This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HiJackThis Log

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My system is running slower than usualy and periodically new browser windows will open up on their own. AVG detected and removed several threats, all except 1. When I tried to use AVG to do a forced removal of the fial threat my system crashed. After rebooting I manually deleted the file that AVG specified (which I realize now was probably a bad move). Have since installed ERUNT and made a backup of my registry. Thanks in advance for any assistance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:15 AM, on 2/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\system\smss.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\TDxVGAUTIL.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJYQiHY.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8B638B80-10C3-453E-B96C-AE11F0457B2D} - C:\WINDOWS\system32\awttRIBu.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: worldadmarketplace - {bc0db5b2-d324-f718-8833-0bcba86e26bf} - C:\WINDOWS\system32\nsv723.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: worldadmarketplace browser enhancer - {F178D686-F66C-F209-0234-1ED4A635C4F8} - C:\WINDOWS\system32\qyyvcskqfmbtfcym.dll (file missing)
O2 - BHO: {9b3e0fe9-a1eb-e349-4834-cc3d22a47f2f} - {f2f74a22-d3cc-4384-943e-be1a9ef0e3b9} - C:\WINDOWS\system32\egrtxv.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [TDxVGAUTIL] C:\WINDOWS\system32\TDxVGAUTIL.EXE
O4 - HKLM\..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [d89cf6b4] rundll32.exe "C:\WINDOWS\system32\pbngkyvc.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Cortex AutoLogon for Microsoft Outlook.lnk = C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.yanceyrod.com/view/tiffx.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1166133209843
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CAB38AF9-1760-46DF-91C9-E280EC07A2A2}: NameServer = 69.78.96.14 66.174.95.44
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL egrtxv.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: ljJYQiHY - ljJYQiHY.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logical Disk Manager (NDIS) - Unknown owner - C:\Program Files\system\smss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 15559 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
I followed your instructions however Extras.txt was never created…never opened and there is no copy of it in the same location as OTListIt2. I ran the scan a few times to be sure. I did get a Scan Complete message each time but only the one file.

Here is OTListIt.txt…

Thanks.

OTListIt logfile created on: 2/5/2009 3:30:39 PM - Run 3
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\od\Desktop\OTListIt2
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.11 Mb Total Physical Memory | 570.04 Mb Available Physical Memory | 56.21% Memory free
2.38 Gb Paging File | 1.12 Gb Available in Paging File | 47.14% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 40.13 Gb Free Space | 46.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TVGVAIO
Current User Name: od
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
C:\Program Files\system\smss.exe ()
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
C:\WINDOWS\ehome\ehmsas.exe (Microsoft Corporation)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
C:\Program Files\DISC\DISCUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\WINDOWS\system32\Tdxvgautil.exe (Generic Provider)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\Documents and Settings\od\Desktop\OTListIt2\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment [On_Demand | Stopped]) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Logical Disk Manager (NDIS) [Auto | Running]) – C:\Program Files\system\smss.exe ()
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\system32\mhn.dll (Microsoft Corporation)
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (MSSQL$VAIO_VEDB [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SonicStageMonitoring [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (SQLAgent$VAIO_VEDB [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VAIO Event Service [Auto | Running]) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (Vcsw [On_Demand | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ADM851X [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ADM851X.sys (ADMtek Incorporated)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (cmudau [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmudaxu.sys (C-Media Inc)
DRV - (DMICall [System | Running]) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (e1express [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hpzid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PTDCBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCWWAN [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SI3132 [Boot | Running]) – C:\WINDOWS\system32\drivers\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\system32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) – C:\WINDOWS\system32\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SMNDIS5 [On_Demand | Running]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (SNC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (SonyImgF [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (TdxMrMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxMrMini.sys (Generic Provider.)
DRV - (TdxVGAMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxVgaMini.sys (Generic Provider.)
DRV - (TdxVGAUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\TdxVGAUSB.sys (Generic Provider.)
DRV - (ti21sony [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (tosporte [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom [System | Running]) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfnds [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (U2SP [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\U2S2KXP.sys (Magic Control Technology Corp.)
