Hello Mowman. Thank you for helping me. Have to tell you I am not very computer savvy so please bear with me.
I am going to paste the OTL.TXT-notepad
OTL logfile created on: 9/10/2011 6:23:56 PM - Run 1
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Administrator\My Documents
64bit-Windows Server 2003 Service Pack 2 (Version = 5.2.3790) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.67 Gb Available Physical Memory | 66.71% Memory free
5.75 Gb Paging File | 4.73 Gb Available in Paging File | 82.26% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.75 Gb Total Space | 440.94 Gb Free Space | 94.67% Space Free | Partition Type: NTFS
Computer Name: JOHN-C0E22DEC35 | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\My Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Microsoft Works\wkssb.exe (Microsoft® Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (LBTServ) – C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:
64bit: - (ForceWare Intelligent Application Manager (IAM)) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
SRV:
64bit: - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (helpsvc) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) – C:\Program Files (x86)\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (mnmdd) – C:\WINDOWS\SysWow64\mnmdd.dll (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\..\URLSearchHook: {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:\Program Files (x86)\Softonic_English\prxtbSof0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/09/09 13:15:11 | 000,000,000 | —D | M]
Hosts file not found
O2:
64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Wisdom-soft toolbar) - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll (Conduit Ltd.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Softonic English Toolbar) - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:\Program Files (x86)\Softonic_English\prxtbSof0.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Wisdom-soft toolbar) - {6dfc55bb-bfff-485a-9709-90c3fdf6db58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Softonic English Toolbar) - {930f1200-f5f1-4870-bac6-e233ec8e7023} - C:\Program Files (x86)\Softonic_English\prxtbSof0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3:
64bit: - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - File not found
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - File not found
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Wisdom-soft toolbar) - {6DFC55BB-BFFF-485A-9709-90C3FDF6DB58} - C:\Program Files (x86)\Wisdom-soft\tbWisd.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Softonic English Toolbar) - {930F1200-F5F1-4870-BAC6-E233EC8E7023} - C:\Program Files (x86)\Softonic_English\prxtbSof0.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4:
64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [NvCplDaemon] File not found
O4:
64bit: - HKLM..\Run: [NvMediaCenter] File not found
O4:
64bit: - HKLM..\Run: [nwiz] File not found
O4:
64bit: - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Microsoft Works Portfolio] C:\Program Files (x86)\Microsoft Works\WksSb.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [Microsoft Works Update Detection] C:\Program Files (x86)\Microsoft Works\WkDetect.exe (Microsoft® Corporation)
O4 - HKLM..\Run: [RegWork] File not found
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [WorksFUD] C:\Program Files (x86)\Microsoft Works\wkfud.exe (Microsoft® Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:
64bit: - Extra context menu item: &Define - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM ()
O8:
64bit: - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM ()
O8 - Extra context menu item: &Define - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM ()
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM ()
O9:
64bit: - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9:
64bit: - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM ()
O9 - Extra 'Tools' menuitem : Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM ()
O9 - Extra Button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM ()
