OTL logfile created on: 7/17/2011 11:10:29 PM - Run 2
OTL by OldTimer - Version 3.2.26.1 Folder = F:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.09 Gb Available Physical Memory | 54.69% Memory free
3.85 Gb Paging File | 3.10 Gb Available in Paging File | 80.63% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 145.85 Gb Total Space | 69.79 Gb Free Space | 47.85% Space Free | Partition Type: NTFS
Drive F: | 7.53 Gb Total Space | 0.26 Gb Free Space | 3.42% Space Free | Partition Type: FAT32
Computer Name: STEVENHOMEDESK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - F:\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (PCDSRVC{E9D79540-57D5953E-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LBeepKE) – C:\WINDOWS\system32\drivers\LBeepKE.sys (Logitech, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) – C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) – C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (RT61) Linksys Wireless-G PCI Adapter Driver(RT61) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (BCM42RLY) – C:\WINDOWS\system32\bcm42rly.sys (Broadcom Corporation)
DRV - (GTNDIS5) – C:\WINDOWS\system32\GTNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 06 8C 29 29 B6 41 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.losangelesgasprices.com/index.aspx?area=Bellflower"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3.1
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.652: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/07/11 12:01:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2011/05/25 12:30:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/13 12:41:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/07/01 21:47:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/03 11:12:00 | 000,000,000 | —D | M]
[2009/07/03 13:58:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/07/03 13:58:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\[removed]
[2011/03/24 12:23:02 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\extensions
[2010/10/08 00:50:03 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/02/20 21:03:43 | 000,001,739 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\searchplugins\aim-search.xml
[2009/02/19 00:13:10 | 000,001,632 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\searchplugins\live-search.xml
[2011/03/20 21:26:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/23 01:15:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/10 11:45:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/27 11:43:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
File not found (No name found) –
[2011/07/11 12:01:53 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX4
[2009/03/10 23:24:37 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/07/01 21:47:58 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/11/12 19:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/04/16 10:07:12 | 000,180,293 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2009/11/08 21:49:48 | 000,122,856 | —- | M] (NOS Microsystems Ltd.) – C:\Program Files\mozilla firefox\plugins\np_IEGetPlugin.dll
[2011/03/24 12:26:13 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/11/23 12:16:28 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2011/07/14 23:12:59 | 000,434,955 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14995 more lines…
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [PlayNC Launcher] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: motive.com ([pattta.att] https in Trusted sites)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B}
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (Reg Error: Key error.)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/25 13:08:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "C:\Documents and Settings\Owner\Local Settings\Application Data\alt.exe" -a "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Documents and Settings\Owner\Local Settings\Application Data\alt.exe" -a "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/07/07 13:24:50 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/06/21 15:10:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\assembly
[2011/06/21 15:09:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCsoft
[2011/06/21 15:09:32 | 000,000,000 | —D | C] – C:\Program Files\NCSoft
[2011/06/21 15:05:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\City of Heroes
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/07/17 23:14:02 | 000,000,432 | —- | M] () – C:\WINDOWS\tasks\SystemToolsDailyTest.job
[2011/07/17 22:50:12 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-115176313-1801674531-1003.job
[2011/07/17 22:50:11 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-854245398-115176313-1801674531-1003.job
[2011/07/17 22:35:29 | 000,185,856 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/17 21:52:44 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/17 21:36:31 | 122,622,350 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/07/17 21:32:09 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/07/17 12:32:16 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/07/16 08:35:50 | 000,001,408 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\671n8w107xhhsv
[2011/07/16 08:35:50 | 000,001,408 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\671n8w107xhhsv
[2011/07/15 15:55:56 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2011/07/14 23:12:59 | 000,434,955 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/07/14 23:08:19 | 000,000,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\World of Warcraft.lnk
[2011/07/13 16:36:26 | 000,227,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/07/12 22:39:13 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/07/08 15:38:43 | 000,050,459 | —- | M] () – C:\Documents and Settings\Owner\My Documents\PowerUpRewards Coupon.pdf
[2011/07/08 15:35:45 | 000,001,963 | —- | M] () – C:\Documents and Settings\Owner\Desktop\PowerUpRewards Coupon[1].prn
[2011/07/07 13:24:55 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/07/07 11:50:05 | 000,000,564 | —- | M] () – C:\WINDOWS\tasks\PCDoctorBackgroundMonitorTask.job
[2011/07/06 19:01:29 | 000,190,554 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/07/03 11:20:18 | 000,434,757 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20110714-231259.backup
[2011/06/27 15:35:27 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/06/23 13:52:06 | 000,001,132 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Back to the Future The Game.lnk
[2011/06/21 15:05:29 | 000,001,620 | —- | M] () – C:\Documents and Settings\Owner\Desktop\City of Heroes.lnk
[2011/06/21 12:16:25 | 000,001,924 | —- | M] () – C:\Documents and Settings\Owner\Desktop\IMVU.lnk
[2011/06/19 14:44:50 | 000,505,676 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/06/19 14:44:50 | 000,089,140 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/07/17 13:09:27 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/07/16 08:35:50 | 000,001,408 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\671n8w107xhhsv
[2011/07/16 08:35:50 | 000,001,408 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\671n8w107xhhsv
[2011/07/08 15:38:41 | 000,050,459 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PowerUpRewards Coupon.pdf
[2011/07/08 15:35:42 | 000,001,963 | —- | C] () – C:\Documents and Settings\Owner\Desktop\PowerUpRewards Coupon[1].prn
[2011/06/21 15:05:29 | 000,001,620 | —- | C] () – C:\Documents and Settings\Owner\Desktop\City of Heroes.lnk
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2011/03/03 14:45:49 | 000,338,960 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/18 23:20:17 | 000,243,962 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/02/16 19:53:49 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2011/02/16 19:53:49 | 000,203,331 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2011/02/16 19:53:49 | 000,000,003 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2011/01/12 21:49:25 | 000,041,984 | —- | C] () – C:\WINDOWS\System32\xd2.dll
