karamazov
Topic Starter
Lately the computer has slowed down to an almost crawl, and the internet has been intermittently going off and on. Also been sending bogus emails
OTL logfile created on: 9/18/2011 11:14:06 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 70.02% Memory free
3.85 Gb Paging File | 3.35 Gb Available in Paging File | 87.03% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.13 Gb Total Space | 1.79 Gb Free Space | 12.68% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 34.53 Gb Free Space | 35.36% Space Free | Partition Type: NTFS
Drive F: | 3.75 Gb Total Space | 3.75 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Computer Name: DANIEL-65C6EC9E | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - D:\Program Files\Trillian\trillian.exe (Cerulean Studios)
PRC - D:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealUpgrade\realupgrade.exe (RealNetworks, Inc.)
PRC - D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - D:\Program Files\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - D:\Program Files\Trillian\libspeex.dll ()
MOD - D:\Program Files\Trillian\libungif.dll ()
MOD - D:\Program Files\Trillian\zlib1.dll ()
MOD - d:\Program Files\Trillian\languages\en\buddy.dll ()
MOD - d:\Program Files\Trillian\languages\en\talk.dll ()
MOD - d:\Program Files\Trillian\languages\en\trillian.dll ()
MOD - d:\Program Files\Trillian\languages\en\events.dll ()
MOD - d:\Program Files\Trillian\languages\en\toolkit.dll ()
MOD - D:\Program Files\Orbitdownloader\wtlctrl.dll ()
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - C:\WINDOWS\system32\dxmasf.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (avgwd) – D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (StarWindServiceAE) – d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
========== Driver Services (SafeList) ==========
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\SHP5211.sys (Atheros Communications, Inc.)
DRV - (MLPTDR_C) – C:\WINDOWS\system32\MLPTDR_C.SYS (Minolta Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "http://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: d:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: d:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: D:\Program Files\AVG\AVG2012\Firefox4\ [2011/09/15 12:05:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/05 21:51:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/09/07 02:14:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins
[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions
[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions\[removed]
[2011/09/13 23:34:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions
[2011/09/06 23:23:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/05 21:43:54 | 000,003,739 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\searchplugins\avg-secure-search.xml
[2011/09/05 21:32:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 12:57:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/09/05 21:46:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/15 12:05:00 | 000,000,000 | —D | M] (AVG Safe Search) – D:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/05/23 12:57:22 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = d:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\
O1 HOSTS File: ([2011/09/15 12:00:08 | 000,436,898 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15053 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG_TRAY] D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] d:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1278997763765 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADA77DDB-645F-48A0-BD3F-DC5769D52C0C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\video/x-flv - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/09 16:04:31 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (D:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/18 23:11:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:10:52 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/15 22:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\FACEBOOK!
[2011/09/15 16:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/15 16:05:23 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/15 12:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Start Menu\Programs\Google Chrome
[2011/09/15 12:01:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google
[2011/09/13 23:34:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Orbit
[2011/09/05 21:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Spybot - Search & Destroy
[2011/09/05 21:51:20 | 000,198,832 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:51:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Real
[2011/09/05 21:47:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/09/05 21:46:33 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:33 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:44:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/09/05 21:43:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\AVG 2012
[2011/09/05 21:43:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2011/08/29 15:58:26 | 000,000,000 | —D | C] – C:\Program Files\Compaq
[2011/08/29 15:58:20 | 000,000,000 | —D | C] – C:\CPQSYSTEM
[2004/11/24 14:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/18 23:14:06 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:14:06 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/18 23:11:46 | 000,625,664 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:06:00 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/18 18:02:26 | 104,554,326 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/09/18 17:04:30 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/18 12:06:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/18 11:05:34 | 000,000,656 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/18 11:05:12 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/09/18 11:02:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/17 14:07:32 | 000,002,411 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/17 14:07:32 | 000,002,389 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 16:05:27 | 000,000,670 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:05:00 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/09/15 12:00:08 | 000,436,898 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/09/14 13:40:26 | 000,224,256 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/13 23:34:18 | 000,000,628 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/10 00:41:45 | 000,000,596 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/05 21:57:34 | 000,436,472 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20110915-120008.backup
[2011/09/05 21:51:38 | 000,000,929 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:51:20 | 000,198,832 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:48:47 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:46:20 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/09/05 21:46:20 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:20 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/18 23:11:15 | 000,625,664 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/15 16:05:27 | 000,000,670 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:02:34 | 000,002,411 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/15 12:02:34 | 000,002,389 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 12:01:07 | 000,001,014 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/15 12:01:06 | 000,000,962 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/10 00:41:45 | 000,000,596 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/06 23:15:20 | 000,000,656 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/05 21:54:38 | 000,000,628 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/05 21:51:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:51 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:38 | 000,000,929 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:48:47 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Reader X.lnk
[2011/09/05 21:48:47 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/09/05 21:43:26 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\vvgo2823x2r50oejm
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\vvgo2823x2r50oejm
[2010/07/12 13:54:24 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/07/12 13:54:22 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/07/12 13:54:22 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/07/09 13:32:43 | 002,292,678 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/05/02 09:09:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/18 14:19:05 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/18 14:19:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/18 14:19:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/18 14:19:05 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/18 14:19:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/17 17:35:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\housecall.guid.cache
[2009/12/19 10:39:00 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/08 12:47:02 | 000,025,964 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PnkBstrK.sys
[2009/06/28 15:21:14 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/06/28 15:21:14 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/06/28 15:21:12 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2009/06/22 13:36:15 | 000,002,528 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\$_hpcst$.hpc
[2009/05/13 02:27:58 | 000,004,914 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/05/05 19:26:14 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/05/05 12:21:23 | 000,224,256 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/03 21:06:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/05/03 19:45:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/05/03 19:41:05 | 000,022,720 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/05/03 14:35:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/05/03 14:33:21 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/04 18:31:29 | 000,180,224 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/12/19 10:15:58 | 004,338,246 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 12:41:18 | 000,884,237 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 12:22:58 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 12:22:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 12:17:34 | 000,239,247 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 11:59:54 | 000,560,802 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/08/09 16:04:08 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2006/11/02 11:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2005/06/20 10:31:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/06/20 10:31:34 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2004/10/03 12:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 01:07:22 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/17 11:36:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/10 14:09:52 | 000,021,282 | —- | C] () – C:\WINDOWS\MSTMON_C.INI
[2002/09/03 21:38:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MCMM___C.DLL
[2002/09/03 17:38:04 | 000,010,242 | —- | C] () – C:\WINDOWS\MSUMLT_C.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/09/05 21:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG10
[2011/09/05 22:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2009/05/03 21:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/10/06 16:18:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2011/09/18 18:02:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2011/09/02 21:43:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2009/08/09 11:48:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/06/27 15:48:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/03 13:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/07/13 14:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Auslogics
[2010/10/06 16:19:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG10
[2011/09/05 21:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/07/13 13:56:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Azureus
[2011/05/05 12:16:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\FrostWire
[2009/12/08 14:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GetRightToGo
[2010/04/17 15:27:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GrabPro
[2011/06/01 14:26:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\MechCAD
[2010/08/15 22:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\OpenCandy
[2011/09/18 11:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Orbit
[2011/05/26 12:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong
[2010/08/15 22:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\ProgSense
[2009/08/25 17:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Trillian
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/05/02 13:46:57 | 000,010,524 | —- | M] () – C:\aaw7boot.log
[2008/09/02 18:12:28 | 000,000,645 | —- | M] () – C:\Active SMART.lnk
[2009/02/25 22:05:49 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2009/05/06 00:59:40 | 000,000,487 | -HS- | M] () – C:\Boot.bak
[2011/07/14 05:00:52 | 000,000,440 | -HS- | M] () – C:\boot.ini
[2009/05/06 01:54:32 | 000,000,580 | RHS- | M] () – C:\Boot.ini.saved
[2009/04/22 00:28:23 | 000,383,200 | RHS- | M] () – C:\bootmgr
[2009/05/06 01:54:33 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/23 22:48:47 | 000,009,428 | —- | M] () – C:\ComboFix.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2008/03/29 04:54:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/30 18:52:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/03 21:22:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[1993/02/20 12:49:52 | 000,000,030 | —- | M] () – C:\readme.bat
[2010/04/18 14:12:45 | 000,000,387 | —- | M] () – C:\rkill.log
[2009/12/06 20:11:35 | 000,002,870 | —- | M] () – C:\RootRepeal report 12-06-09 (19-11-35).txt
[2009/05/03 13:07:45 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/03 13:23:21 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/03 13:28:05 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/05/03 14:23:03 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/05/03 17:23:38 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/05/03 18:28:06 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/29 11:51:11 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/04/29 21:49:31 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/04/30 16:07:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/04/30 16:36:05 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/04/30 17:19:43 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/05/01 15:39:25 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/05/02 13:39:29 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/05/02 13:40:22 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/05/02 13:40:38 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/05/02 14:11:14 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/05/02 14:43:31 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/05/02 15:11:06 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/05/02 15:23:57 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/05/03 02:10:55 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/03 13:07:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/03 13:23:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/03 13:28:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/05/03 14:23:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/05/03 17:23:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/05/03 18:28:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/29 11:51:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/04/29 21:49:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/04/30 16:07:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/04/30 16:36:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/04/30 17:19:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/05/01 15:39:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/05/02 13:39:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/05/02 13:40:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/05/02 13:40:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/05/02 14:11:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/05/02 14:43:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/05/02 15:11:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/05/02 15:23:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/05/03 02:10:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/07/12 13:27:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/09/03 18:19:44 | 000,009,728 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_C.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/08/09 16:04:08 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2007/08/09 16:04:08 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/07/12 07:51:07 | 004,718,592 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/07/12 01:54:06 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2010/07/12 07:51:07 | 028,311,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/07/12 07:51:07 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/12 13:27:58 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 21:30:13 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/03 19:48:35 | 000,000,079 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/10/11 21:15:27 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\ATF-Cleaner.exe
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-19 05:49:48
< End of report >
OTL logfile created on: 9/18/2011 11:14:06 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 70.02% Memory free
3.85 Gb Paging File | 3.35 Gb Available in Paging File | 87.03% Paging File free
Paging file location(s): D:\pagefile.sys 2046 4092C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.13 Gb Total Space | 1.79 Gb Free Space | 12.68% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 34.53 Gb Free Space | 35.36% Space Free | Partition Type: NTFS
Drive F: | 3.75 Gb Total Space | 3.75 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Computer Name: DANIEL-65C6EC9E | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - D:\Program Files\Trillian\trillian.exe (Cerulean Studios)
PRC - D:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealUpgrade\realupgrade.exe (RealNetworks, Inc.)
PRC - D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - D:\Program Files\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\WINDOWS\system32\acs.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - D:\Program Files\Trillian\libspeex.dll ()
MOD - D:\Program Files\Trillian\libungif.dll ()
MOD - D:\Program Files\Trillian\zlib1.dll ()
MOD - d:\Program Files\Trillian\languages\en\buddy.dll ()
MOD - d:\Program Files\Trillian\languages\en\talk.dll ()
MOD - d:\Program Files\Trillian\languages\en\trillian.dll ()
MOD - d:\Program Files\Trillian\languages\en\events.dll ()
MOD - d:\Program Files\Trillian\languages\en\toolkit.dll ()
MOD - D:\Program Files\Orbitdownloader\wtlctrl.dll ()
MOD - C:\WINDOWS\system32\acs.exe ()
MOD - C:\WINDOWS\system32\dxmasf.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (avgwd) – D:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (StarWindServiceAE) – d:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (ACS) – C:\WINDOWS\system32\acs.exe ()
========== Driver Services (SafeList) ==========
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (libusb0) – C:\WINDOWS\system32\drivers\libusb0.sys (http://libusb-win32.sourceforge.net)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\SHP5211.sys (Atheros Communications, Inc.)
DRV - (MLPTDR_C) – C:\WINDOWS\system32\MLPTDR_C.SYS (Minolta Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.orbitdownloader.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.startup.homepage: "http://search.orbitdownloader.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: d:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: d:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Motive, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.666: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.666: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: D:\Program Files\AVG\AVG2012\Firefox4\ [2011/09/15 12:05:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/05 21:51:26 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2011/09/07 02:14:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins
[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions
[2009/07/12 12:09:10 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Extensions\[removed]
[2011/09/13 23:34:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions
[2011/09/06 23:23:28 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/05 21:43:54 | 000,003,739 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Mozilla\Firefox\Profiles\3czfsacu.default\searchplugins\avg-secure-search.xml
[2011/09/05 21:32:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 12:57:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/09/05 21:46:20 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/09/15 12:05:00 | 000,000,000 | —D | M] (AVG Safe Search) – D:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
[2010/05/23 12:57:22 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U27 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = d:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\Application\14.0.835.163\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\plugins/avgnpss.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files\Common Files\Motive\npMotive.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\
O1 HOSTS File: ([2011/09/15 12:00:08 | 000,436,898 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15053 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG_TRAY] D:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AlcoholAutomount] d:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download; by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - d:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/D/0…D0C/wmv9dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1278997763765 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ADA77DDB-645F-48A0-BD3F-DC5769D52C0C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\video/x-flv - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/09 16:04:31 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (D:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - ac3filter.acm File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ffdshow.ax ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/09/18 23:11:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:10:52 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/15 22:47:33 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\FACEBOOK!
[2011/09/15 16:05:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/09/15 16:05:23 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/09/15 12:02:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Start Menu\Programs\Google Chrome
[2011/09/15 12:01:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\Google
[2011/09/13 23:34:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Orbit
[2011/09/05 21:56:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Spybot - Search & Destroy
[2011/09/05 21:51:20 | 000,198,832 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:51:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Real
[2011/09/05 21:47:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/09/05 21:46:33 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:33 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:33 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:44:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/09/05 21:43:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\AVG 2012
[2011/09/05 21:43:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2011/08/29 15:58:26 | 000,000,000 | —D | C] – C:\Program Files\Compaq
[2011/08/29 15:58:20 | 000,000,000 | —D | C] – C:\CPQSYSTEM
[2004/11/24 14:25:52 | 000,335,872 | —- | C] ( ) – C:\WINDOWS\System32\drvc.dll
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/18 23:14:06 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:14:06 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
[2011/09/18 23:11:46 | 000,625,664 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:06:00 | 000,001,014 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/18 18:02:26 | 104,554,326 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/09/18 17:04:30 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/09/18 12:06:00 | 000,000,962 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/18 11:05:34 | 000,000,656 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/18 11:05:12 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2011/09/18 11:02:45 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/09/17 14:07:32 | 000,002,411 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/17 14:07:32 | 000,002,389 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 16:05:27 | 000,000,670 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:05:00 | 000,000,616 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/09/15 12:00:08 | 000,436,898 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/09/14 13:40:26 | 000,224,256 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/13 23:34:18 | 000,000,628 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/10 00:41:45 | 000,000,596 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/05 21:57:34 | 000,436,472 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20110915-120008.backup
[2011/09/05 21:51:38 | 000,000,929 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:51:20 | 000,198,832 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/09/05 21:51:15 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/09/05 21:51:15 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/09/05 21:51:15 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/09/05 21:48:47 | 000,001,734 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:46:20 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/09/05 21:46:20 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/09/05 21:46:20 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/09/05 21:46:20 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/08/31 17:00:50 | 000,022,216 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/18 23:11:15 | 000,625,664 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\dds.scr
[2011/09/15 16:05:27 | 000,000,670 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/09/15 12:02:34 | 000,002,411 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Google Chrome.lnk
[2011/09/15 12:02:34 | 000,002,389 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/15 12:01:07 | 000,001,014 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003UA.job
[2011/09/15 12:01:06 | 000,000,962 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-746137067-839522115-1003Core.job
[2011/09/10 00:41:45 | 000,000,596 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\Shortcut to trillian.exe.lnk
[2011/09/06 23:15:20 | 000,000,656 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Orbit.lnk
[2011/09/05 21:54:38 | 000,000,628 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Orbit.lnk
[2011/09/05 21:51:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:51 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-746137067-839522115-1003.job
[2011/09/05 21:51:38 | 000,000,929 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\RealPlayer.lnk
[2011/09/05 21:48:47 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Adobe Reader X.lnk
[2011/09/05 21:48:47 | 000,001,734 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Adobe Reader X.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Mozilla Firefox.lnk
[2011/09/05 21:45:05 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2011/09/05 21:43:26 | 000,000,616 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\AVG 2012.lnk
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\vvgo2823x2r50oejm
[2011/07/15 13:56:08 | 000,001,088 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS\Application Data\vvgo2823x2r50oejm
[2010/07/12 13:54:24 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/07/12 13:54:22 | 000,252,836 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/07/12 13:54:22 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/07/09 13:32:43 | 002,292,678 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2010/05/02 09:09:14 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2010/04/18 14:19:05 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/18 14:19:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/18 14:19:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/18 14:19:05 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/18 14:19:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/17 17:35:31 | 000,000,036 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\housecall.guid.cache
[2009/12/19 10:39:00 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/10/08 12:47:02 | 000,025,964 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/28 15:21:30 | 000,022,328 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PnkBstrK.sys
[2009/06/28 15:21:14 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/06/28 15:21:14 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2009/06/28 15:21:12 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2009/06/22 13:36:15 | 000,002,528 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\$_hpcst$.hpc
[2009/05/13 02:27:58 | 000,004,914 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/05/05 19:26:14 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/05/05 12:21:23 | 000,224,256 | —- | C] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/03 21:06:03 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2009/05/03 19:45:43 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/05/03 19:41:05 | 000,022,720 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2009/05/03 14:35:43 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/05/03 14:33:21 | 000,138,848 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/04 18:31:29 | 000,180,224 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2008/12/19 10:15:58 | 004,338,246 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 12:41:18 | 000,884,237 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 12:22:58 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 12:22:48 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 12:17:34 | 000,239,247 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 11:59:54 | 000,560,802 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2007/08/09 16:04:08 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2006/11/02 11:10:16 | 000,080,912 | —- | C] () – C:\WINDOWS\System32\sherlock2.exe
[2005/06/20 10:31:34 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\AegisI5.exe
[2005/06/20 10:31:34 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\acs.exe
[2004/10/03 12:50:54 | 000,129,024 | —- | C] () – C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 01:07:22 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2004/08/02 14:20:40 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/07/17 11:36:38 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/10 14:09:52 | 000,021,282 | —- | C] () – C:\WINDOWS\MSTMON_C.INI
[2002/09/03 21:38:42 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\MCMM___C.DLL
[2002/09/03 17:38:04 | 000,010,242 | —- | C] () – C:\WINDOWS\MSUMLT_C.INI
[2001/08/23 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 07:00:00 | 000,311,934 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 07:00:00 | 000,040,196 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 07:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/09/05 21:39:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG10
[2011/09/05 22:58:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\AVG2012
[2009/05/03 21:49:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2010/10/06 16:18:13 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Common Files
[2011/09/18 18:02:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\MFAData
[2011/09/02 21:43:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
[2009/08/09 11:48:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/06/27 15:48:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/03 13:57:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/07/13 14:15:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Auslogics
[2010/10/06 16:19:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG10
[2011/09/05 21:44:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\AVG2012
[2011/07/13 13:56:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Azureus
[2011/05/05 12:16:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\FrostWire
[2009/12/08 14:29:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GetRightToGo
[2010/04/17 15:27:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\GrabPro
[2011/06/01 14:26:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\MechCAD
[2010/08/15 22:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\OpenCandy
[2011/09/18 11:06:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Orbit
[2011/05/26 12:50:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\PriceGong
[2010/08/15 22:26:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\ProgSense
[2009/08/25 17:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Trillian
[2011/09/18 11:05:05 | 000,000,282 | —- | M] () – C:\WINDOWS\Tasks\SmartDefrag_Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/05/02 13:46:57 | 000,010,524 | —- | M] () – C:\aaw7boot.log
[2008/09/02 18:12:28 | 000,000,645 | —- | M] () – C:\Active SMART.lnk
[2009/02/25 22:05:49 | 000,000,216 | —- | M] () – C:\ASLog.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2009/05/06 00:59:40 | 000,000,487 | -HS- | M] () – C:\Boot.bak
[2011/07/14 05:00:52 | 000,000,440 | -HS- | M] () – C:\boot.ini
[2009/05/06 01:54:32 | 000,000,580 | RHS- | M] () – C:\Boot.ini.saved
[2009/04/22 00:28:23 | 000,383,200 | RHS- | M] () – C:\bootmgr
[2009/05/06 01:54:33 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/04/23 22:48:47 | 000,009,428 | —- | M] () – C:\ComboFix.txt
[2007/08/09 16:04:31 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2008/03/29 04:54:34 | 000,000,000 | —- | M] () – C:\DBS.TXT
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/04/30 18:52:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2007/08/09 16:04:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/03 21:22:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[1993/02/20 12:49:52 | 000,000,030 | —- | M] () – C:\readme.bat
[2010/04/18 14:12:45 | 000,000,387 | —- | M] () – C:\rkill.log
[2009/12/06 20:11:35 | 000,002,870 | —- | M] () – C:\RootRepeal report 12-06-09 (19-11-35).txt
[2009/05/03 13:07:45 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2009/05/03 13:23:21 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2009/05/03 13:28:05 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2009/05/03 14:23:03 | 000,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/05/03 17:23:38 | 000,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/05/03 18:28:06 | 000,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/04/29 11:51:11 | 000,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/04/29 21:49:31 | 000,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/04/30 16:07:14 | 000,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/04/30 16:36:05 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2009/04/30 17:19:43 | 000,000,232 | -H– | M] () – C:\sqmdata10.sqm
[2009/05/01 15:39:25 | 000,000,232 | -H– | M] () – C:\sqmdata11.sqm
[2009/05/02 13:39:29 | 000,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/05/02 13:40:22 | 000,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/05/02 13:40:38 | 000,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/05/02 14:11:14 | 000,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/05/02 14:43:31 | 000,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/05/02 15:11:06 | 000,000,232 | -H– | M] () – C:\sqmdata17.sqm
[2009/05/02 15:23:57 | 000,000,232 | -H– | M] () – C:\sqmdata18.sqm
[2009/05/03 02:10:55 | 000,000,232 | -H– | M] () – C:\sqmdata19.sqm
[2009/05/03 13:07:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/05/03 13:23:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/05/03 13:28:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/05/03 14:23:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/05/03 17:23:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/05/03 18:28:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/04/29 11:51:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/04/29 21:49:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/04/30 16:07:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/04/30 16:36:05 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/04/30 17:19:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/05/01 15:39:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/05/02 13:39:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/05/02 13:40:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/05/02 13:40:38 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/05/02 14:11:14 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/05/02 14:43:31 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/05/02 15:11:06 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/05/02 15:23:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/05/03 02:10:55 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/07/12 13:27:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2002/09/03 18:19:44 | 000,009,728 | —- | M] (Zenographics, Inc.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\MIMFPR_C.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2007/08/09 16:04:08 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2007/08/09 16:04:08 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/07/12 07:51:07 | 004,718,592 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/07/12 01:54:06 | 000,049,152 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2010/07/12 07:51:07 | 028,311,552 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/07/12 07:51:07 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/12 13:27:58 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users.WINDOWS\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 21:30:13 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/03 19:48:35 | 000,000,079 | —- | M] () – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/10/11 21:15:27 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\ATF-Cleaner.exe
[2011/09/18 23:11:21 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\HiJackThis.exe
[2011/09/18 23:12:47 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Daniel.DANIEL-65C6EC9E\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-19 05:49:48
< End of report >