O9 - Extra 'Tools' menuitem : Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files (x86)\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\SysWOW64\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\SysWOW64\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\SysWOW64\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\SysWOW64\nvappfilter.dll (NVIDIA)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A}
https://h20364.www2.hp.com/CSMWeb/Customer/…DataManager.CAB (Hewlett-Packard Online Support Services)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D090BA0-9582-4210-8392-5C57BF72A6D7}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18:
64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - File not found
O18:
64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - File not found
O18:
64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - File not found
O18:
64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - File not found
O18:
64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - File not found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - File not found
O18:
64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - File not found
O18:
64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - File not found
O18:
64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - File not found
O18:
64bit: - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - File not found
O18:
64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - File not found
O18:
64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - File not found
O18:
64bit: - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O18:
64bit: - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - File not found
O18:
64bit: - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - File not found
O18:
64bit: - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - File not found
O18:
64bit: - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - File not found
O18:
64bit: - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - File not found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - File not found
O20:
64bit: - HKLM Winlogon: UIHost - (%SystemRoot%\system32\logonui.exe) - File not found
O20:
64bit: - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: System - (lsass.exe) - File not found
O20 - HKLM Winlogon: UserInit - (userinit) - C:\WINDOWS\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - File not found
O20:
64bit: - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - File not found
O20:
64bit: - Winlogon\Notify\cscdll: DllName - cscdll.dll - File not found
O20:
64bit: - Winlogon\Notify\dimsntfy: DllName - dimsntfy.dll - File not found
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20:
64bit: - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20:
64bit: - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20:
64bit: - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - File not found
O20:
64bit: - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20:
64bit: - Winlogon\Notify\termsrv: DllName - Reg Error: Key error. - File not found
O20:
64bit: - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - File not found
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - File not found
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - File not found
O21:
64bit: - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - File not found
O21:
64bit: - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - File not found
O21:
64bit: - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - File not found
O21:
64bit: - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - File not found
O22:
64bit: - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - File not found
O22:
64bit: - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Windows XP.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Windows XP.bmp
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/05/31 21:12:03 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{aa0d0677-8208-11dd-a6f0-001fc63b21d7}\Shell - "" = AutoRun
O33 - MountPoints2\{aa0d0677-8208-11dd-a6f0-001fc63b21d7}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{aa0d0677-8208-11dd-a6f0-001fc63b21d7}\Shell\AutoRun\command - "" = E:\StarterOfficeGuardian.exe
O33 - MountPoints2\{f8f6d769-2edb-11dd-8b61-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{f8f6d769-2edb-11dd-8b61-806e6f6e6963}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f8f6d769-2edb-11dd-8b61-806e6f6e6963}\Shell\AutoRun\command - "" = D:\.\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart) - C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe (AVG Technologies CZ, s.r.o.)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:
64bit: aux - File not found
Drivers32:
64bit: midi - File not found
Drivers32:
64bit: midimapper - File not found
Drivers32:
64bit: mixer - File not found
Drivers32:
64bit: msacm.imaadpcm - File not found
Drivers32:
64bit: msacm.msadpcm - File not found
Drivers32:
64bit: msacm.msg711 - File not found
Drivers32:
64bit: msacm.msgsm610 - File not found
Drivers32:
64bit: msacm.trspch - File not found
Drivers32:
64bit: vidc.i420 - File not found
Drivers32:
64bit: vidc.iv31 - File not found
Drivers32:
64bit: vidc.iv32 - File not found
Drivers32:
64bit: vidc.iv41 - File not found
Drivers32:
64bit: vidc.iv50 - File not found
Drivers32:
64bit: vidc.iyuv - File not found
Drivers32:
64bit: vidc.mrle - File not found
Drivers32:
64bit: vidc.msvc - File not found
Drivers32:
64bit: vidc.uyvy - File not found
Drivers32:
64bit: vidc.yuy2 - File not found
Drivers32:
64bit: vidc.yvu9 - File not found
Drivers32:
64bit: vidc.yvyu - File not found
Drivers32:
64bit: wave - File not found
Drivers32:
64bit: wavemapper - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\SysWow64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\SysWow64\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\SysWow64\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\SysWow64\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\SysWow64\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\SysWOW64\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/10 18:18:35 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\OTL.exe
[2011/09/10 18:15:40 | 001,916,416 | —- | C] (AVAST Software) – C:\Documents and Settings\Administrator\My Documents\aswMBR.exe
[2011/09/09 13:15:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\AVG2012
[2011/09/09 13:15:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG 2012
[2011/09/09 13:15:07 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\AVG Secure Search
[2011/09/09 13:15:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/09/09 13:15:04 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/09/09 13:14:59 | 000,000,000 | —D | C] – C:\WINDOWS\SysWow64\drivers\AVG
[2011/09/09 13:14:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/09/09 08:43:12 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Recent
[2011/09/09 07:30:27 | 000,000,000 | —D | C] – C:\!KillBox
[2011/09/09 01:25:23 | 000,000,000 | —D | C] – C:\VIPRERESCUE
[2011/09/08 23:31:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2011/09/08 23:31:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/09/08 23:17:55 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/09/08 23:17:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/09/08 21:41:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData(2)
[2011/09/08 21:41:35 | 003,894,928 | —- | C] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_avct_stb_all_2012_1796.exe
[2011/09/08 18:08:55 | 003,894,928 | —- | C] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stb_all_2012_1796_cnet.exe
[3 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/10 18:18:42 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\OTL.exe
[2011/09/10 18:17:32 | 000,000,512 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\MBR.dat
[2011/09/10 18:15:59 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\My Documents\aswMBR.exe
[2011/09/10 17:03:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/09 21:09:46 | 000,000,334 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\PhotoshopForums.com - General Photoshop and Design Discussion.url
[2011/09/09 21:07:21 | 000,000,235 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Inside Outlook Express - Errors, Bugs and Problems.url
[2011/09/09 20:53:42 | 000,000,287 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Need help.url
[2011/09/09 16:27:47 | 000,000,939 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Image hosting, free photo sharing & video sharing at Photobucket.url
[2011/09/09 13:15:11 | 000,000,775 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/09/09 13:14:59 | 000,000,000 | —- | M] () – C:\WINDOWS\SysWow64\drivers\AVG\incavi.avm