DRV - (usbvm321 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (1030 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.0.1.178 www.los-testweb
O1 - Hosts: 10.0.1.178 los-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-officetimesheets
O1 - Hosts: 10.0.1.148 www.st-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-TestArea
O1 - Hosts: 10.0.1.178 los-TestArea
O1 - Hosts: 10.0.1.178 los-lookout
O1 - Hosts: 10.0.1.178 www.los-lookout
O1 - Hosts: 10.0.1.178 www.los-rsscalendarv2
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJYQiHY.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (no name) - {8B638B80-10C3-453E-B96C-AE11F0457B2D} - C:\WINDOWS\system32\awttRIBu.dll File not found
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (worldadmarketplace) - {bc0db5b2-d324-f718-8833-0bcba86e26bf} - C:\WINDOWS\system32\nsv723.dll File not found
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O2 - BHO: (worldadmarketplace browser enhancer) - {F178D686-F66C-F209-0234-1ED4A635C4F8} - C:\WINDOWS\system32\qyyvcskqfmbtfcym.dll File not found
O2 - BHO: (no name) - {f2f74a22-d3cc-4384-943e-be1a9ef0e3b9} - C:\WINDOWS\system32\egrtxv.dll ()
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [d89cf6b4] rundll32.exe "C:\WINDOWS\system32\pbngkyvc.dll",b File not found
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TDxVGAUTIL] C:\WINDOWS\system32\TDxVGAUTIL.EXE (Generic Provider)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary (Sony Corporation)
O4 - HKLM..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" (Sony Corporation)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Cortex AutoLogon for Microsoft Outlook.lnk = C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Sites: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.yanceyrod.com/view/tiffx.cab (AlternaTIFF ActiveX)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/download/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {5420B688-FDB2-41EB-9C8B-FE7DFEAA496F} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1166133209843 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL egrtxv.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\system32\VESWinlogon.dll (Sony Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJYQiHY.dll File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\awttRIBu) - File not found
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{6d65cb8a-bf63-11da-981c-806d6172696f}\Shell\AutoRun\command - "" = E:\sony\Autorun.exe – File not found
O33 - MountPoints2\{94cbac49-78f5-11dc-b311-0013a913497f}\Shell\AutoRun\command - "" = F:\PortableVault.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/05 15:20:24 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\OTListIt2
[2009/02/04 11:46:34 | 00,001,734 | —- | C] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:32 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/04 11:13:05 | 00,000,767 | —- | C] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | C] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | C] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 11:12:40 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/02/04 11:11:33 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\Erunt
[2009/02/04 11:06:53 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/04 11:05:11 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\HijackThis
[2009/02/03 07:44:39 | 00,078,336 | —- | C] () – C:\WINDOWS\System32\svschost.exe
[2009/02/03 07:44:39 | 00,078,336 | —- | C] () – C:\WINDOWS\System32\svñshost.exe
[2009/02/03 07:13:46 | 00,000,000 | —D | C] – C:\Program Files\system
[2009/02/03 00:18:42 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/02/03 00:11:59 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 32,763,955 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/03 00:11:44 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:44 | 00,085,942 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/03 00:11:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/02/03 00:11:43 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\AVGTOOLBAR
[2009/02/03 00:11:23 | 00,107,272 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 23:27:23 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\AVG 8.0 Free
[2009/02/02 23:19:08 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\stu2.exe
[2009/02/02 23:17:53 | 00,085,301 | —- | C] () – C:\WINDOWS\System32\cont_worldadmarketplace-remove.exe
[2009/02/02 23:14:47 | 00,048,266 | —- | C] () – C:\WINDOWS\System32\onlbnqsmdcb.exe
[2009/02/02 23:13:44 | 00,127,488 | —- | C] () – C:\WINDOWS\System32\egrtxv.dll
[2009/02/02 23:13:32 | 01,550,299 | -HS- | C] () – C:\WINDOWS\System32\cvykgnbp.ini
[2009/02/01 23:08:24 | 01,550,288 | -HS- | C] () – C:\WINDOWS\System32\dtalgobt.ini
[2009/02/01 23:07:27 | 00,277,830 | -HS- | C] () – C:\WINDOWS\System32\uBIRttwa.ini2
[2009/02/01 23:07:27 | 00,277,830 | -HS- | C] () – C:\WINDOWS\System32\uBIRttwa.ini
[2009/02/01 23:02:31 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\cogad
[2009/02/01 23:02:19 | 00,000,310 | —- | C] () – C:\WINDOWS\tasks\cxvzgqgo.job
[2009/02/01 23:02:15 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\GetModule
[2009/02/01 23:02:14 | 00,000,000 | —D | C] – C:\Program Files\GetModule
[2009/02/01 23:02:13 | 00,000,000 | —D | C] – C:\Program Files\iCheck
[2009/01/20 15:20:21 | 00,000,494 | —- | C] () – C:\hpfr5550.xml
[2009/01/20 15:10:22 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\Hewlett-Packard
[2009/01/20 15:08:49 | 00,000,396 | —- | C] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:03:20 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2009/01/20 15:01:23 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/20 15:00:26 | 00,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2009/01/20 14:58:57 | 00,019,558 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 14:58:57 | 00,016,606 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2009/01/20 13:47:23 | 00,000,000 | —D | C] – C:\Program Files\Hp
