Kilmez
Topic Starter
My PC has been acting screwey lately. A few weeks ago it wouldnt even start, it would freeze at the screen were Windows was loading up. That happened a few times then it worked fine. But now it's really slow, and I get different types of error messages for Explorer and Firefox. I should note that I have an old PC, so I know it doesnt help, but it does work acceptably… just not lately.
For Firefox I see an error that says: A script on this page may be busy, or it may have stopped responding.
For Explorer its a C++ Runtime Error, that it terminates in an unusual way.
And just today I saw one while using Firefox that was an avira Error. C:/Program Files\Avira\Antivir Desktop\ccwkrlib.dll has been modified or destroyed.
A few days ago I tried running Avira and Superantispyware but both came back clean.
Anyways, here is the OTL log:
OTL logfile created on: 11/10/2011 12:05:27 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
351.48 Mb Total Physical Memory | 182.15 Mb Available Physical Memory | 51.82% Memory free
998.14 Mb Paging File | 652.47 Mb Available in Paging File | 65.37% Paging File free
Paging file location(s): C:\pagefile.sys 572 672 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 53.68 Gb Free Space | 48.02% Space Free | Partition Type: NTFS
Computer Name: OWNER-XUKSZMPNK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\FireFox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
PRC - C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (npf) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) – C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (videX32) – C:\WINDOWS\System32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (Ptserial) – C:\WINDOWS\system32\drivers\ptserial.sys (PCTEL, INC.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "IMDb"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:III
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.0.1
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct;=&gc;=1&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.16: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/16 10:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\FireFox\components [2011/06/23 00:58:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\FireFox\plugins [2011/07/03 15:25:13 | 000,000,000 | —D | M]
[2008/08/26 20:56:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/11/09 14:47:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions
[2011/04/03 11:39:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/08/26 21:31:01 | 000,000,000 | —D | M] (Aero Fox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2008/08/27 00:58:47 | 000,000,000 | —D | M] (Dallas Cowboys) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{769d93be-4857-11dc-8314-0800200c9a66}
[2010/03/15 16:14:09 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/12/20 18:09:47 | 000,000,000 | —D | M] (Amazon Quick Search) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{dffa0a29-2400-4d34-b469-efe699ce0115}
[2009/12/20 18:15:45 | 000,000,000 | —D | M] (Amazonbutton+) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2007/12/08 00:05:49 | 000,000,000 | —D | M] (Xuxen III EDBL) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2009/04/25 13:46:16 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2011/01/05 15:04:15 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\vshareus@toolbar
[2008/06/02 00:13:47 | 000,001,193 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\altavista.xml
[2009/12/20 18:18:16 | 000,002,684 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\amazon-search-suggestions.xml
[2011/08/23 20:16:36 | 000,002,333 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\askcom.xml
[2008/08/23 00:27:33 | 000,001,137 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\dictionarycom.xml
[2008/06/02 00:13:48 | 000,002,200 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\gamefaqs.xml
[2008/06/18 23:26:40 | 000,000,908 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\imdb.xml
[2008/04/21 12:09:51 | 000,002,006 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\urban-dictionary.xml
[2008/06/23 21:35:33 | 000,001,108 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-en.xml
[2010/05/29 09:15:10 | 000,001,292 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-es.xml
[2008/08/23 21:51:43 | 000,001,224 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\yahoo-answers.xml
[2010/03/16 10:46:51 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/03/15 17:00:15 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
[2010/07/12 00:02:59 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/03/15 16:59:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
O1 HOSTS File: ([2010/03/14 01:15:05 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKLM\..\Toolbar: (att.net Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\PROGRAM FILES\Logitech\GAMING SOFTWARE\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.motive.com/wizlet/DSLAct…etInstaller.cab (WebBrowserType Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC292830-E399-48EB-8B1F-484EE0F8D685}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.dll) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/01/09 21:40:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell - "" = AutoRun
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/09 13:26:11 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/11/04 12:43:43 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/09 23:41:23 | 000,013,669 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/09 16:15:13 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 16:15:13 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 14:36:15 | 000,016,082 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/09 10:26:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
[2011/11/07 20:09:58 | 000,472,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/07 20:09:58 | 000,084,224 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/11/07 20:05:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/07 20:05:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/03 21:25:37 | 000,020,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:38 | 000,089,691 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/20 09:48:56 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/16 03:16:02 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/16 02:11:09 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/14 04:27:40 | 1587,686,488 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/10/11 17:41:01 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/09 23:41:21 | 000,013,669 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/07 20:47:55 | 000,016,082 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/03 21:25:36 | 000,020,297 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:34 | 000,089,691 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/14 01:41:11 | 1587,686,488 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/08/30 10:26:59 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/08/30 10:26:59 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/08/30 10:26:59 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/08/30 10:26:59 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/08/30 10:26:59 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/08 18:30:13 | 000,000,037 | —- | C] () – C:\WINDOWS\ULVIO40.INI
[2010/12/08 18:25:49 | 000,000,212 | —- | C] () – C:\WINDOWS\ULead32.ini
[2010/06/29 17:54:37 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2010/03/19 16:39:57 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/02/10 03:12:21 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/12/05 17:34:46 | 000,027,480 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/16 10:33:38 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/25 20:18:49 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/06/25 20:03:31 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/06/07 05:27:20 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\vbzlib1.dll
[2009/02/12 21:36:00 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/02/12 21:35:50 | 002,041,363 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2009/02/12 21:35:48 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/02/12 21:35:48 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/13 03:20:33 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/07/29 18:17:48 | 000,001,160 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/07/21 16:19:55 | 000,112,128 | —- | C] () – C:\WINDOWS\audiow32.dll
[2008/03/04 17:52:34 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2008/01/24 19:27:24 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\STLibWrapper.dll
[2007/10/31 08:39:54 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/05/17 12:58:10 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/02/07 15:14:58 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/05 10:11:50 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/12/18 23:12:42 | 000,054,398 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/12/12 16:49:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
[2006/12/12 16:49:05 | 000,009,216 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
[2006/12/12 16:49:05 | 000,000,049 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb41.dat
[2006/12/12 16:48:57 | 000,000,234 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/12 16:48:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb5436.dat
[2006/12/12 16:48:51 | 000,020,480 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb4827.dat
[2006/12/12 16:48:50 | 000,000,337 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb1942.dat
[2006/12/12 16:48:50 | 000,000,023 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inifile41.ini
[2006/11/26 01:24:03 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/23 16:15:53 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/11/22 18:27:08 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/11/22 12:18:37 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/11/21 22:58:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/11/21 22:47:06 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/11/21 22:47:00 | 000,151,552 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/21 20:17:40 | 000,001,536 | —- | C] () – C:\WINDOWS\System32\TrueSoft.dat
[2006/11/21 20:17:36 | 000,000,456 | R— | C] () – C:\WINDOWS\System32\pthsp.dat
[2006/11/21 20:16:49 | 000,173,056 | —- | C] () – C:\WINDOWS\System32\pctspk.exe
[2006/11/21 00:36:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/20 23:24:39 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2006/11/20 23:12:11 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/11/20 23:05:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/11/20 16:58:54 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/11/20 16:57:24 | 000,144,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/09/24 12:37:00 | 000,169,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2006/08/16 08:47:08 | 000,000,114 | —- | C] () – C:\WINDOWS\PART0100.DAT
[2002/08/29 01:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 06:00:00 | 000,472,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 06:00:00 | 000,084,224 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2009/05/15 21:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/06/07 12:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2011/09/08 01:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTYToolbar
[2001/01/09 18:53:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2006/11/23 19:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kazaa Lite
[2010/03/09 17:49:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2007/08/24 12:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\show itch idol that
[2010/04/18 12:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 12:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/17 09:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/25 00:09:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/18 12:27:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2009/05/15 21:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AT&T;
[2009/06/07 12:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATTToolbar
[2010/06/24 07:00:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aura4You
[2010/07/26 21:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\avidemux
[2010/04/18 12:19:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Clone2Go Video Converter Professional
[2009/09/12 15:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2010/06/29 16:55:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeVideoConverter
[2010/12/06 23:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HamsterSoft
[2010/08/09 16:51:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\licenses
[2010/02/25 17:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panda Security
[2010/08/09 16:54:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2009
[2010/08/09 16:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2010
[2009/06/25 20:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/01/05 15:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\vShare
[2009/06/14 10:36:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2001/01/09 18:47:18 | 000,020,156 | —- | M] () – C:\aaw7boot.log
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/30 09:15:04 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2011/08/30 10:50:40 | 000,008,933 | —- | M] () – C:\ComboFix.txt
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2001/01/09 21:40:15 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2001/01/09 21:40:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/08 13:28:41 | 704,643,072 | -HS- | M] () – C:\pagefile.sys
[2011/08/30 10:14:17 | 000,000,359 | —- | M] () – C:\rkill.log
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2001/01/09 21:40:15 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2001/01/09 21:40:16 | 000,000,280 | -H– | M] () – C:\sqmdata16.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/05/10 09:28:14 | 045,881,127 | —- | M] () – C:\t25g
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/11/20 23:08:24 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/03/19 22:33:35 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/20 16:56:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/11/20 16:56:08 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/11/20 16:56:08 | 000,405,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/30 13:18:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/30 15:34:10 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/11/20 23:15:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-20 05:22:59
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7578EF04
< End of report >
————-
That's it I guess… thank you very much for any help.
For Firefox I see an error that says: A script on this page may be busy, or it may have stopped responding.
For Explorer its a C++ Runtime Error, that it terminates in an unusual way.
And just today I saw one while using Firefox that was an avira Error. C:/Program Files\Avira\Antivir Desktop\ccwkrlib.dll has been modified or destroyed.
A few days ago I tried running Avira and Superantispyware but both came back clean.
Anyways, here is the OTL log:
OTL logfile created on: 11/10/2011 12:05:27 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
351.48 Mb Total Physical Memory | 182.15 Mb Available Physical Memory | 51.82% Memory free
998.14 Mb Paging File | 652.47 Mb Available in Paging File | 65.37% Paging File free
Paging file location(s): C:\pagefile.sys 572 672 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 53.68 Gb Free Space | 48.02% Space Free | Partition Type: NTFS
Computer Name: OWNER-XUKSZMPNK | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\FireFox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
PRC - C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (npf) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) – C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (videX32) – C:\WINDOWS\System32\DRIVERS\videX32.sys (VIA Technologies, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (S3Psddr) – C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (DNINDIS5) – C:\WINDOWS\system32\DNINDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (viaagp1) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (ASPI) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
DRV - (Ptserial) – C:\WINDOWS\system32\drivers\ptserial.sys (PCTEL, INC.)
DRV - (Vpctcom) – C:\WINDOWS\System32\DRIVERS\vpctcom.sys (PCtel, Inc.)
DRV - (Vvoice) – C:\WINDOWS\System32\DRIVERS\vvoice.sys (PCtel, Inc.)
DRV - (Vmodem) – C:\WINDOWS\System32\DRIVERS\vmodem.sys (PCTEL, INC.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p;="
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "IMDb"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:III
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.0.1
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct;=&gc;=1&q;="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Content Upload Plugin,version=1.0.0: C:\Program Files\DivX\DivX Content Uploader\npUpload.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.709: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.709: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.16: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Owner\Application Data\Move Networks\plugins\071803000001\npqmp071803000001.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/03/16 10:46:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Components: C:\Program Files\FireFox\components [2011/06/23 00:58:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 2.0.0.20\extensions\\Plugins: C:\Program Files\FireFox\plugins [2011/07/03 15:25:13 | 000,000,000 | —D | M]
[2008/08/26 20:56:39 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/11/09 14:47:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions
[2011/04/03 11:39:06 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/08/26 21:31:01 | 000,000,000 | —D | M] (Aero Fox) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2008/08/27 00:58:47 | 000,000,000 | —D | M] (Dallas Cowboys) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{769d93be-4857-11dc-8314-0800200c9a66}
[2010/03/15 16:14:09 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/12/20 18:09:47 | 000,000,000 | —D | M] (Amazon Quick Search) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\{dffa0a29-2400-4d34-b469-efe699ce0115}
[2009/12/20 18:15:45 | 000,000,000 | —D | M] (Amazonbutton+) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2007/12/08 00:05:49 | 000,000,000 | —D | M] (Xuxen III EDBL) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2009/04/25 13:46:16 | 000,000,000 | —D | M] (TVU Web Player) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\[removed]
[2011/01/05 15:04:15 | 000,000,000 | —D | M] (vShare) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\extensions\vshareus@toolbar
[2008/06/02 00:13:47 | 000,001,193 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\altavista.xml
[2009/12/20 18:18:16 | 000,002,684 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\amazon-search-suggestions.xml
[2011/08/23 20:16:36 | 000,002,333 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\askcom.xml
[2008/08/23 00:27:33 | 000,001,137 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\dictionarycom.xml
[2008/06/02 00:13:48 | 000,002,200 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\gamefaqs.xml
[2008/06/18 23:26:40 | 000,000,908 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\imdb.xml
[2008/04/21 12:09:51 | 000,002,006 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\urban-dictionary.xml
[2008/06/23 21:35:33 | 000,001,108 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-en.xml
[2010/05/29 09:15:10 | 000,001,292 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\wikipedia-es.xml
[2008/08/23 21:51:43 | 000,001,224 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\wal9bexx.default\searchplugins\yahoo-answers.xml
[2010/03/16 10:46:51 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/03/15 17:00:15 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
[2010/07/12 00:02:59 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES\FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/03/15 16:59:26 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
O1 HOSTS File: ([2010/03/14 01:15:05 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKLM\..\Toolbar: (att.net Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4E7BD74F-2B8D-469E-94BE-FD60BB9AAE29} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\PROGRAM FILES\Logitech\GAMING SOFTWARE\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10e.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: motive.com ([patttbc.att] https in Trusted sites)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.motive.com/wizlet/DSLAct…etInstaller.cab (WebBrowserType Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BC292830-E399-48EB-8B1F-484EE0F8D685}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.dll) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/01/09 21:40:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell - "" = AutoRun
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{0fae7670-8047-11e0-832e-00e04c79f129}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: VIDC.FMVC - C:\WINDOWS\System32\fmcodec.DLL (Fox Magic Software)
Drivers32: VIDC.HFYU - C:\WINDOWS\System32\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\WINDOWS\System32\I263_32.drv (Intel Corporation)
Drivers32: vidc.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\WINDOWS\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/09 13:26:11 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/11/04 12:43:43 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/09 23:41:23 | 000,013,669 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/09 16:15:13 | 000,000,286 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 16:15:13 | 000,000,278 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-796845957-789336058-854245398-1003.job
[2011/11/09 14:36:15 | 000,016,082 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/09 10:26:13 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
[2011/11/07 20:09:58 | 000,472,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/07 20:09:58 | 000,084,224 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/11/07 20:05:48 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/07 20:05:43 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/11/03 21:25:37 | 000,020,297 | —- | M] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:38 | 000,089,691 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/20 09:48:56 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/10/16 03:16:02 | 000,144,424 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/16 02:11:09 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/10/14 04:27:40 | 1587,686,488 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/10/11 17:41:01 | 000,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/09 23:41:21 | 000,013,669 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E3.JPG
[2011/11/07 20:47:55 | 000,016,082 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E2.JPG
[2011/11/03 21:25:36 | 000,020,297 | —- | C] () – C:\Documents and Settings\Owner\Desktop\E1.JPG
[2011/10/24 23:22:34 | 000,089,691 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Klose.jpg
[2011/10/14 01:41:11 | 1587,686,488 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Illuminati The Music Industry Exposed [Full Length].avi
[2011/08/30 10:26:59 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/08/30 10:26:59 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/08/30 10:26:59 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/08/30 10:26:59 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/08/30 10:26:59 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/12/08 18:30:13 | 000,000,037 | —- | C] () – C:\WINDOWS\ULVIO40.INI
[2010/12/08 18:25:49 | 000,000,212 | —- | C] () – C:\WINDOWS\ULead32.ini
[2010/06/29 17:54:37 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2010/03/19 16:39:57 | 008,892,928 | —- | C] () – C:\Documents and Settings\All Users\Application Data\atscie.msi
[2010/02/10 03:12:21 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009/12/05 17:34:46 | 000,027,480 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/16 10:33:38 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/25 20:18:49 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/06/25 20:03:31 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2009/06/07 05:27:20 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\vbzlib1.dll
[2009/02/12 21:36:00 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/02/12 21:35:50 | 002,041,363 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2009/02/12 21:35:48 | 000,755,027 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/02/12 21:35:48 | 000,159,839 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/11/13 03:20:33 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2008/07/29 18:17:48 | 000,001,160 | —- | C] () – C:\WINDOWS\mozver.dat
[2008/07/21 16:19:55 | 000,112,128 | —- | C] () – C:\WINDOWS\audiow32.dll
[2008/03/04 17:52:34 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\libcurl.dll
[2008/01/24 19:27:24 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\STLibWrapper.dll
[2007/10/31 08:39:54 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2007/05/17 12:58:10 | 000,143,360 | —- | C] () – C:\WINDOWS\System32\libexpatw.dll
[2007/02/07 15:14:58 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/02/05 10:11:50 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2006/12/18 23:12:42 | 000,054,398 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/12/12 16:49:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
[2006/12/12 16:49:05 | 000,009,216 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
[2006/12/12 16:49:05 | 000,000,049 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb41.dat
[2006/12/12 16:48:57 | 000,000,234 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/12/12 16:48:52 | 000,000,000 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb5436.dat
[2006/12/12 16:48:51 | 000,020,480 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb4827.dat
[2006/12/12 16:48:50 | 000,000,337 | —- | C] () – C:\Documents and Settings\Owner\Application Data\internaldb1942.dat
[2006/12/12 16:48:50 | 000,000,023 | —- | C] () – C:\Documents and Settings\Owner\Application Data\inifile41.ini
[2006/11/26 01:24:03 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/23 16:15:53 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/11/22 18:27:08 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006/11/22 12:18:37 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2006/11/21 22:58:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/11/21 22:47:06 | 000,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/11/21 22:47:00 | 000,151,552 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/11/21 20:17:40 | 000,001,536 | —- | C] () – C:\WINDOWS\System32\TrueSoft.dat
[2006/11/21 20:17:36 | 000,000,456 | R— | C] () – C:\WINDOWS\System32\pthsp.dat
[2006/11/21 20:16:49 | 000,173,056 | —- | C] () – C:\WINDOWS\System32\pctspk.exe
[2006/11/21 00:36:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/11/20 23:24:39 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\AegisI5.exe
[2006/11/20 23:12:11 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/11/20 23:05:30 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/11/20 16:58:54 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/11/20 16:57:24 | 000,144,424 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2006/09/24 12:37:00 | 000,169,472 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2006/08/16 08:47:08 | 000,000,114 | —- | C] () – C:\WINDOWS\PART0100.DAT
[2002/08/29 01:57:58 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/23 06:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/23 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2001/08/23 06:00:00 | 000,472,604 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2001/08/23 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2001/08/23 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2001/08/23 06:00:00 | 000,084,224 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2001/08/23 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2001/08/23 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2001/08/23 06:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2009/05/15 21:50:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AT&T;
[2009/06/07 12:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTToolbar
[2011/09/08 01:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATTYToolbar
[2001/01/09 18:53:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2006/11/23 19:45:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kazaa Lite
[2010/03/09 17:49:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2007/08/24 12:53:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\show itch idol that
[2010/04/18 12:13:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 12:07:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/17 09:55:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/25 00:09:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/04/18 12:27:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AnvSoft
[2009/05/15 21:51:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AT&T;
[2009/06/07 12:20:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ATTToolbar
[2010/06/24 07:00:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aura4You
[2010/07/26 21:24:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\avidemux
[2010/04/18 12:19:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Clone2Go Video Converter Professional
[2009/09/12 15:49:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FMZilla
[2010/06/29 16:55:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FreeVideoConverter
[2010/12/06 23:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HamsterSoft
[2010/08/09 16:51:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\licenses
[2010/02/25 17:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panda Security
[2010/08/09 16:54:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2009
[2010/08/09 16:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCMM2010
[2009/06/25 20:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Samsung
[2011/01/05 15:05:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\vShare
[2009/06/14 10:36:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2011/11/07 20:06:09 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
[2011/11/08 11:33:45 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{33466F56-B28E-432D-BB34-A90DEADB4A78}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2001/01/09 18:47:18 | 000,020,156 | —- | M] () – C:\aaw7boot.log
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/30 09:15:04 | 000,000,282 | -HS- | M] () – C:\boot.ini
[2011/08/30 10:50:40 | 000,008,933 | —- | M] () – C:\ComboFix.txt
[2001/01/09 21:40:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2001/01/09 21:40:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2001/01/09 21:40:15 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2001/01/09 21:40:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/11/08 13:28:41 | 704,643,072 | -HS- | M] () – C:\pagefile.sys
[2011/08/30 10:14:17 | 000,000,359 | —- | M] () – C:\rkill.log
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2001/01/09 21:40:15 | 000,000,232 | -H– | M] () – C:\sqmdata09.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2001/01/09 21:40:15 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2001/01/09 21:40:16 | 000,000,280 | -H– | M] () – C:\sqmdata16.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2001/01/09 21:40:16 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2001/01/09 21:40:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/05/10 09:28:14 | 045,881,127 | —- | M] () – C:\t25g
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/11/20 23:08:24 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/03/19 22:33:35 | 000,001,754 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/20 16:56:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2006/11/20 16:56:08 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2006/11/20 16:56:08 | 000,405,504 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/30 13:18:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/30 15:34:10 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/11/20 23:15:56 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011/11/04 12:43:35 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-10-20 05:22:59
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7578EF04
< End of report >
————-
That's it I guess… thank you very much for any help.