[2011/09/09 13:14:59 | 000,000,000 | —- | M] () – C:\WINDOWS\SysWow64\drivers\AVG\iavifw.avm
[2011/09/09 13:14:59 | 000,000,000 | —- | M] () – C:\WINDOWS\SysWow64\drivers\AVG\iavichjw.avm
[2011/09/08 23:00:00 | 000,000,354 | —- | M] () – C:\WINDOWS\tasks\Regwork.job
[2011/09/08 22:40:37 | 134,225,920 | —- | M] () – C:\WINDOWS\sectest.db
[2011/09/08 22:34:55 | 000,000,134 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Microsoft Fix it.url
[2011/09/08 21:41:43 | 003,894,928 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_avct_stb_all_2012_1796.exe
[2011/09/08 20:44:44 | 003,894,928 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stb_all_2012_1796_cnet.exe
[2011/09/06 22:04:29 | 000,000,292 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Sylvane - Better Air Begins with Knowledge.url
[2011/09/06 22:00:44 | 000,000,327 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Danby Dehumidifier DDR7009REE - Danby Dehumidifier - Room Dehumidifier - AchooAllergy.com.url
[2011/09/03 17:19:08 | 000,000,262 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\WoodworkersZone - Woodworking Forums.url
[2011/09/01 21:07:06 | 000,000,251 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\MLB Baseball Scores - MLB Scoreboard - ESPN (2).url
[2011/08/30 17:29:33 | 000,003,302 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\My eBay Summary.url
[2011/08/27 18:09:34 | 000,000,180 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Punches.url
[2011/08/27 18:05:49 | 000,000,680 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Amazon.com Diamond Shape Punch Stamp For Blanks 1-4 6mm (1) Arts, Crafts & Sewing.url
[2011/08/27 18:04:20 | 000,000,208 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Hand Punches, Punch Card and Hand Metal Punches, Slot - Badge - ID.url
[2011/08/27 09:32:27 | 000,000,280 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Deco Mesh Products.url
[2011/08/27 09:30:03 | 000,000,294 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Mardi Gras Outlet Deco Flex Tubing.url
[2011/08/27 09:23:25 | 000,000,272 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Deco Flex Tubing Ribbon Metallic Blue (30 Yards).url
[2011/08/27 09:21:08 | 000,000,746 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Emerald Green Deco Flex Tubing Metallic Ribbon 30 yds RE300457.url
[2011/08/25 14:56:05 | 000,000,305 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Order Copper 101 Tube in Small Quantities at OnlineMetals.com.url
[2011/08/20 16:58:47 | 000,000,334 | —- | M] () – C:\Documents and Settings\Administrator\Desktop\Clarity D603 DECT 6.0 Ampllfied Cordless Phone.url
[2011/08/20 16:10:10 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2011/08/13 15:30:10 | 000,011,169 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\Mom's Money Account #1.odt
[2011/08/12 12:16:34 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\SysWow64\FlashPlayerCPLApp.cpl
[3 C:\WINDOWS\SysWow64\*.tmp files -> C:\WINDOWS\SysWow64\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/10 18:17:32 | 000,000,512 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\MBR.dat
[2011/09/09 20:53:42 | 000,000,287 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Need help.url
[2011/09/09 13:15:11 | 000,000,775 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/09/09 13:14:59 | 000,000,000 | —- | C] () – C:\WINDOWS\SysWow64\drivers\AVG\incavi.avm
[2011/09/09 13:14:59 | 000,000,000 | —- | C] () – C:\WINDOWS\SysWow64\drivers\AVG\iavifw.avm
[2011/09/09 13:14:59 | 000,000,000 | —- | C] () – C:\WINDOWS\SysWow64\drivers\AVG\iavichjw.avm
[2011/09/08 22:39:03 | 134,225,920 | —- | C] () – C:\WINDOWS\sectest.db
[2011/09/08 22:20:57 | 000,000,134 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Microsoft Fix it.url
[2011/09/06 22:04:29 | 000,000,292 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Sylvane - Better Air Begins with Knowledge.url
[2011/09/06 22:00:44 | 000,000,327 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Danby Dehumidifier DDR7009REE - Danby Dehumidifier - Room Dehumidifier - AchooAllergy.com.url
[2011/08/27 18:09:34 | 000,000,180 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Punches.url
[2011/08/27 18:05:49 | 000,000,680 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Amazon.com Diamond Shape Punch Stamp For Blanks 1-4 6mm (1) Arts, Crafts & Sewing.url
[2011/08/27 18:04:20 | 000,000,208 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Hand Punches, Punch Card and Hand Metal Punches, Slot - Badge - ID.url
[2011/08/27 09:32:27 | 000,000,280 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Deco Mesh Products.url
[2011/08/27 09:30:03 | 000,000,294 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Mardi Gras Outlet Deco Flex Tubing.url
[2011/08/27 09:23:25 | 000,000,272 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Deco Flex Tubing Ribbon Metallic Blue (30 Yards).url
[2011/08/27 09:21:08 | 000,000,746 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Emerald Green Deco Flex Tubing Metallic Ribbon 30 yds RE300457.url
[2011/08/25 14:56:05 | 000,000,305 | —- | C] () – C:\Documents and Settings\Administrator\Desktop\Order Copper 101 Tube in Small Quantities at OnlineMetals.com.url
[2011/08/13 15:26:55 | 000,011,169 | —- | C] () – C:\Documents and Settings\Administrator\My Documents\Mom's Money Account #1.odt
[2011/05/13 23:28:36 | 000,000,760 | —- | C] () – C:\Documents and Settings\Administrator\Application Data\setup_ldm.iss
[2009/04/13 13:11:20 | 000,164,570 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2009/04/13 13:11:20 | 000,007,262 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2008/05/31 23:25:03 | 000,015,625 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/05/31 21:30:56 | 000,024,576 | R— | C] () – C:\WINDOWS\SysWow64\AsIO.dll
[2008/05/31 21:30:56 | 000,013,632 | R— | C] () – C:\WINDOWS\SysWow64\drivers\AsIO.sys
[2008/05/31 21:29:24 | 000,049,152 | R— | C] () – C:\WINDOWS\SysWow64\ChCfg.exe
[2008/05/31 21:28:47 | 000,037,376 | R— | C] () – C:\WINDOWS\CPLUtl64.exe
[2008/05/31 21:24:38 | 000,015,859 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2008/05/31 21:24:02 | 000,012,536 | —- | C] () – C:\WINDOWS\SysWow64\drivers\ASUSHWIO.SYS
[2008/05/31 21:17:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2008/05/31 04:56:00 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\SysWow64\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\SysWow64\nvwimg.dll
[2008/01/14 16:47:06 | 000,099,712 | —- | C] () – C:\WINDOWS\HPBroker.dll
[2007/02/18 08:00:00 | 001,278,464 | —- | C] () – C:\WINDOWS\SysWow64\quartz.dll
[2007/02/18 08:00:00 | 000,733,696 | —- | C] () – C:\WINDOWS\SysWow64\qedwipes.dll
[2007/02/18 08:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\SysWow64\mlang.dat
[2007/02/18 08:00:00 | 000,512,512 | —- | C] () – C:\WINDOWS\SysWow64\qedit.dll
[2007/02/18 08:00:00 | 000,498,742 | —- | C] () – C:\WINDOWS\SysWow64\dxmasf.dll
[2007/02/18 08:00:00 | 000,396,288 | —- | C] () – C:\WINDOWS\SysWow64\encdec.dll
[2007/02/18 08:00:00 | 000,385,536 | —- | C] () – C:\WINDOWS\SysWow64\qdvd.dll
[2007/02/18 08:00:00 | 000,355,112 | —- | C] () – C:\WINDOWS\SysWow64\msjetoledb40.dll
[2007/02/18 08:00:00 | 000,279,040 | —- | C] () – C:\WINDOWS\SysWow64\qdv.dll
[2007/02/18 08:00:00 | 000,276,992 | —- | C] () – C:\WINDOWS\SysWow64\sbe.dll
[2007/02/18 08:00:00 | 000,199,168 | —- | C] () – C:\WINDOWS\SysWow64\ir32_32.dll
[2007/02/18 08:00:00 | 000,192,512 | —- | C] () – C:\WINDOWS\SysWow64\qcap.dll
[2007/02/18 08:00:00 | 000,114,688 | —- | C] () – C:\WINDOWS\SysWow64\msencode.dll
[2007/02/18 08:00:00 | 000,072,704 | —- | C] () – C:\WINDOWS\SysWow64\amstream.dll
[2007/02/18 08:00:00 | 000,062,464 | —- | C] () – C:\WINDOWS\SysWow64\mciqtz32.dll
[2007/02/18 08:00:00 | 000,061,440 | —- | C] () – C:\WINDOWS\SysWow64\devenum.dll
[2007/02/18 08:00:00 | 000,055,808 | —- | C] () – C:\WINDOWS\SysWow64\dvdplay.exe
[2007/02/18 08:00:00 | 000,046,907 | —- | C] () – C:\WINDOWS\mib.bin
[2007/02/18 08:00:00 | 000,016,896 | —- | C] () – C:\WINDOWS\SysWow64\tsd32.dll
[2007/02/18 08:00:00 | 000,014,336 | —- | C] () – C:\WINDOWS\SysWow64\msdmo.dll
[2007/02/18 08:00:00 | 000,012,498 | —- | C] () – C:\WINDOWS\SysWow64\append.exe
[2007/02/18 08:00:00 | 000,004,126 | —- | C] () – C:\WINDOWS\SysWow64\msdxmlc.dll
[2007/02/18 08:00:00 | 000,001,129 | —- | C] () – C:\WINDOWS\SysWow64\vwipxspx.exe
[2005/08/26 14:28:34 | 000,143,360 | —- | C] () – C:\WINDOWS\unzip.exe
[2005/08/26 14:28:20 | 000,024,576 | —- | C] () – C:\WINDOWS\shortcut.exe
[2005/08/26 14:27:58 | 000,045,056 | —- | C] () – C:\WINDOWS\devenum.exe
[2000/07/07 17:49:30 | 000,069,120 | —- | C] () – C:\WINDOWS\SysWow64\LTDLL.DLL
[2000/03/25 22:00:00 | 000,030,208 | —- | C] () – C:\WINDOWS\SysWow64\clcd32.dll
[1999/09/20 16:43:10 | 000,006,784 | —- | C] () – C:\WINDOWS\SysWow64\clcd16.dll
========== LOP Check ==========
[2011/09/09 13:15:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AVG Secure Search
[2010/10/03 05:35:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AVG10
[2011/09/09 13:15:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\AVG2012
[2008/08/09 11:30:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/05/13 23:02:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\gtk-2.0
[2009/01/14 16:15:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2009/04/29 10:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\OpenOffice.org
[2011/09/10 18:18:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\PriceGong
[2009/01/14 16:15:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Runaware
[2010/09/23 12:51:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Template
[2011/09/08 23:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG10
[2011/09/09 16:02:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/09/08 21:31:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/10/03 05:35:16 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/09/09 13:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/09/08 23:17:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData(2)
[2011/02/03 09:16:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegWork
[2011/09/08 23:00:00 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\Regwork.job
[2011/09/09 21:14:22 | 000,032,576 | —- | M] () – C:\WINDOWS\Tasks\SchedLgU.Txt
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/05/31 21:12:03 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/05/31 21:04:49 | 000,000,213 | -HS- | M] () – C:\boot.ini
[2008/05/31 21:12:03 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/05/31 21:12:03 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/09/23 00:39:38 | 000,894,976 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2008/05/31 21:12:03 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/02/18 08:00:00 | 000,047,772 | RHS- | M] () – C:\NTDETECT.COM
[2007/02/18 08:00:00 | 000,297,072 | RHS- | M] () – C:\ntldr
[2011/09/10 17:02:45 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2008/05/31 21:29:26 | 000,000,563 | —- | M] () – C:\RHDSetup.log
[2011/09/08 22:13:49 | 000,035,614 | —- | M] () – C:\TDSSKiller.2.5.18.0_08.09.2011_22.13.24_log.txt
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/05/31 21:11:37 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/02/18 08:00:00 | 000,000,002 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/05/31 21:12:10 | 000,000,290 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2008/05/31 21:19:48 | 000,000,117 | -HS- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/05/31 21:19:47 | 000,000,079 | —- | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2009/04/13 13:10:17 | 208,082,712 | —- | M] () – C:\Documents and Settings\Administrator\My Documents\100_228_PS_AIO_02_Full_Net_enu.exe
[2011/09/10 18:15:59 | 001,916,416 | —- | M] (AVAST Software) – C:\Documents and Settings\Administrator\My Documents\aswMBR.exe
[2011/09/08 21:41:43 | 003,894,928 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_avct_stb_all_2012_1796.exe
[2011/09/08 20:44:44 | 003,894,928 | —- | M] (AVG Technologies) – C:\Documents and Settings\Administrator\My Documents\avg_free_stb_all_2012_1796_cnet.exe
[2010/03/24 00:08:28 | 038,874,608 | —- | M] (Google) – C:\Documents and Settings\Administrator\My Documents\GoogleSketchUpWEN.exe
[2011/09/10 18:18:42 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Administrator\My Documents\OTL.exe
< %USERPROFILE%\*.exe >
[2008/07/24 00:02:18 | 035,124,856 | —- | M] ( ) – C:\Documents and Settings\Administrator\AdbeRdr90_en_US.exe
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2008/05/31 21:19:47 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Administrator\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/09/10 18:18:24 | 000,065,536 | -HS- | M] () – C:\Documents and Settings\Administrator\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >