Hello oldman960,
Thank you for your help!
Here is my OTL.txt file:
OTL logfile created on: 6/17/2012 2:21:40 PM - Run 1
OTL by OldTimer - Version 3.2.49.0 Folder = C:\Documents and Settings\Ike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 76.91% Memory free
2.07 Gb Paging File | 1.72 Gb Available in Paging File | 83.19% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 31.44 Gb Free Space | 33.75% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 41.31 Gb Free Space | 27.72% Space Free | Partition Type: NTFS
Computer Name: BUD | User Name: Ike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Ike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
PRC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
PRC - C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
PRC - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
MOD - C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (McAfee SiteAdvisor Service) – c:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\psia.exe (Secunia)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (vsmon) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WDBtnMgrSvc.exe) – C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe (WDC)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (ColdFusion MX 7 Application Server) – C:\CFusionMX7\runtime\bin\jrunsvc.exe (Macromedia Inc.)
SRV - (APC UPS Service) – C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe (American Power Conversion Corporation)
SRV - (ColdFusion MX 7 Search Server) – C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe (Verity, Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (MySql) – C:/mysql/bin/mysqld-nt.exe ()
SRV - (ColdFusion MX 7 ODBC Server) – C:\CFusionMX7\db\slserver54\bin\swstrtr.exe ()
SRV - (ColdFusion MX 7 ODBC Agent) – C:\CFusionMX7\db\slserver54\bin\swagent.exe ()
SRV - (MSSQLServer) – C:\MSSQL7\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLServerAgent) – C:\MSSQL7\Binn\sqlagent.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (srescan) – system32\ZoneLabs\srescan.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (KeyScrambler) – C:\WINDOWS\system32\drivers\keyscrambler.sys (QFX Software Corporation)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ggsemc) – C:\WINDOWS\system32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\WINDOWS\system32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (a016obex) – C:\WINDOWS\system32\drivers\a016obex.sys (MCCI Corporation)
DRV - (a016mdm) – C:\WINDOWS\system32\drivers\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt) Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\a016mgmt.sys (MCCI Corporation)
DRV - (a016mdfl) – C:\WINDOWS\system32\drivers\a016mdfl.sys (MCCI Corporation)
DRV - (a016bus) Sony Ericsson Device A016 driver (WDM) – C:\WINDOWS\system32\drivers\a016bus.sys (MCCI Corporation)
DRV - (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\s115mgmt.sys (MCCI Corporation)
DRV - (s115obex) – C:\WINDOWS\system32\drivers\s115obex.sys (MCCI Corporation)
DRV - (s115mdm) – C:\WINDOWS\system32\drivers\s115mdm.sys (MCCI Corporation)
DRV - (s115mdfl) – C:\WINDOWS\system32\drivers\s115mdfl.sys (MCCI Corporation)
DRV - (s115bus) Sony Ericsson Device 115 driver (WDM) – C:\WINDOWS\system32\drivers\s115bus.sys (MCCI Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (USBCM) – C:\WINDOWS\system32\drivers\Sacm2A.sys ( )
DRV - (viaagp1) – C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (crlscsi) – C:\WINDOWS\System32\drivers\crlscsi.sys (Corel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…age={startPage}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.selectedEngine: ""
FF - prefs.js..browser.startup.homepage: "D:\\Data Files\\Work Files\\WebsiteFiles\\HomePage\\Home.htm"
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.102: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2536: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.2594: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1698: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/02/05 00:39:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2012/06/08 03:20:57 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/06/11 12:49:14 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/06/08 03:20:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/06/05 22:59:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/08 12:56:22 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.1\Extensions\\Components: c:\Application Files\Internet\NewsReaders\Netscape\Components [2009/03/30 20:41:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Netscape 7.1\Extensions\\Plugins: c:\Application Files\Internet\NewsReaders\Netscape\Plugins [2012/06/16 00:41:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.1\Extensions\\Components: c:\Application Files\Internet\NewsReaders\Netscape\Components [2009/03/30 20:41:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Netscape 7.1\Extensions\\Plugins: c:\Application Files\Internet\NewsReaders\Netscape\Plugins [2012/06/16 00:41:13 | 000,000,000 | —D | M]
[2009/11/21 15:24:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Extensions
[2009/11/21 15:24:03 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Extensions\[removed]
[2011/03/07 10:33:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions
[2009/07/23 21:07:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/13 20:05:07 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Ike\Application Data\Mozilla\Firefox\Profiles\xaac7lao.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/06/16 00:41:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/04/15 18:43:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/06/10 15:06:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2012/06/08 12:56:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA}
[2012/06/16 00:41:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/06/08 12:56:06 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/05 00:39:43 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\PROGRAM FILES\MCAFEE\SITEADVISOR
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2008/06/17 20:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2010/11/26 09:55:52 | 000,002,024 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2011/07/15 19:25:11 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (KeyScramblerBHO Class) - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Anonymizer 2005 Toolbar) - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Anonymizer 2005 Toolbar) - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe (Google Inc.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe (HP)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe (ScanSoft, Inc.)
O4 - HKLM..\Run: [ScanSoft OmniPage SE 4.0-reminder] C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [VTTrayp] C:\WINDOWS\System32\VTTrayp.exe (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe (WDC)
O4 - HKLM..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe ()
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O4 - Startup: C:\Documents and Settings\Ike\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : &KeyScrambler; Options - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll (QFX Software Corporation)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE}
http://supportcenter.rr.com/sdccommon/download/tgctlins.cab (SupportSoft Installer)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623}
http://www.alternatiff.com/distribution/al…x-w32-2.0.3.cab (AlternaTIFF ActiveX)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {3253344D-0000-0010-8000-00AA00389B71}
http://codecs.microsoft.com/codecs/i386/mpg4sax.cab (Reg Error: Key error.)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1135806761620 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1135807830562 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/12/28 11:41:55 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/17 13:25:18 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe
[2012/06/16 00:41:13 | 000,157,448 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2012/06/16 00:41:13 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2012/06/16 00:41:13 | 000,149,256 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2012/06/15 22:39:25 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2012/06/15 22:39:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Start Menu\Programs\HiJackThis
[2012/06/15 20:40:11 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Ike\Desktop\dds.scr
[2012/06/12 11:06:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\QFX Software
[2012/06/12 11:06:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\QFX Software
[2012/06/12 11:02:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\KeyScrambler
[2012/06/12 11:02:26 | 000,173,880 | —- | C] (QFX Software Corporation) – C:\WINDOWS\System32\drivers\keyscrambler.sys
[2012/06/12 11:02:26 | 000,000,000 | —D | C] – C:\Program Files\KeyScrambler
[2012/06/12 10:51:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\FK_Monitor
[2012/06/12 10:51:28 | 000,000,000 | —D | C] – C:\Program Files\FK_Monitor
[2012/06/11 12:49:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG
[2012/06/08 12:56:22 | 000,476,936 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\npdeployJava1.dll
[2012/06/08 03:22:43 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Application Data\AVG2012
[2012/06/08 03:21:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2012/06/08 03:20:49 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/08 03:20:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2012/06/08 03:20:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2012/06/08 03:19:53 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2012/06/08 03:15:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/06/08 02:48:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/06/03 04:17:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/03 04:17:54 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012/06/03 04:17:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/03 03:38:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Ike\Local Settings\Application Data\Secunia PSI
[2012/06/03 03:38:04 | 000,000,000 | —D | C] – C:\Program Files\Secunia
========== Files - Modified Within 30 Days ==========
[2012/06/17 14:14:05 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/06/17 14:13:20 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2012/06/17 14:12:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/06/17 14:12:55 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2012/06/17 13:25:17 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe
[2012/06/17 11:03:25 | 100,539,838 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/17 00:28:50 | 000,002,709 | —- | M] () – C:\WINDOWS\SOLFIRE4.INI
[2012/06/15 22:40:14 | 000,002,445 | —- | M] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.lnk
[2012/06/15 22:19:55 | 001,402,880 | —- | M] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.msi
[2012/06/15 20:40:11 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Ike\Desktop\dds.scr
[2012/06/13 21:25:38 | 000,002,497 | —- | M] () – C:\Documents and Settings\Ike\Desktop\Microsoft Office Word 2003.lnk
[2012/06/13 12:59:54 | 000,298,704 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/13 12:52:48 | 000,492,562 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/06/13 12:52:48 | 000,085,594 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/06/13 12:38:37 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/06/11 20:30:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/11 12:49:14 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/10 08:13:14 | 000,034,764 | —- | M] () – C:\Documents and Settings\Ike\Local Settings\Application Data\dt.dat
[2012/06/08 03:05:55 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012/06/08 02:07:53 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2012/06/03 04:17:58 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/03 03:38:15 | 000,000,753 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/05/31 03:22:09 | 000,599,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\crypt32.dll
[2012/05/21 21:35:26 | 000,419,488 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/05/21 21:35:26 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
========== Files Created - No Company Name ==========
[2012/06/17 11:03:25 | 100,539,838 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/06/15 22:39:25 | 000,002,445 | —- | C] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.lnk
[2012/06/15 22:19:55 | 001,402,880 | —- | C] () – C:\Documents and Settings\Ike\Desktop\HiJackThis.msi
[2012/06/12 11:57:21 | 2078,855,168 | -HS- | C] () – C:\hiberfil.sys
[2012/06/10 08:13:14 | 000,034,764 | —- | C] () – C:\Documents and Settings\Ike\Local Settings\Application Data\dt.dat
[2012/06/08 03:21:37 | 000,000,702 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2012/06/03 04:17:58 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/03 03:38:15 | 000,000,753 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/06/03 03:38:15 | 000,000,716 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Secunia PSI.lnk
[2010/12/17 02:52:39 | 000,009,322 | —- | C] () – C:\Documents and Settings\Ike\Application Data\Comma Separated Values (Windows).EML
========== LOP Check ==========
[2009/05/16 12:58:05 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ACD Systems
[2012/06/08 02:02:19 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/06/08 03:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/06/08 03:25:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2008/12/23 15:06:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2012/06/08 03:21:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2008/01/16 07:25:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2008/07/09 05:39:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/11/30 14:29:02 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Memeo
[2008/12/01 04:02:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MemeoCommon
[2012/06/16 23:43:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/06/12 11:06:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QFX Software
[2007/10/24 11:47:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/12/23 02:32:35 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/08/01 10:12:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/01/13 23:16:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/30 20:46:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/05/16 13:04:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\ACD Systems
[2010/06/08 23:07:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\AnvSoft
[2012/06/08 03:22:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\AVG2012
[2007/10/24 12:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Canon
[2012/06/17 11:23:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\CoreFTP
[2012/06/12 12:16:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\FK_Monitor
[2008/01/05 04:36:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\FrostWire
[2005/12/30 10:27:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\funkitron
[2009/05/20 22:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\GrabPro
[2008/01/16 07:28:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Grisoft
[2006/01/01 22:37:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Image Zone Express
[2005/12/29 17:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Leadertech
[2011/03/13 21:10:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\MailWasher
[2009/11/26 15:19:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Newsbin
[2007/10/24 16:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\NewSoft
[2011/07/17 03:35:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Opera
[2010/05/01 11:34:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Orbit
[2012/06/12 11:06:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\QFX Software
[2005/12/28 18:41:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Qualcomm
[2007/10/24 11:47:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\ScanSoft
[2008/12/23 15:50:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Sony
[2008/12/23 02:22:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Sony Setup
[2008/12/16 14:04:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Teleca
[2007/01/13 23:16:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Viewpoint
[2008/12/01 04:01:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\WD
[2010/06/08 22:31:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Ike\Application Data\Xilisoft Corporation
[2012/06/17 14:13:20 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/01/13 08:02:58 | 000,011,395 | —- | M] () – C:\2009-1-13 - hijackthis.log
[2007/06/11 07:11:43 | 000,374,032 | —- | M] () – C:\ACF3758.zip
[2005/12/28 11:41:55 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2008/12/20 12:08:44 | 000,000,211 | —- | M] () – C:\Boot.bak
[2012/06/08 02:07:53 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2005/12/28 11:41:55 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/04/04 19:55:35 | 000,003,872 | —- | M] () – C:\cvv1.gif
[2009/07/23 21:39:42 | 007,024,337 | —- | M] () – C:\Daves.flv
[2011/08/16 10:35:09 | 000,123,886 | —- | M] () – C:\Diamond Head Theatre.jpg
[2007/06/04 22:46:03 | 001,524,871 | —- | M] () – C:\easybio_setup.exe
[2007/03/16 05:55:53 | 000,000,269 | —- | M] () – C:\executive.log
[2012/06/17 14:12:55 | 2078,855,168 | -HS- | M] () – C:\hiberfil.sys
[2009/04/01 22:34:34 | 000,011,590 | —- | M] () – C:\hijackthis.log
[2009/07/23 21:41:00 | 013,712,566 | —- | M] () – C:\Holly.flv
[2005/12/28 11:41:55 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/01/13 18:27:22 | 000,002,986 | —- | M] () – C:\Kas - C Drive - Eudora Directory.html
[2009/01/17 05:12:12 | 000,003,043 | —- | M] () – C:\Kas - C Drive.html
[2009/01/13 19:12:52 | 000,002,888 | —- | M] () – C:\Kas - K Drive - Backup Directory Look Again.html
[2009/01/13 18:37:34 | 000,002,897 | —- | M] () – C:\Kas - K Drive - Backup Directory.html
[2009/01/13 19:01:52 | 000,002,893 | —- | M] () – C:\Kas - K Drive - Old-E-Drive Directory.html
[2009/01/13 18:11:22 | 000,002,955 | —- | M] () – C:\Kas L Drive.html
[2009/01/13 06:45:57 | 000,029,102 | —- | M] () – C:\Kas.gif
[2009/01/12 06:32:54 | 000,016,016 | —- | M] () – C:\Kasp.gif
[2007/07/17 05:23:30 | 000,157,988 | —- | M] () – C:\LylaCaptcha_v1Beta.zip
[2009/04/01 23:13:14 | 000,003,566 | —- | M] () – C:\mbam-log-2009-04-01 (23-11-56).txt
[2009/01/12 05:20:40 | 000,020,872 | —- | M] () – C:\Modify - ComboFix.txt
[2005/12/28 11:41:55 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2005/12/28 13:04:06 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/03 09:19:34 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/06/17 14:12:53 | 301,989,888 | -HS- | M] () – C:\pagefile.sys
[2009/01/12 06:11:24 | 000,000,833 | —- | M] () – C:\Post This - mbam-log-2009-01-12 (06-06-59).txt
[2009/05/24 22:15:37 | 000,000,022 | -H– | M] () – C:\qpmd8378.bin
[2008/03/09 09:53:02 | 000,000,320 | —- | M] () – C:\t12g.1
[2007/07/05 21:48:51 | 000,000,094 | —- | M] () – C:\t15s.1
[2008/08/06 13:41:06 | 000,001,923 | —- | M] () – C:\t1o0.1
[2008/08/07 17:38:11 | 000,001,925 | —- | M] () – C:\t1o8.1
[2008/07/20 23:04:55 | 000,001,229 | —- | M] () – C:\t1r8.3
[2006/04/18 21:24:43 | 000,000,313 | —- | M] () – C:\t1rs.1
[2008/03/01 00:51:42 | 000,001,659 | —- | M] () – C:\t6o.5
[2008/02/28 06:59:03 | 000,000,400 | —- | M] () – C:\t7k.3
[2008/04/18 03:04:37 | 000,000,317 | —- | M] () – C:\tc4.3
[2007/08/09 12:12:02 | 000,000,866 | —- | M] () – C:\tck.1
[2007/08/13 12:12:55 | 000,000,389 | —- | M] () – C:\tdg.3
[2007/10/10 15:53:19 | 000,000,323 | —- | M] () – C:\tu4.3
[2012/06/12 10:50:15 | 000,098,447 | —- | M] () – C:\winzip.log
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005/12/28 11:41:33 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 02:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2005/05/05 08:48:54 | 000,067,072 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp3xu.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 00:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005/12/28 01:29:31 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/12/28 01:29:31 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/12/28 01:29:31 | 000,434,176 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/06/17 13:25:17 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Ike\Desktop\aswMBR.exe
[2008/01/16 07:39:16 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Ike\Desktop\ATF-Cleaner.exe
[2012/06/17 13:23:44 | 000,595,968 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Ike\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 22:53:53
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.CPL >
[1996/06/24 06:51:20 | 000,005,536 | —- | M] () MD5=8AD05DB07CD116CD4223A8B606945A77 – C:\Application Files\Multimedia\Graphics\ImageEditors\Corel\Draw70\programs\DATA\explorer.cpl
< MD5 for: EXPLORER.EXE >
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\erdnt\cache\explorer.exe
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/13 14:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2007/06/13 01:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 00:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
[2004/08/03 21:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
< MD5 for: EXPLORER.EXE.000 >
[2004/08/03 21:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe.000
< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/06/17 14:14:09 | 000,067,016 | —- | M] () MD5=2DC79D736DFABF65D2D7447FEA0BFEA9 – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
< MD5 for: EXPLORER.GIF >
[2008/02/14 13:22:08 | 000,001,054 | —- | M] () MD5=678B9EABF7493254CDB7F86E98AFAFD7 – C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\Sync Studio\Images\Explorer.gif
< MD5 for: EXPLORER.SCF >
[2003/03/31 02:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CHM >
[2004/07/17 08:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2004/07/17 08:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ServicePackFiles\i386\iexplore.chm
[2006/09/01 07:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\Help\iexplore.chm
< MD5 for: IEXPLORE.EXE >
[2009/06/28 21:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 19:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/14 20:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2010/12/20 01:25:27 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=091D358EFC9D22901BD879EF37F0DAC4 – C:\WINDOWS\ie7updates\KB2497640-IE7\iexplore.exe
[2009/04/24 19:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3gdr\iexplore.exe
[2012/04/21 20:40:38 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=0A39EEAD063CCDFF36AC9F0B8F800956 – C:\WINDOWS\system32\dllcache\iexplore.exe
[2007/04/24 04:26:26 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=10BDB55982586A432A3951EB19A26009 – C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
[2008/12/18 19:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/21 22:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2011/12/16 01:00:16 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=1C206B8FEEC6882B7F7F479E95D2BDD9 – C:\WINDOWS\ie7updates\KB2675157-IE7\iexplore.exe
[2011/10/31 00:32:32 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=1C5DA2D9EA2A59D0D5C116FA3A5A21AA – C:\WINDOWS\$hf_mig$\KB2618444-IE7\SP3QFE\iexplore.exe
[2008/08/22 19:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2010/06/17 05:12:57 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=203E897F843D56496E2CC101DFF6CE34 – C:\WINDOWS\ie7updates\KB2360131-IE7\iexplore.exe
[2008/04/21 21:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 01:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINDOWS\ie7updates\KB947864-IE7\iexplore.exe
[2007/06/26 22:27:30 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=275CEE268B9E5D82474C43D5D249D111 – C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
[2008/02/28 22:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
[2011/10/31 00:46:00 | 000,634,504 | —- | M] (Microsoft Corporation) MD5=2E34CF22B5862AB02786F0819B9FD819 – C:\WINDOWS\ie7updates\KB2647516-IE7\iexplore.exe
[2009/08/26 19:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2007/08/17 00:21:21 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=3AC2BC667DA0AF2C968E96E1630F5AB5 – C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
[2009/06/28 22:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2011/04/21 00:34:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=3E23DBEBE1020D52C63235E4189FAC03 – C:\WINDOWS\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[2009/10/27 20:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2012/02/29 01:01:00 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=50BA6A230D743A4D33BFFA2FA1113055 – C:\WINDOWS\ie7updates\KB2699988-IE7\iexplore.exe
[2006/10/17 12:04:40 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=5334D4461AA92A7B008755FE6D13C5F2 – C:\WINDOWS\ie7updates\KB928090-IE7\iexplore.exe
[2009/12/18 03:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[2007/08/17 00:12:49 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=5577D0E3AC2F9F035ACD81B44AF5F511 – C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[2008/04/13 14:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2007/10/09 22:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2008/06/22 23:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[2007/02/20 22:00:58 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 – C:\WINDOWS\ie7updates\KB933566-IE7\iexplore.exe
[2011/08/17 01:01:37 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=6A1D755C68C10863C598C78A597FA7C3 – C:\WINDOWS\ie7updates\KB2618444-IE7\iexplore.exe
[2008/02/21 23:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2010/10/18 01:07:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=72D1F43C4146D312B0DB6AB98C21340E – C:\WINDOWS\ie7updates\KB2482017-IE7\iexplore.exe
[2009/10/27 20:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/05 22:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/01/08 18:08:42 | 000,623,616 | —- | M] (Microsoft Corporation) MD5=93A6A4F5293AE19E3B37021AABCF0902 – C:\WINDOWS\ie7updates\KB931768-IE7\iexplore.exe
[2011/06/20 01:29:11 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=993F33696EF219C306BF9BBA34D85073 – C:\WINDOWS\ie7updates\KB2586448-IE7\iexplore.exe
[2007/04/24 04:20:41 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=9B3516C1F30DA17ADD3818573047D63C – C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[2008/10/14 21:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/27 18:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2010/06/17 04:45:15 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B0BC6DC9C9277250C5C8F7B7A48A02CC – C:\WINDOWS\$hf_mig$\KB2183461-IE7\SP3QFE\iexplore.exe
[2010/04/16 01:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/22 19:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2011/04/21 00:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\erdnt\cache\iexplore.exe
[2011/04/21 00:58:25 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6E13F9C120C776A89D783E26D6C15C5 – C:\WINDOWS\ie7updates\KB2559049-IE7\iexplore.exe
[2010/12/20 00:49:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B74CBEBA34E3CAA2CCACC87FEE8A16C0 – C:\WINDOWS\$hf_mig$\KB2482017-IE7\SP3QFE\iexplore.exe
[2009/02/27 18:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2007/06/26 23:16:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=BD8502DFD53FC24FB8D6929DC46B8C2C – C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[2009/04/24 19:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 01:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie7updates\KB2183461-IE7\iexplore.exe
[2008/06/22 22:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/22 19:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2011/08/17 00:34:43 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=CB0AFAF9E5C5FE70EC7087E71275DD33 – C:\WINDOWS\$hf_mig$\KB2586448-IE7\SP3QFE\iexplore.exe
[2012/04/21 20:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\$hf_mig$\KB2699988-IE7\SP3QFE\iexplore.exe
[2012/04/21 20:32:36 | 000,634,488 | —- | M] (Microsoft Corporation) MD5=CE2379FC341C65CAD88FF8264A791AB5 – C:\WINDOWS\SoftwareDistribution\Download\44db2dc6f65744579e39a12db0457613\sp3qfe\iexplore.exe
[2009/12/17 21:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/02/27 20:51:34 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=D321092F8529CDAE843D6E24E3CAC6CB – C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[2010/10/18 00:36:30 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DA6E1F0F1932B62DD2F6ED05541C555C – C:\WINDOWS\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[2011/12/16 00:35:06 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DB9D9A73FACB0B11992201D670D73E16 – C:\WINDOWS\$hf_mig$\KB2647516-IE7\SP3QFE\iexplore.exe
[2011/06/20 00:38:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=DE0F15DD275A36C3E67DC1E36F958F3A – C:\WINDOWS\$hf_mig$\KB2559049-IE7\SP3QFE\iexplore.exe
[2012/02/29 00:34:48 | 000,634,680 | —- | M] (Microsoft Corporation) MD5=DF642AABFDACE36E3B4329091A07DE87 – C:\WINDOWS\$hf_mig$\KB2675157-IE7\SP3QFE\iexplore.exe
[2011/02/14 01:36:55 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E3CC8CCF21BFDC954255BB17083FB9F0 – C:\WINDOWS\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[2011/02/14 02:17:08 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E4A798DFDE7FE6E79F23548F0EF0F844 – C:\WINDOWS\ie7updates\KB2530548-IE7\iexplore.exe
[2010/08/25 01:30:33 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=E5412ED9E07C42C20C48D3FF71E6B1E8 – C:\WINDOWS\ie7updates\KB2416400-IE7\iexplore.exe
[2004/08/03 21:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe
[2004/08/03 21:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe
[2008/08/22 19:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 00:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINDOWS\ie7updates\KB944533-IE7\iexplore.exe
[2010/08/25 01:07:58 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F047BEB9771E45A05F425499A30F9BBA – C:\WINDOWS\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[2009/08/26 19:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2006/10/17 12:04:26 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=E83C9C1F9DD9D47BB44871BFC7E69DDD – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/06/17 14:14:26 | 000,074,610 | —- | M] () MD5=E4EA8E1782684C9A90E9B96BE402FF0F – C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf
< MD5 for: IEXPLORE.GIF >
[1999/09/27 08:00:50 | 000,001,272 | -H– | M] () MD5=E33A77046E2004ED5A299F90DEE7080C – C:\Application Files\Development\Website\ColdFusionStudio\Help\HTML_Reference\images\iexplore.gif
< MD5 for: IEXPLORE.HLP >
[2003/03/31 02:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: WINLOGON.EXE >
[2004/08/03 21:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\erdnt\cache\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 14:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
< End of report >
Here is my Extras.Txt file:
OTL Extras logfile created on: 6/17/2012 2:21:40 PM - Run 1
OTL by OldTimer - Version 3.2.49.0 Folder = C:\Documents and Settings\Ike\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.94 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 76.91% Memory free
2.07 Gb Paging File | 1.72 Gb Available in Paging File | 83.19% Paging File free
Paging file location(s): C:\pagefile.sys 288 576 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 93.16 Gb Total Space | 31.44 Gb Free Space | 33.75% Space Free | Partition Type: NTFS
Drive D: | 149.05 Gb Total Space | 41.31 Gb Free Space | 27.72% Space Free | Partition Type: NTFS
Computer Name: BUD | User Name: Ike | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Opera.HTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – "C:\Application Files\Internet\Browsers\Opera\Opera.exe" "%1" (Opera Software)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\APPLIC~1\MULTIM~1\Graphics\IMAGEV~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Enqueue] – "C:\Application Files\Multimedia\Audio\Mp3Players\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Application Files\Multimedia\Audio\Mp3Players\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe" = C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0 – (SmartFTP GmbH)
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe" = C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2 – (Sony Creative Software Inc.)
"C:\Application Files\Internet\NewsReaders\NewsBin\nbpro.exe" = C:\Application Files\Internet\NewsReaders\NewsBin\nbpro.exe:*:Enabled:NewsBin Pro – (CMCEI)
"C:\Application Files\Internet\Browsers\Opera\opera.exe" = C:\Application Files\Internet\Browsers\Opera\opera.exe:*:Enabled:Opera Internet Browser – (Opera Software)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
"C:\Documents and Settings\Ike\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\Ike\Local Settings\Application Data\Akamai\netsession_win.exe:*:Disabled:Akamai NetSession Client – (Akamai Technologies, Inc)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4802" = CanoScan LiDE 600F
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 33
"{29042B1C-0713-4575-B7CA-5C8E7B0899D4}" = MyODBC 3.51.8
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 4.006.00
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33D6CC28-9F75-4d1b-A11D-98895B3A3729}" = HP Photosmart 330,380,420,470,7800,8000,8200 Series
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{4073AAEC-B01B-4000-BC9B-1447E3A7BD87}" = AVG 2012
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6E7D29CB-E3D9-4ef2-B4DC-ECF1C0C45ECC}" = PS470
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{755EC5E3-FD51-46bd-A57F-7A2D56FBF061}" = PSTAPlugin
"{769A295C-DCF4-41d6-AFBA-7D9394B23AFE}" = PSPrinters08
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}" = URGE
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EB1504E-FD95-4BCD-8E93-B4039F59C469}" = Sony Ericsson Media Manager 1.2
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A3455242-DAE0-4523-8242-FD82706ABF4B}" = CameraDrivers
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70500000002}" = Adobe Reader 7.0.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BCF75973-29C2-4245-80E3-B3C2B7E7548B}" = AVG 2012
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C169D3BB-9A27-43F5-9979-09A0D65FE95C}" = SmartFTP Client 2.0
"{C1E693A4-B1D5-4DCD-B68D-2087835B7184}" = ScanSoft OmniPage SE 4.0
"{C6A09671-93A6-4548-9FAE-3BF21EB9C921}" = AVG 2012
"{CAAB0192-5704-469F-A0BE-2D842D70E93B}_is1" = Sothink FLV Player
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}" = Presto! PageManager 7.15.14
"{DE076BC1-42A1-4C8C-BFCD-C1BC48531762}" = Anonymizer 2005
"{E1F4FB82-3EA6-46B6-A18A-9B3A62DA393E}" = hp deskjet 6122
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E934E2A2-BE3B-4C1A-A3D9-753FFB2B38B4}" = WD Drive Manager (x86)
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{ECDBCAF5-BC83-4E03-86EB-552E7D53A94F}_is1" = AML Power Video Converter 1.2
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F86B6D9F-FA9A-4164-A66A-EAFF7C067272}_is1" = Sothink Video Encoder for Adobe Flash
"{F87BD397-DE42-4679-A91B-30E9E531711B}" = Eudora
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"7-Zip" = 7-Zip 4.57
"AC3Filter" = AC3Filter (remove only)
"ACDSee Trial Version" = ACDSee Trial Version
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Any Video Converter_is1" = Any Video Converter 3.0.5
"AVG" = AVG 2012
"BearShare" = BearShare
"BearShare Acceleration Patch_is1" = BearShare Acceleration Patch 4.5
"Canon CanoScan LiDE 600F User Registration" = Canon CanoScan LiDE 600F User Registration
"CanoScan Toolbox 5.0" = Canon CanoScan Toolbox 5.0
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"CodInstl" = Intel A/V Codecs V2.0
"CoreFTP" = Core FTP LE
"Corel Applications" = Corel Applications
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Desktop Weather by The Weather Channel" = Desktop Weather by The Weather Channel
"DivX Pro Codec Adware" = DivX Pro Codec Adware
"ERUNT_is1" = ERUNT 1.1j
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"FastStone Image Viewer" = FastStone Image Viewer 2.8
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"FLV Player" = FLV Player 2.0 (build 25)
"hp deskjet 6122 series_Driver" = hp deskjet 6122 series
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"hp print screen utility" = hp print screen utility
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IrfanView" = IrfanView (remove only)
"KeyScrambler" = KeyScrambler
"MailWasher_is1" = MailWasher
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"MasterSplitter" = MasterSplitter Program
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 7.0" = Microsoft SQL Server 7.0
"Move Networks Player_is1" = Move Networks Player for Internet Explorer
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MySQL Servers and Clients 4.0.20d" = MySQL Servers and Clients 4.0.20d
"MySQL-Front_is1" = MySQL-Front 3.1
"Netscape (7.1)" = Netscape (7.1)
"NetTracker 7.5 Lite" = NetTracker 7.5 Lite
"NewsBin5" = NewsBin Pro
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Numerology Calculator_is1" = Numerology Calculator
"oggcodecs" = oggcodecs 0.71.0946
"Opera" = Opera
"Panda ActiveScan" = Panda ActiveScan
"PartyPoker" = PartyPoker
"Poker Superstars Deluxe" = Poker Superstars Deluxe (remove only)
"PokerStars.net" = PokerStars.net
"QuickPar" = QuickPar 0.9
"RealPlayer 6.0" = RealPlayer
"Rhythm & Bio" = Rhythm & Bio
"Riva FLV Encoder 2.0_is1" = Riva FLV Encoder 2.0
"Secunia PSI" = Secunia PSI (2.0.0.4003)
"SmartFTP Client 2.0 Setup Files" = SmartFTP Client 2.0 Setup Files (remove only)
"SUPER ©" = SUPER © Version 2009.bld.36 (June 10, 2009)
"TopStyle Lite (Version 2)" = TopStyle Lite (Version 2)
"Tweak UI 2.10" = Tweak UI
"Uninstall Macromedia ColdFusion MX 7" = Macromedia ColdFusion MX 7
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"VLC media player" = VLC media player 1.0.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebSTAR DPC2100 Uninstall" = Scientific-Atlanta WebSTAR 2000 series Cable Modem
"WIC" = Windows Imaging Component
"Winamp" = Winamp (Remove Only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMA To MP3 Converter" = WMA To MP3 Converter
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xenu_is1" = Xenu's Link Sleuth
"ZoneAlarm" = ZoneAlarm
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"ColdFusion Studio 4.5" = ColdFusion Studio 4.5
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 6/4/2012 5:22:23 PM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application opera.exe, version 8.51.7712.0, faulting module
ntdll.dll, version 5.1.2600.6055, fault address 0x00010a1b.
Error - 6/5/2012 5:45:36 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module msvcrt.dll, version 7.0.2600.5512, fault address 0x00037fd4.
Error - 6/5/2012 5:51:09 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.
Error - 6/5/2012 5:55:48 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.
Error - 6/5/2012 5:55:58 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.
Error - 6/5/2012 11:11:30 AM | Computer Name = BUD | Source = Application Error | ID = 1000
Description = Faulting application dllhost.exe, version 5.1.2600.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x00019af2.
Error - 6/6/2012 6:55:11 PM | Computer Name = BUD | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.
Error - 6/7/2012 8:24:05 AM | Computer Name = BUD | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1593.0,
P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.
Error - 6/8/2012 9:26:33 AM | Computer Name = BUD | Source = MsiInstaller | ID = 11722
Description = SA_Error1709: StandardAction(0xC00706AD): Product: AVG 2012 – Error
1722. SA_Error1722: StandardAction(0xC00706BA): There is a problem with this Windows
Installer package. A program run as part of the setup did not finish as expected.
Contact your support personnel or package vendor. Action RegisterTuneUp, location:
C:\Program Files\AVG\AVG2012\PCTuneup\MicroScanner.exe, command: -REGSERVER
Error - 6/8/2012 6:55:34 PM | Computer Name = BUD | Source = MsiInstaller | ID = 11704
Description = Product: Java™ 6 Update 31 – Error 1704.An installation for AVG
2012 is currently suspended. You must undo the changes made by that installation
to continue. Do you want to undo those changes?
[ System Events ]
Error - 6/17/2012 8:02:10 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 6/17/2012 8:03:52 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 6/17/2012 8:04:00 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 6/17/2012 8:06:54 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 6/17/2012 8:08:51 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 6/17/2012 8:13:23 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}
Error - 6/17/2012 8:13:49 PM | Computer Name = BUD | Source = Service Control Manager | ID = 7001
Description = The World Wide Web Publishing service depends on the IIS Admin service
which failed to start because of the following error: %%1058
Error - 6/17/2012 8:17:01 PM | Computer Name = BUD | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {601D72B9-326F-46CD-815E-12D5D15761BA}.
The
error: "%2" Happened while starting this command: "c:\PROGRA~1\mcafee\SITEAD~1\saui.exe"
-Embedding
Error - 6/17/2012 8:24:22 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}
Error - 6/17/2012 8:24:31 PM | Computer Name = BUD | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service IISADMIN with
arguments "" in order to run the server: {A9E69610-B80D-11D0-B9B9-00A0C922E750}
< End of report >
Here is my aswMBR.txt file:
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-06-17 14:57:34
—————————–
14:57:34.593 OS Version: Windows 5.1.2600 Service Pack 3
14:57:34.593 Number of processors: 1 586 0x1C00
14:57:34.593 ComputerName: BUD UserName:
14:57:35.296 Initialize success
14:58:56.140 AVAST engine defs: 12061700
15:02:28.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-13
15:02:28.203 Disk 0 Vendor: ST3100011A 3.02 Size: 95396MB BusType: 3
15:02:28.203 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-1b
15:02:28.218 Disk 1 Vendor: ST3160023A 8.01 Size: 152627MB BusType: 3
15:02:28.234 Disk 0 MBR read successfully
15:02:28.234 Disk 0 MBR scan
15:02:28.265 Disk 0 Windows XP default MBR code
15:02:28.296 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63
15:02:28.312 Disk 0 scanning sectors +195366465
15:02:28.406 Disk 0 scanning C:\WINDOWS\system32\drivers
15:02:41.468 Service scanning
15:03:06.968 Service vsdatant C:\WINDOWS\System32\vsdatant.sys **LOCKED** 32
15:03:10.625 Modules scanning
15:03:20.296 Disk 0 trace - called modules:
15:03:20.343 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys PCIIDEX.SYS
15:03:20.343 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa5aab8]
15:03:20.343 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000062[0x8aa93bd0]
15:03:20.359 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-13[0x8a9f2940]
15:03:20.640 AVAST engine scan C:\WINDOWS
15:03:45.000 AVAST engine scan C:\WINDOWS\system32
15:06:45.203 AVAST engine scan C:\WINDOWS\system32\drivers
15:07:03.203 AVAST engine scan C:\Documents and Settings\Ike
15:23:58.312 AVAST engine scan C:\Documents and Settings\All Users
15:27:46.203 Scan finished successfully
15:40:32.140 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ike\Desktop\MBR.dat"
15:40:32.156 The log file has been saved successfully to "C:\Documents and Settings\Ike\Desktop\aswMBR.txt"
Attached is the Zip file (finally got it to work).
Thank you,
Ike