[2010/08/26 15:10:54 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2010/08/26 15:09:59 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2010/03/20 00:46:19 | 000,758,018 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/03/20 00:46:19 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/12/16 19:21:46 | 000,083,456 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/21 00:49:39 | 000,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2009/09/06 18:12:15 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2009/09/04 01:48:27 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/07/04 22:45:27 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2009/06/27 17:52:42 | 000,002,828 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2009/06/27 17:52:42 | 000,000,088 | RHS- | C] () – C:\Documents and Settings\All Users\Application Data\BFB5F09187.sys
[2009/06/10 00:41:00 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2009/06/10 00:41:00 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2009/06/10 00:41:00 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/12/12 02:15:45 | 000,000,022 | —- | C] () – C:\WINDOWS\msnmsgr.exe.ini
[2008/12/10 22:52:52 | 000,004,096 | -H– | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\keyfile3.drm
[2008/11/28 21:26:10 | 000,185,856 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/11/27 20:59:19 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/11/27 00:34:08 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2008/11/27 00:29:00 | 000,117,091 | —- | C] () – C:\WINDOWS\hpoins11.dat.temp
[2008/11/27 00:29:00 | 000,011,634 | —- | C] () – C:\WINDOWS\hpomdl11.dat.temp
[2008/11/26 18:38:20 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2008/11/26 18:15:54 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/26 12:10:01 | 000,002,825 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/11/25 14:50:06 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\GTW32N50.dll
[2008/11/25 13:25:45 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2008/11/25 13:15:32 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/11/25 13:10:23 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/11/25 13:06:35 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2008/11/25 05:02:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/11/25 05:01:13 | 000,227,208 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/28 18:40:41 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/10/21 09:40:00 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2008/10/21 09:40:00 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2006/05/05 14:18:56 | 000,011,634 | —- | C] () – C:\WINDOWS\hpomdl11.dat
[2005/03/22 11:48:43 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005/03/22 11:48:43 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 03:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 03:00:00 | 000,505,676 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 03:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 03:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 03:00:00 | 000,089,140 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 03:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 03:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 03:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 03:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 03:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 04:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2009/02/20 20:09:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/12/03 00:23:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2010/11/30 14:44:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/18 12:56:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/18 13:07:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/16 19:28:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Last.fm
[2008/11/25 14:46:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2011/05/26 01:46:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2008/12/12 02:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008/11/27 15:04:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC-Doctor
[2011/05/25 12:57:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCDr
[2010/11/12 20:38:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2008/12/12 03:01:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pixelStorm
[2011/03/09 17:12:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Screentime
[2011/07/14 23:09:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/25 13:20:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/09/21 00:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/20 20:09:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2010/08/15 22:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2010/10/18 13:09:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG10
[2009/12/06 15:19:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG9
[2009/11/08 21:12:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Folding@home-gpu
[2009/02/14 01:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2008/12/14 20:05:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ieSpell
[2011/06/21 12:17:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IMVU
[2011/06/08 16:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\IMVUClient
[2010/01/22 23:32:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2008/11/27 18:09:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2011/03/03 14:38:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCDr
[2011/01/08 14:14:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment
[2010/11/13 11:15:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Tific
[2009/12/22 20:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Vivox
[2008/11/25 14:37:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2011/07/17 21:52:44 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/07/07 11:50:05 | 000,000,564 | —- | M] () – C:\WINDOWS\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/07/17 23:14:02 | 000,000,432 | —- | M] () – C:\WINDOWS\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/11/25 13:08:40 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/11/29 22:27:30 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/07/15 15:55:56 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/04 00:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2008/12/15 21:19:38 | 000,026,013 | —- | M] () – C:\ComboFix.txt
[2008/11/25 13:08:40 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/04/28 20:15:54 | 000,000,079 | —- | M] () – C:\ifsverifylog.txt
[2008/11/25 13:08:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/10 12:40:52 | 000,002,227 | -H– | M] () – C:\IPH.PH
[2010/05/03 13:12:47 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008/11/25 13:08:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/11/25 15:39:02 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/07/17 21:32:01 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/11/25 19:01:15 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/11/25 19:01:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/08/22 13:43:55 | 000,000,756 | —- | M] () – C:\updatedatfix.log
[2009/06/27 17:36:29 | 000,508,048 | —- | M] () – C:\vcredist_x86.log
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
[2006/02/19 04:28:56 | 000,012,288 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\WINDOWS\Fonts\RandFont.dll
< %systemroot%\Fonts\*.ini >
[2008/11/25 13:08:25 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 05:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 15:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 03:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2009/02/10 00:46:34 | 003,013,120 | —- | M] (KellySoftware) – C:\WINDOWS\Matrix_ks.SCR
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2009/01/21 16:50:21 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
[2011/07/16 08:37:01 | 000,005,632 | -HS- | M] () – C:\Program Files\Thumbs.db
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/11/25 05:00:32 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/11/25 05:00:32 | 000,634,880 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/11/25 05:00:32 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/11/25 15:43:28 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2011/07/17 12:43:52 | 000,008,192 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/11/25 13:12:06 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/11/25 13:12:06 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-07-13 05:44:06
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >