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1}
http://www.freerealms.com/gamedata/FreeRealmsInstaller.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.3.cab (DLM Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688 (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} http://download.microsoft.com/download/Pow…N-US/msorun.cab (IEAnimBehaviorFactory Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D}
https://www.plaxo.com/activex/plx_upldr-2k-xp.cab (Plaxo Auto-Import Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\SASWINLO.dll - C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Documents and Settings\Kevin\Desktop\Virus Protection\Superantispyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/08/30 18:37:39 | 000,000,000 | R–D | M] - D:\Autorun – [ CDFS ]
O32 - AutoRun File - [2002/07/31 18:40:10 | 000,151,552 | R— | M] () - D:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/08/28 21:23:59 | 000,000,054 | R— | M] () - D:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2002/10/08 16:15:00 | 000,000,000 | R–D | M] - E:\Autorun – [ CDFS ]
O32 - AutoRun File - [2002/07/31 18:40:10 | 000,151,552 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/08/28 21:23:59 | 000,000,054 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell - "" = AutoRun
O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2002/07/31 18:40:10 | 000,151,552 | R— | M] ()
O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\Auto\command - "" = G:\autorun.bat
O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.bat
O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\explore\Command - "" = G:\autorun.bat
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/28 16:09:33 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2011/05/25 01:37:53 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Kevin\Recent
[2011/05/14 22:40:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011/05/12 17:28:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Infogrames Interactive
[2011/05/11 00:25:51 | 000,218,688 | —- | C] (DT Soft Ltd) – C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2011/05/11 00:25:38 | 000,000,000 | —D | C] – C:\Program Files\DAEMON Tools Lite
[2011/05/11 00:24:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Kevin\Application Data\DAEMON Tools Lite
[2011/05/11 00:24:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/05/10 14:07:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Alcohol 120%
[11 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/28 16:12:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 2).job
[2011/05/28 16:09:35 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2011/05/28 15:56:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/28 10:12:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 1).job
[2011/05/28 09:05:57 | 076,406,478 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/05/28 04:12:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 4).job
[2011/05/27 22:12:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Daily 3).job
[2011/05/27 16:56:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/27 10:12:00 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/05/26 12:54:44 | 000,362,310 | —- | M] () – C:\Documents and Settings\Kevin\Desktop\Bill_of_Sale_Form.pdf
[2011/05/25 01:44:10 | 000,381,692 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/05/25 01:44:10 | 000,053,436 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/05/25 01:39:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/05/25 01:39:36 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/05/25 01:22:19 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/05/23 22:57:44 | 000,000,000 | -H– | M] () – C:\Documents and Settings\Kevin\My Documents\Default.rdp
[2011/05/23 01:26:44 | 000,000,346 | —- | M] () – C:\Documents and Settings\Kevin\defogger_reenable
[2011/05/21 16:41:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/17 14:34:31 | 000,434,425 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/05/12 17:30:51 | 000,001,525 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RollerCoaster Tycoon 2.lnk
[2011/05/11 00:25:51 | 000,218,688 | —- | M] (DT Soft Ltd) – C:\WINDOWS\System32\drivers\dtsoftbus01.sys
[2011/05/11 00:25:42 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2011/05/10 13:58:29 | 000,004,216 | —- | M] () – C:\Documents and Settings\Kevin\Application Data\mainhst.zgh
[2011/05/02 16:29:17 | 000,070,565 | —- | M] () – C:\Documents and Settings\Kevin\Desktop\kevinadjuster.PDF
[11 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/26 12:54:44 | 000,362,310 | —- | C] () – C:\Documents and Settings\Kevin\Desktop\Bill_of_Sale_Form.pdf
[2011/05/23 22:57:44 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Kevin\My Documents\Default.rdp
[2011/05/23 01:26:28 | 000,000,346 | —- | C] () – C:\Documents and Settings\Kevin\defogger_reenable
[2011/05/12 17:30:51 | 000,001,525 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RollerCoaster Tycoon 2.lnk
[2011/05/11 00:25:42 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2011/05/02 16:29:14 | 000,070,565 | —- | C] () – C:\Documents and Settings\Kevin\Desktop\kevinadjuster.PDF
[2010/07/08 23:08:37 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\Implode.dll
[2010/07/08 23:08:27 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\Crutl14.dll
[2010/07/08 23:08:25 | 000,100,352 | —- | C] () – C:\WINDOWS\System32\pg32conv.dll
[2010/03/23 02:18:02 | 000,004,216 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\mainhst.zgh
[2010/01/30 03:24:14 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/01/30 03:24:14 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/01/30 03:24:14 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/01/30 03:24:14 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/01/30 03:24:14 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/01 03:56:27 | 000,046,324 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/05/27 04:48:08 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\zmbv.dll
[2009/03/03 14:19:17 | 000,000,027 | —- | C] () – C:\WINDOWS\ic.ini
[2009/03/03 14:05:18 | 000,001,100 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/02 16:07:46 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2008/12/26 10:47:39 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/12/21 23:19:20 | 000,045,568 | —- | C] () – C:\WINDOWS\UniFish3.exe
[2008/12/01 23:34:11 | 000,000,000 | —- | C] () – C:\WINDOWS\Textart.INI
[2008/11/14 18:54:33 | 000,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/11/13 23:22:03 | 000,000,086 | —- | C] () – C:\WINDOWS\ka.ini
[2008/11/13 22:10:06 | 000,000,227 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2008/10/30 01:13:04 | 000,032,256 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/09 15:48:07 | 000,000,037 | —- | C] () – C:\WINDOWS\iltwain.ini
[2008/10/09 15:30:29 | 000,000,120 | —- | C] () – C:\WINDOWS\DDSSetup.ini
[2008/10/05 21:39:29 | 000,002,516 | —- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2008/10/05 21:39:29 | 000,000,056 | RHS- | C] () – C:\WINDOWS\System32\993E0536C7.sys
[2008/10/03 02:00:34 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JPR.{PB
[2008/10/03 02:00:34 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JCM.{PB
[2008/10/01 00:22:26 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/10/01 00:15:51 | 000,000,128 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\fusioncache.dat
[2008/10/01 00:10:11 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/10/01 00:06:57 | 000,000,203 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/10/01 00:03:45 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2008/09/30 23:59:17 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/09/30 23:54:29 | 000,005,811 | —- | C] () – C:\WINDOWS\System32\CTSBMB.INI
[2008/09/15 19:14:24 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/09/15 19:11:10 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/06/02 20:54:14 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\DSRIRREM.EXE
[2006/06/02 20:53:58 | 000,004,969 | —- | C] () – C:\WINDOWS\System32\Sigfilt.ini
[2006/06/02 20:53:58 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/06/02 20:53:44 | 001,345,520 | —- | C] () – C:\WINDOWS\System32\CTMBHA.DLL
[2006/06/02 20:53:44 | 000,102,400 | —- | C] () – C:\WINDOWS\SETLANG.EXE
[2006/06/02 20:53:22 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2006/06/02 20:53:20 | 000,095,617 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/06/02 20:52:40 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 04:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/08/16 04:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/08/16 04:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 04:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/08/16 04:27:59 | 000,201,736 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/08/16 04:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005/08/16 04:18:33 | 000,381,692 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/08/16 04:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005/08/16 04:18:33 | 000,053,436 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/08/16 04:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005/08/16 04:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005/08/16 04:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/08/16 04:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005/08/16 04:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005/08/16 04:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005/08/16 04:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005/08/16 04:18:08 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/12/21 11:13:56 | 000,191,136 | —- | C] () – C:\WINDOWS\System32\plx_upldr.dll
[1997/08/19 00:00:00 | 000,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/08/19 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1997/08/14 00:00:00 | 000,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/08/14 00:00:00 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
========== Custom Scans ==========
< :Services >
< >
< :OTL >
< IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec…amp;gc=1&q;= >
Invalid Switch: askRedirec…amp;gc=1&q;=
< IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8074 >
< O4 - HKCU..\Run: [oimutlua] File not found >
< O4 - Startup: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\PowerReg Scheduler.exe () >
< O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell - "" = AutoRun >
< O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell\AutoRun - "" = Auto&Play; >
< O33 - MountPoints2\{c0e81e61-7b38-11e0-a032-001372c51f84}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2002/07/31 18:40:10 | 000,151,552 | R— | M] () >
< O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\Auto\command - "" = G:\autorun.bat >
< O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\AutoRun - "" = Auto&Play; >
< O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.bat >
< O33 - MountPoints2\{f3d7dde6-e184-11de-9fbb-001372c51f84}\Shell\explore\Command - "" = G:\autorun.bat >
< [11 C:\Documents and Settings\Kevin\My Documents\*.tmp files -> C:\Documents and Settings\Kevin\My Documents\*.tmp -> ] >
< [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] >
< [1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] >
< >
< :Commands >
< [purity] >
< [EmptyFlash] >
< [emptytemp] >
< >
< End of report >
OTL Extras logfile created on: 5/28/2011 4:10:03 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.08 Mb Total Physical Memory | 396.08 Mb Available Physical Memory | 38.75% Memory free
2.40 Gb Paging File | 1.89 Gb Available in Paging File | 78.57% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.49 Gb Total Space | 34.61 Gb Free Space | 46.47% Space Free | Partition Type: NTFS
Drive D: | 551.46 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 557.95 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: HOME | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" =
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dune\Dune 2000\DUNE2000.DAT" = C:\Program Files\Dune\Dune 2000\DUNE2000.DAT:*:Disabled:Dune2000 – (Intelligent Games)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{003DF6C7-2E32-46E1-8CAE-3BB038F88CBB}" = BVSInstall
"{024E6362-7D37-4D78-93F9-00C1747DA645}" = Residential Component Technology - Standalone
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{09B57AFC-66B1-432C-A1FE-5F9115154671}" = MyCheckBook
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{43CAC9A1-1993-4F65-9096-7C9AFC2BBF54}" = Dell CinePlayer
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{46C73DE4-E96D-4F7C-8371-F28052183B12}" = Sonic Advanced Decoder
"{53C6D09E-EAB6-49E5-BA4C-BA7FF13830FB}" = Sound Blaster Audigy ADVANCED MB
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}" = RollerCoaster Tycoon 2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7AB3A249-FB81-416B-917A-A2A10E74C503}" = iTunes
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{87F88639-CD50-4827-A5C3-535E7FC75334}" = Ki-Washer
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{8D2AE3F6-79DF-423C-91CB-389F6FB5837B}" = Andrea VoiceCenter
"{990036E7-D647-45A4-8F7F-1CB277EF0ABD}" = RollerCoaster Tycoon 3 Demo
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AEEB3643-71DE-414d-9E3F-1159177FE211}" = Office Animation Runtime
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BA1E1AFD-D1F2-4C52-88C3-186FC5E61604}" = RollerCoaster Tycoon 2: Time Twister
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1" = ZipGenius 6 (6.3.1.2552)
"{ECA1A3B6-898F-4DCE-9F04-714CF3BA126B}" = Adobe Flash Player 10 Plugin
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"D-Fend Reloaded" = D-Fend Reloaded 0.9.3 (deinstall)
"DVDStyler_is1" = DVDStyler v1.7.3 rc 1
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"Excel" = Microsoft Excel 97
"GrabIt_is1" = GrabIt 1.7.2 Beta 4 (build 997)
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"InstallShield_{1632FD86-1BA4-4FC4-8B25-A8C655D63F68}" = Sid Meier's Pirates!
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PROSet" = Intel® PRO Network Connections Drivers
"PunchClock 2.40" = PunchClock 2.40
"RealPlayer 6.0" = RealPlayer Basic
"RollerCoaster Tycoon Setup" = Roll
"Sound Blaster Audigy ADVANCED MB Product Registration" = Sound Blaster Audigy ADVANCED MB Product Registration
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Word8.0" = Microsoft Word 97
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger
"ZMBV" = Zip Motion Block Video codec (Remove Only)
"Zoo Tycoon 1.0" = Microsoft Zoo Tycoon
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/21/2010 12:14:23 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 12:15:17 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 12:15:56 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 12:28:09 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 12:33:25 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 12:37:01 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 1:00:09 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 1:04:26 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 1:08:17 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 3/21/2010 1:09:11 AM | Computer Name = HOME | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 5/11/2011 3:33:52 AM | Computer Name = HOME | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 5/11/2011 3:33:56 AM | Computer Name = HOME | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 5/11/2011 3:34:00 AM | Computer Name = HOME | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 5/11/2011 3:34:03 AM | Computer Name = HOME | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 5/11/2011 3:34:09 AM | Computer Name = HOME | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.
Error - 5/22/2011 2:51:36 AM | Computer Name = HOME | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 5/22/2011 2:55:14 AM | Computer Name = HOME | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 5/22/2011 11:20:39 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Lavasoft Ad-Aware Service
service to connect.
Error - 5/22/2011 11:20:40 PM | Computer Name = HOME | Source = Service Control Manager | ID = 7000
Description = The Lavasoft Ad-Aware Service service failed to start due to the following
error: %%1053
Error - 5/25/2011 2:39:46 AM | Computer Name = HOME | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.102 for the Network Card with network
address 001372C51F84 has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
< End of report >