[2009/01/14 11:08:46 | 16,375,382 | —- | C] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\od\Local Settings\Application Data\*.tmp files]
[2009/02/05 15:18:46 | 00,000,494 | —- | M] () – C:\hpfr5550.xml
[2009/02/04 14:47:18 | 00,000,044 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2009/02/04 12:51:40 | 00,000,832 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/04 11:46:34 | 00,001,734 | —- | M] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:05 | 00,000,767 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | M] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | M] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 11:00:00 | 00,000,310 | —- | M] () – C:\WINDOWS\tasks\cxvzgqgo.job
[2009/02/04 10:59:49 | 00,001,893 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2009/02/04 10:59:16 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/04 10:58:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/04 10:58:22 | 10,634,40384 | -HS- | M] () – C:\hiberfil.sys
[2009/02/04 10:58:22 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/04 10:56:15 | 00,277,830 | -HS- | M] () – C:\WINDOWS\System32\uBIRttwa.ini
[2009/02/04 10:55:16 | 32,763,955 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 10:54:59 | 00,277,830 | -HS- | M] () – C:\WINDOWS\System32\uBIRttwa.ini2
[2009/02/04 10:34:11 | 00,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/04 10:34:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/03 13:18:33 | 01,550,299 | -HS- | M] () – C:\WINDOWS\System32\cvykgnbp.ini
[2009/02/03 07:44:39 | 00,078,336 | —- | M] () – C:\WINDOWS\System32\svschost.exe
[2009/02/03 07:44:39 | 00,078,336 | —- | M] () – C:\WINDOWS\System32\svñshost.exe
[2009/02/03 02:06:40 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/03 02:06:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/03 00:14:21 | 00,085,942 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/03 00:11:59 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:23 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 23:17:53 | 00,085,301 | —- | M] () – C:\WINDOWS\System32\cont_worldadmarketplace-remove.exe
[2009/02/02 23:14:47 | 00,048,266 | —- | M] () – C:\WINDOWS\System32\onlbnqsmdcb.exe
[2009/02/02 23:13:44 | 00,127,488 | —- | M] () – C:\WINDOWS\System32\egrtxv.dll
[2009/02/02 22:37:45 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/02/02 22:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/02/02 19:08:05 | 04,815,422 | -H– | M] () – C:\Documents and Settings\od\Local Settings\Application Data\IconCache.db
[2009/02/02 18:42:05 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/02 14:47:44 | 01,550,288 | -HS- | M] () – C:\WINDOWS\System32\dtalgobt.ini
[2009/01/31 11:14:13 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/31 11:14:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/31 11:01:49 | 00,000,577 | —- | M] () – C:\Documents and Settings\od\My Documents\My Sharing Folders.lnk
[2009/01/21 11:50:01 | 00,190,464 | —- | M] () – C:\Documents and Settings\od\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/20 15:08:50 | 00,000,396 | —- | M] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:08:03 | 00,019,558 | —- | M] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 15:01:23 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/14 11:05:42 | 16,375,382 | —- | M] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG
[2009/01/09 20:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/08 22:15:46 | 00,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/08 22:15:46 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm

========== LOP Check ==========

[2009/02/03 00:09:10 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/01 21:24:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/02/13 17:46:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/03/13 11:06:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2006/11/17 16:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/07/06 11:27:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/12/31 12:59:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/04 10:58:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/10/24 16:57:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Interactive Systems Corporation
[2009/01/19 01:11:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2006/03/15 20:46:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2006/03/29 15:58:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2007/01/16 17:50:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/03/17 19:16:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2007/10/12 16:50:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2006/12/18 10:33:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OfficeCalendar
[2006/08/13 18:37:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2006/03/15 20:26:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2006/06/23 17:50:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony Corporation
[2006/11/17 17:04:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2006/03/29 16:02:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VAIO Media Platform
[2006/08/13 18:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/07/09 15:03:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WholeSecurity
[2006/12/08 15:25:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2006/12/12 11:39:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/02/03 00:11:43 | 00,000,000 | RH-D | M] – C:\Documents and Settings\od\Application Data
[2008/03/10 18:02:29 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Adobe
[2007/02/05 13:09:29 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\AdobeUM
[2006/11/17 13:40:59 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\AOL
[2008/01/04 14:43:59 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Apple Computer
[2009/02/03 03:45:35 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\AVGTOOLBAR
[2009/02/03 02:09:25 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\cogad
[2006/12/19 13:09:33 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook
[2009/02/01 23:02:48 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\GetModule
[2006/12/13 13:22:53 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Google
[2007/03/12 08:31:10 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Help
[2009/01/20 15:10:22 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Hewlett-Packard
[2006/03/15 20:16:54 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Identities
[2006/06/13 14:34:25 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\InterVideo
[2006/03/29 15:58:59 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Intuit
[2006/11/27 10:39:38 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Leadertech
[2007/11/13 13:02:58 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\LinkedIn
[2006/06/23 13:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Macromedia
[2008/03/24 11:42:04 | 00,000,000 | –SD | M] – C:\Documents and Settings\od\Application Data\Microsoft
[2006/12/14 16:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\OfficeUpdate12
[2007/12/13 12:45:38 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Opera
[2008/12/10 13:44:52 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Real
[2008/08/21 18:45:41 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\RssPopper
[2007/03/01 02:14:17 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\SmartDraw
[2008/10/15 20:11:17 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Smith Micro
[2006/11/27 10:39:47 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Sonic
[2006/09/02 20:14:53 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Sony Corporation
[2006/12/26 15:52:03 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Sun
[2006/10/21 19:16:09 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Template
[2007/11/27 17:32:52 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\Viewpoint
[2007/11/13 18:23:41 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\WinRAR
[2006/08/13 18:38:25 | 00,000,000 | —D | M] – C:\Documents and Settings\od\Application Data\You've Got Pictures Screensaver
[2009/02/02 18:42:05 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2009/02/04 11:00:00 | 00,000,310 | —- | M] () – C:\WINDOWS\Tasks\cxvzgqgo.job
[2004/08/10 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/01/20 15:08:50 | 00,000,396 | —- | M] () – C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/02/04 10:58:25 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\System32\Thumbs.db:encryptable
< End of report >
hello


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJYQiHY.dll File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
    O2 - BHO: (no name) - {8B638B80-10C3-453E-B96C-AE11F0457B2D} - C:\WINDOWS\system32\awttRIBu.dll File not found
    O2 - BHO: (worldadmarketplace browser enhancer) - {F178D686-F66C-F209-0234-1ED4A635C4F8} - C:\WINDOWS\system32\qyyvcskqfmbtfcym.dll File not found
    O2 - BHO: (no name) - {f2f74a22-d3cc-4384-943e-be1a9ef0e3b9} - C:\WINDOWS\system32\egrtxv.dll ()
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key does not exist or could not be opened. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key does not exist or could not be opened. File not found
    O4 - HKLM..\Run: [d89cf6b4] rundll32.exe "C:\WINDOWS\system32\pbngkyvc.dll",b File not found
    O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
    O28 - HKLM ShellExecuteHooks: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJYQiHY.dll File not found
    O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
    O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\awttRIBu) - File not found
    O33 - MountPoints2\{6d65cb8a-bf63-11da-981c-806d6172696f}\Shell\AutoRun\command - "" = E:\sony\Autorun.exe – File not found
    O33 - MountPoints2\{94cbac49-78f5-11dc-b311-0013a913497f}\Shell\AutoRun\command - "" = F:\PortableVault.exe – File not found
    [2009/02/03 07:44:39 | 00,078,336 | —- | C] () – C:\WINDOWS\System32\svschost.exe
    [2009/02/03 07:44:39 | 00,078,336 | —- | C] () – C:\WINDOWS\System32\svñshost.exe
    [2009/02/03 07:13:46 | 00,000,000 | —D | C] – C:\Program Files\system
    [2009/02/02 23:19:08 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\stu2.exe
    [2009/02/02 23:17:53 | 00,085,301 | —- | C] () – C:\WINDOWS\System32\cont_worldadmarketplace-remove.exe
    [2009/02/02 23:14:47 | 00,048,266 | —- | C] () – C:\WINDOWS\System32\onlbnqsmdcb.exe
    [2009/02/02 23:13:44 | 00,127,488 | —- | C] () – C:\WINDOWS\System32\egrtxv.dll
    [2009/02/02 23:13:32 | 01,550,299 | -HS- | C] () – C:\WINDOWS\System32\cvykgnbp.ini
    [2009/02/01 23:08:24 | 01,550,288 | -HS- | C] () – C:\WINDOWS\System32\dtalgobt.ini
    [2009/02/01 23:07:27 | 00,277,830 | -HS- | C] () – C:\WINDOWS\System32\uBIRttwa.ini2
    [2009/02/01 23:07:27 | 00,277,830 | -HS- | C] () – C:\WINDOWS\System32\uBIRttwa.ini
    [2009/02/01 23:02:31 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\cogad
    [2009/02/01 23:02:19 | 00,000,310 | —- | C] () – C:\WINDOWS\tasks\cxvzgqgo.job
    [2009/02/01 23:02:15 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\GetModule
    [2009/02/01 23:02:14 | 00,000,000 | —D | C] – C:\Program Files\GetModule
    [2009/02/01 23:02:13 | 00,000,000 | —D | C] – C:\Program Files\iCheck
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
quick clarification please…should I check the LOP and Purity the first time I rerun it and uncheck it the 2nd or leave them unchecked both times?
========== OTLISTIT ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8B638B80-10C3-453E-B96C-AE11F0457B2D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F178D686-F66C-F209-0234-1ED4A635C4F8}\ deleted successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\egrtxv.dll C:\WINDOWS\system32\egrtxv.dll NOT unregistered. C:\WINDOWS\system32\egrtxv.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f2f74a22-d3cc-4384-943e-be1a9ef0e3b9}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\d89cf6b4 deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\\ljJYQiHY not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digeste.dll deleted successfully. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\awttRIBu deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d65cb8a-bf63-11da-981c-806d6172696f}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{94cbac49-78f5-11dc-b311-0013a913497f}\ deleted successfully. C:\WINDOWS\System32\svschost.exe moved successfully. C:\WINDOWS\System32\svñshost.exe moved successfully. C:\Program Files\system moved successfully. C:\WINDOWS\System32\stu2.exe moved successfully. C:\WINDOWS\System32\cont_worldadmarketplace-remove.exe moved successfully. C:\WINDOWS\System32\onlbnqsmdcb.exe moved successfully. LoadLibrary failed for C:\WINDOWS\System32\egrtxv.dll C:\WINDOWS\System32\egrtxv.dll NOT unregistered. File move failed. C:\WINDOWS\System32\egrtxv.dll scheduled to be moved on reboot. C:\WINDOWS\System32\cvykgnbp.ini moved successfully. C:\WINDOWS\System32\dtalgobt.ini moved successfully. C:\WINDOWS\System32\uBIRttwa.ini2 moved successfully. C:\WINDOWS\System32\uBIRttwa.ini moved successfully. C:\Documents and Settings\od\Application Data\cogad moved successfully. C:\WINDOWS\tasks\cxvzgqgo.job moved successfully. C:\Documents and Settings\od\Application Data\GetModule moved successfully. C:\Program Files\GetModule moved successfully. C:\Program Files\iCheck moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\od\Local Settings\Temp\Acr8710.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\od\Local Settings\Temp\~DFDCF1.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JETD224.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_398.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.5 log created on 02052009_155455 Files moved on Reboot… File C:\WINDOWS\System32\egrtxv.dll not found! File C:\Documents and Settings\od\Local Settings\Temp\Acr8710.tmp not found! C:\Documents and Settings\od\Local Settings\Temp\~DFDCF1.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\JETD224.tmp not found! C:\WINDOWS\temp\Perflib_Perfdata_398.dat moved successfully. Registry entries deleted on Reboot…
oops…

OTListIt logfile created on: 2/5/2009 4:32:16 PM - Run 6
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\od\Desktop\OTListIt2
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.11 Mb Total Physical Memory | 441.81 Mb Available Physical Memory | 43.57% Memory free
2.38 Gb Paging File | 1.85 Gb Available in Paging File | 77.82% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 41.60 Gb Free Space | 48.28% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TVGVAIO
Current User Name: od
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
C:\WINDOWS\ehome\ehmsas.exe (Microsoft Corporation)
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
C:\Program Files\DISC\DISCUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\WINDOWS\system32\Tdxvgautil.exe (Generic Provider)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
C:\WINDOWS\system32\HPZipm12.exe (HP)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Co.)
C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\aAvgApi.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgui.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Documents and Settings\od\Desktop\OTListIt2\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment [On_Demand | Stopped]) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Logical Disk Manager (NDIS) [Auto | Stopped]) – File not found
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\system32\mhn.dll (Microsoft Corporation)
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (MSSQL$VAIO_VEDB [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SonicStageMonitoring [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (SQLAgent$VAIO_VEDB [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VAIO Event Service [Auto | Running]) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (Vcsw [On_Demand | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ADM851X [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ADM851X.sys (ADMtek Incorporated)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (cmudau [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmudaxu.sys (C-Media Inc)
DRV - (DMICall [System | Running]) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (e1express [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hpzid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PTDCBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCWWAN [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SI3132 [Boot | Running]) – C:\WINDOWS\system32\drivers\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\system32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) – C:\WINDOWS\system32\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SMNDIS5 [On_Demand | Running]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (SNC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (SonyImgF [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (TdxMrMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxMrMini.sys (Generic Provider.)
DRV - (TdxVGAMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxVgaMini.sys (Generic Provider.)
DRV - (TdxVGAUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\TdxVGAUSB.sys (Generic Provider.)
DRV - (ti21sony [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (tosporte [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom [System | Running]) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfnds [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (U2SP [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\U2S2KXP.sys (Magic Control Technology Corp.)
DRV - (usbvm321 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (1030 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.0.1.178 www.los-testweb
O1 - Hosts: 10.0.1.178 los-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-officetimesheets
O1 - Hosts: 10.0.1.148 www.st-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-TestArea
O1 - Hosts: 10.0.1.178 los-TestArea
O1 - Hosts: 10.0.1.178 los-lookout
O1 - Hosts: 10.0.1.178 www.los-lookout
O1 - Hosts: 10.0.1.178 www.los-rsscalendarv2
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (worldadmarketplace) - {bc0db5b2-d324-f718-8833-0bcba86e26bf} - C:\WINDOWS\system32\nsv723.dll File not found
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TDxVGAUTIL] C:\WINDOWS\system32\TDxVGAUTIL.EXE (Generic Provider)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary (Sony Corporation)
O4 - HKLM..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" (Sony Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Cortex AutoLogon for Microsoft Outlook.lnk = C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Sites: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Sites: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.yanceyrod.com/view/tiffx.cab (AlternaTIFF ActiveX)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/download/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {5420B688-FDB2-41EB-9C8B-FE7DFEAA496F} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1166133209843 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL egrtxv.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\system32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/05 16:06:36 | 00,000,450 | —- | C] () – C:\WINDOWS\tasks\WebReg 20090205160636.job
[2009/02/05 15:54:55 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 15:20:24 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\OTListIt2
[2009/02/04 11:46:34 | 00,001,734 | —- | C] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:32 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/04 11:13:05 | 00,000,767 | —- | C] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | C] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | C] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 11:12:40 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/02/04 11:11:33 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\Erunt
[2009/02/04 11:06:53 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/04 11:05:11 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\HijackThis
[2009/02/03 00:18:42 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/02/03 00:11:59 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 32,820,251 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/03 00:11:44 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:44 | 00,086,834 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/03 00:11:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/02/03 00:11:43 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\AVGTOOLBAR
[2009/02/03 00:11:23 | 00,107,272 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 23:27:23 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\AVG 8.0 Free
[2009/01/20 15:20:21 | 00,000,494 | —- | C] () – C:\hpfr5550.xml
[2009/01/20 15:10:22 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\Hewlett-Packard
[2009/01/20 15:08:49 | 00,000,396 | —- | C] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:03:20 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2009/01/20 15:01:23 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/20 15:00:26 | 00,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2009/01/20 14:58:57 | 00,019,558 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 14:58:57 | 00,016,606 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2009/01/20 13:47:23 | 00,000,000 | —D | C] – C:\Program Files\Hp
[2009/01/14 11:08:46 | 16,375,382 | —- | C] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\od\Local Settings\Application Data\*.tmp files]
[2009/02/05 16:09:28 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/05 16:09:27 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/05 16:06:37 | 00,000,450 | —- | M] () – C:\WINDOWS\tasks\WebReg 20090205160636.job
[2009/02/05 16:05:53 | 00,000,832 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/05 16:05:39 | 00,001,893 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2009/02/05 16:04:20 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 16:02:59 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 16:02:56 | 10,634,40384 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 16:02:56 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 16:00:40 | 00,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/02/05 16:00:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/02/05 15:18:46 | 00,000,494 | —- | M] () – C:\hpfr5550.xml
[2009/02/04 14:47:18 | 00,000,044 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2009/02/04 11:46:34 | 00,001,734 | —- | M] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:05 | 00,000,767 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | M] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | M] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 10:34:11 | 00,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/04 10:34:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/03 02:06:40 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/03 02:06:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/03 00:11:59 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:23 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 22:37:45 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/02/02 22:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/02/02 19:08:05 | 04,815,422 | -H– | M] () – C:\Documents and Settings\od\Local Settings\Application Data\IconCache.db
[2009/02/02 18:42:05 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/31 11:14:13 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/31 11:14:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/31 11:01:49 | 00,000,577 | —- | M] () – C:\Documents and Settings\od\My Documents\My Sharing Folders.lnk
[2009/01/21 11:50:01 | 00,190,464 | —- | M] () – C:\Documents and Settings\od\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/20 15:08:50 | 00,000,396 | —- | M] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:08:03 | 00,019,558 | —- | M] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 15:01:23 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/14 11:05:42 | 16,375,382 | —- | M] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG
[2009/01/09 20:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/08 22:15:46 | 00,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/08 22:15:46 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\System32\Thumbs.db:encryptable
< End of report >
hello



Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O2 - BHO: (worldadmarketplace) - {bc0db5b2-d324-f718-8833-0bcba86e26bf} - C:\WINDOWS\system32\nsv723.dll File not found
    O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )




Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
I haven't done the ATF Cleaner, Malwarebytes or the Kaspersky web scan yet…

OTListIt logfile created on: 2/5/2009 4:50:34 PM - Run 8
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\od\Desktop\OTListIt2
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.11 Mb Total Physical Memory | 493.32 Mb Available Physical Memory | 48.65% Memory free
2.38 Gb Paging File | 1.94 Gb Available in Paging File | 81.35% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 86.16 Gb Total Space | 41.60 Gb Free Space | 48.29% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Unable to calculate disk information.
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TVGVAIO
Current User Name: od
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\WINDOWS\system32\igfxext.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
C:\WINDOWS\ehome\ehmsas.exe (Microsoft Corporation)
C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe (Sony Corporation)
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (Sony Corporation)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
C:\Program Files\DISC\DISCUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\WINDOWS\system32\Tdxvgautil.exe (Generic Provider)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\DISC\DiscStreamHub.exe (Digital Interactive Systems Corporation, Inc.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe (Hewlett-Packard Co.)
C:\WINDOWS\system32\HPZipm12.exe (HP)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe (Hewlett-Packard Co.)
C:\Documents and Settings\od\Desktop\OTListIt2\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ehRecvr [Auto | Running]) – C:\WINDOWS\ehome\ehrecvr.exe (Microsoft Corporation)
SRV - (ehSched [Auto | Running]) – C:\WINDOWS\ehome\ehSched.exe (Microsoft Corporation)
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoogleDesktopManager-061008-081103 [On_Demand | Stopped]) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (IISADMIN [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Image Converter video recording monitor for VAIO Entertainment [On_Demand | Stopped]) – C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (Logical Disk Manager (NDIS) [Auto | Stopped]) – File not found
SRV - (McrdSvc [Auto | Running]) – C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (MHN [On_Demand | Stopped]) – C:\WINDOWS\system32\mhn.dll (Microsoft Corporation)
SRV - (MSCSPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (MSSQL$VAIO_VEDB [Auto | Running]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PACSPTISVR [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Running]) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SMTPSVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SonicStageMonitoring [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe (Sony Corporation)
SRV - (SPTISRV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (SQLAgent$VAIO_VEDB [On_Demand | Stopped]) – C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (SSScsiSV [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (VAIO Event Service [Auto | Running]) – C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-AppServer [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-HTTP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-IntegratedServer-UPnP [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)
SRV - (VAIOMediaPlatform-Mobile-Gateway [On_Demand | Stopped]) – C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)
SRV - (Vcsw [On_Demand | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VzFw [Auto | Running]) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)
SRV - (W3SVC [Auto | Running]) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ADM851X [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ADM851X.sys (ADMtek Incorporated)
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (cmudau [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\cmudaxu.sys (C-Media Inc)
DRV - (DMICall [System | Running]) – C:\WINDOWS\system32\drivers\DMICall.sys (Sony Corporation)
DRV - (E100B [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (e1express [On_Demand | Running]) – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HPZid412 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hpzid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HSFHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (PTDCBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCBus.sys (DEVGURU Co,LTD.)
DRV - (PTDCMdm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDCVsp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDCWWAN [On_Demand | Running]) – C:\WINDOWS\system32\drivers\PTDCWWAN.sys (DEVGURU Co,LTD.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SI3132 [Boot | Running]) – C:\WINDOWS\system32\drivers\SI3132.sys (Silicon Image, Inc.)
DRV - (SiFilter [Boot | Running]) – C:\WINDOWS\system32\drivers\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil [Boot | Running]) – C:\WINDOWS\system32\drivers\SiRemFil.sys (Silicon Image, Inc.)
DRV - (SMNDIS5 [On_Demand | Running]) – C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (SNC [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyNC.sys (Sony Corporation)
DRV - (SonyImgF [On_Demand | Running]) – C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (TdxMrMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxMrMini.sys (Generic Provider.)
DRV - (TdxVGAMINI [On_Demand | Running]) – C:\WINDOWS\system32\drivers\TdxVgaMini.sys (Generic Provider.)
DRV - (TdxVGAUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\TdxVGAUSB.sys (Generic Provider.)
DRV - (ti21sony [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ti21sony.sys (Texas Instruments)
DRV - (tosporte [On_Demand | Running]) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfbd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (Tosrfbnp [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfcom [System | Running]) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (Tosrfhid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfhid.sys (TOSHIBA Corporation.)
DRV - (tosrfnds [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Tosrfusb [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (U2SP [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\U2S2KXP.sys (Magic Control Technology Corp.)
DRV - (usbvm321 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbvm321.sys (Vimicro Corporation)
DRV - (w39n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;

O1 HOSTS File: (1030 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 10.0.1.178 www.los-testweb
O1 - Hosts: 10.0.1.178 los-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-officetimesheets
O1 - Hosts: 10.0.1.148 www.st-officetimesheets
O1 - Hosts: 10.0.1.178 www.los-TestArea
O1 - Hosts: 10.0.1.178 los-TestArea
O1 - Hosts: 10.0.1.178 los-lookout
O1 - Hosts: 10.0.1.178 www.los-lookout
O1 - Hosts: 10.0.1.178 www.los-rsscalendarv2
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe (Digital Interactive Systems Corporation)
O4 - HKLM..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdMgr.exe (Digital Interactive Systems Corporation, Inc.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (Sony Corporation)
O4 - HKLM..\Run: [TDxVGAUTIL] C:\WINDOWS\system32\TDxVGAUTIL.EXE (Generic Provider)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe (Sony Electronics Inc)
O4 - HKLM..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary (Sony Corporation)
O4 - HKLM..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" (Sony Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\Cortex AutoLogon for Microsoft Outlook.lnk = C:\Documents and Settings\od\Application Data\Cortex AutoLogon for Microsoft Outlook\AutoLogon.exe (Cortex)
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe (Smith Micro Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Sites: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Sites: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} http://www.yanceyrod.com/view/tiffx.cab (AlternaTIFF ActiveX)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://www.ipix.com/download/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {5420B688-FDB2-41EB-9C8B-FE7DFEAA496F} http://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1166133209843 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DDRevision Class)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL egrtxv.dll) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\WINDOWS\system32\VESWinlogon.dll (Sony Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/02/05 16:06:36 | 00,000,450 | —- | C] () – C:\WINDOWS\tasks\WebReg 20090205160636.job
[2009/02/05 15:54:55 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 15:20:24 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\OTListIt2
[2009/02/04 11:46:34 | 00,001,734 | —- | C] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:32 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/04 11:13:05 | 00,000,767 | —- | C] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | C] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | C] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 11:12:40 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/02/04 11:11:33 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\Erunt
[2009/02/04 11:06:53 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/04 11:05:11 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\HijackThis
[2009/02/03 00:18:42 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/02/03 00:11:59 | 00,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 32,820,251 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/03 00:11:44 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:44 | 00,086,834 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/03 00:11:44 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/02/03 00:11:43 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\AVGTOOLBAR
[2009/02/03 00:11:23 | 00,107,272 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 23:27:23 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Desktop\AVG 8.0 Free
[2009/01/20 15:20:21 | 00,000,494 | —- | C] () – C:\hpfr5550.xml
[2009/01/20 15:10:22 | 00,000,000 | —D | C] – C:\Documents and Settings\od\Application Data\Hewlett-Packard
[2009/01/20 15:08:49 | 00,000,396 | —- | C] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:03:20 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Hewlett-Packard
[2009/01/20 15:01:23 | 00,000,779 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | C] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/20 15:00:26 | 00,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2009/01/20 14:58:57 | 00,019,558 | —- | C] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 14:58:57 | 00,016,606 | —- | C] () – C:\WINDOWS\hpomdl01.dat
[2009/01/20 13:47:23 | 00,000,000 | —D | C] – C:\Program Files\Hp
[2009/01/14 11:08:46 | 16,375,382 | —- | C] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\od\Local Settings\Application Data\*.tmp files]
[2009/02/05 16:50:15 | 00,000,832 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/05 16:50:05 | 00,001,893 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\VZAccess Manager.lnk
[2009/02/05 16:48:50 | 00,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 16:48:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 16:48:28 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 16:48:27 | 10,634,40384 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 16:46:54 | 00,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/02/05 16:46:54 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/02/05 16:09:28 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/05 16:09:27 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/05 16:06:37 | 00,000,450 | —- | M] () – C:\WINDOWS\tasks\WebReg 20090205160636.job
[2009/02/05 16:00:40 | 00,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/02/05 16:00:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/02/05 15:18:46 | 00,000,494 | —- | M] () – C:\hpfr5550.xml
[2009/02/04 14:47:18 | 00,000,044 | —- | M] () – C:\WINDOWS\cdplayer.ini
[2009/02/04 11:46:34 | 00,001,734 | —- | M] () – C:\Documents and Settings\od\Desktop\HijackThis.lnk
[2009/02/04 11:13:05 | 00,000,767 | —- | M] () – C:\Documents and Settings\od\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 11:12:45 | 00,000,611 | —- | M] () – C:\Documents and Settings\od\Desktop\NTREGOPT.lnk
[2009/02/04 11:12:44 | 00,000,592 | —- | M] () – C:\Documents and Settings\od\Desktop\ERUNT.lnk
[2009/02/04 10:34:11 | 00,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/02/04 10:34:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/02/03 02:06:40 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/03 02:06:40 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/03 00:11:59 | 00,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/02/03 00:11:58 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/02/03 00:11:52 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/03 00:11:47 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/03 00:11:44 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/02/03 00:11:44 | 00,368,010 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/03 00:11:23 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/02 22:37:45 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/02/02 22:37:45 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/02/02 19:08:05 | 04,815,422 | -H– | M] () – C:\Documents and Settings\od\Local Settings\Application Data\IconCache.db
[2009/02/02 18:42:05 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/31 11:14:13 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/31 11:14:13 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/31 11:01:49 | 00,000,577 | —- | M] () – C:\Documents and Settings\od\My Documents\My Sharing Folders.lnk
[2009/01/21 11:50:01 | 00,190,464 | —- | M] () – C:\Documents and Settings\od\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/20 15:08:50 | 00,000,396 | —- | M] () – C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1232482084.job
[2009/01/20 15:08:21 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk
[2009/01/20 15:08:03 | 00,019,558 | —- | M] () – C:\WINDOWS\hpoins01.dat
[2009/01/20 15:01:23 | 00,000,779 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/01/20 15:01:22 | 00,000,851 | —- | M] () – C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/01/14 11:05:42 | 16,375,382 | —- | M] () – C:\Documents and Settings\od\Desktop\Red Cardinal.MPG
[2009/01/09 20:35:28 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/08 22:15:46 | 00,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/08 22:15:46 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm

========== Alternate Data Streams ==========

@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %SystemRoot%\System32\Thumbs.db:encryptable
< End of report >
ok do the other steps then do this Paste this into Run Fix in OTL2 :OTLI O20 - Winlogon\Notify\ljJYQiHY: DllName - ljJYQiHY.dll - File not found
Ran ATF Cleaner. Here's the MalwareBytes log. Headed to the Kapersky web site… Malwarebytes' Anti-Malware 1.33 Database version: 1732 Windows 5.1.2600 Service Pack 3 2/5/2009 5:42:38 PM mbam-log-2009-02-05 (17-42-38).txt Scan type: Quick Scan Objects scanned: 65037 Time elapsed: 6 minute(s), 53 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 14 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a3ed5288-f558-4f6e-8d5c-740cb6f89029} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f919fbd3-a96b-4679-af26-f551439bb5fd} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\goaivoeo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mbkgekus.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hpepxe.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\fiyhnc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI