This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Suspicious Registry Keys error messages on startup

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

New log after runfix ========== PROCESSES ========== Process explorer.exe killed successfully! ========== OTLISTIT ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\58ea0404 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nduvugav deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nfutuxekuv deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\powukokela deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\\xxyYoNfd not found. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\satnam\Local Settings\Temp\~DFC9F5.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_104.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_160.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.7 log created on 02062009_125741 Files moved on Reboot… File C:\Documents and Settings\satnam\Local Settings\Temp\hsperfdata_satnam\596 not found! File C:\Documents and Settings\satnam\Local Settings\Temp\etilqs_Uuym0dImuVZKk3yehe14 not found! File C:\Documents and Settings\satnam\Local Settings\Temp\~DFC9F5.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_104.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_160.dat not found! Registry entries deleted on Reboot…
new ot log



OTListIt logfile created on: 06/02/2009 17:47:15 - Run 28
OTListIt2 by OldTimer - Version 2.0.0.7 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 446.18 Mb Available Physical Memory | 43.59% Memory free
2.40 Gb Paging File | 1.94 Gb Available in Paging File | 80.90% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.18 Gb Free Space | 76.76% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\satnam\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: () - File not found
O20 - AppInit_DLLs: (c:\windows\system32\) - c:\WINDOWS\system32 [2009/01/31 12:38:23 00,000,000 | —D | M]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/06 12:50:03 | 00,488,960 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2009/01/07 20:24:44 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:24:41 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/07 20:24:41 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:24:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/07 20:24:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 20:23:35 | 00,251,392 | —- | C] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe
[2009/01/07 20:02:50 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgrprxy.dll
[2009/01/07 20:02:50 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx2.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx4.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bitsprx3.dll
[2009/01/07 20:02:50 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bitsprx4.dll
[2009/01/07 20:02:49 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\qmgr.dll

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/06 17:45:06 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/06 17:43:55 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/06 17:43:47 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/06 17:43:20 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/06 17:43:12 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
[2009/02/06 17:43:12 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/06 17:43:07 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/06 13:39:02 | 04,314,388 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/06 13:03:39 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/06 12:50:29 | 00,488,960 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/06 12:22:43 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/06 09:31:52 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye
[2009/01/07 20:24:41 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 20:23:36 | 00,251,392 | —- | M] () – C:\Documents and Settings\satnam\Desktop\hijackthis_sfx.exe

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/06 17:48:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 17:43:12 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
[2009/02/06 17:43:12 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
hello

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.





Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    O4 - HKLM..\Run: [58ea0404] rundll32.exe "C:\WINDOWS\system32\ibcaojvd.dll",b File not found
    O4 - HKLM..\Run: [Nduvugav] rundll32.exe "C:\WINDOWS\urifemey.dll",e File not found
    O4 - HKLM..\Run: [Nfutuxekuv] rundll32.exe "C:\WINDOWS\Hqixapa.dll",e File not found
    O4 - HKLM..\Run: [powukokela] Rundll32.exe "C:\WINDOWS\system32\viyutoni.dll",s File not found
    O20 - AppInit_DLLs: () - File not found
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
The error messages did not appear this time, although I heard an error tone whilst typing this and no error message displayed. This has happened a few times since my pc got infected. ========== OTLISTIT ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\58ea0404 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nduvugav deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Nfutuxekuv deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\powukokela deleted successfully. Registry value \SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls deleted successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\satnam\Local Settings\Temp\~DF7CA.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7e0.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_b8.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.7 log created on 02062009_195321 Files moved on Reboot… C:\Documents and Settings\satnam\Local Settings\Temp\~DF7CA.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_7e0.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_b8.dat not found! Registry entries deleted on Reboot…
OTListIt logfile created on: 06/02/2009 20:47:24 - Run 31
OTListIt2 by OldTimer - Version 2.0.0.7 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 492.20 Mb Available Physical Memory | 48.09% Memory free
2.40 Gb Paging File | 1.96 Gb Available in Paging File | 81.77% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.11 Gb Free Space | 76.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Creative\Shared Files\CamTray.exe (Creative Technology Ltd)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\satnam\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/06 12:50:03 | 00,488,960 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/06 20:03:46 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/06 20:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
[2009/02/06 19:59:11 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/06 19:58:11 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/06 19:57:57 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/06 19:57:43 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/06 19:57:34 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/06 19:57:30 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/06 19:56:34 | 04,819,758 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/06 13:03:39 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/06 12:50:29 | 00,488,960 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/06 09:31:52 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/06 20:48:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 20:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\Tasks\qxefzrnl.job
[2009/02/06 19:57:34 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
    [2009/02/06 20:00:00 | 00,000,312 | —- | M] () – C:\WINDOWS\tasks\qxefzrnl.job
    [2009/01/07 21:44:37 | 00,006,456 | -H– | M] () – C:\WINDOWS\System32\fabovaye
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
========== OTLISTIT ========== Process explorer.exe killed successfully! Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\\xxyYoNfd not found. C:\WINDOWS\tasks\qxefzrnl.job moved successfully. C:\WINDOWS\System32\fabovaye moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\satnam\Local Settings\Temp\~DFA649.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_14c.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_168.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.7 log created on 02062009_210311 Files moved on Reboot… C:\Documents and Settings\satnam\Local Settings\Temp\~DFA649.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_14c.dat not found! File C:\WINDOWS\temp\Perflib_Perfdata_168.dat not found! Registry entries deleted on Reboot…
OTListIt logfile created on: 06/02/2009 21:10:10 - Run 34
OTListIt2 by OldTimer - Version 2.0.0.7 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 432.59 Mb Available Physical Memory | 42.27% Memory free
2.40 Gb Paging File | 1.95 Gb Available in Paging File | 80.96% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.11 Gb Free Space | 76.71% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Creative\Shared Files\CamTray.exe (Creative Technology Ltd)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\satnam\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/06 12:50:03 | 00,488,960 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/06 21:08:19 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/06 21:05:21 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/06 21:05:17 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/06 21:04:55 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/06 21:04:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/06 21:04:25 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/06 21:03:21 | 04,819,900 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/06 19:59:11 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/06 13:03:39 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/06 12:50:29 | 00,488,960 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/06 09:31:52 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 23:32:52 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/06 21:11:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 21:04:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
OTListIt logfile created on: 07/02/2009 11:19:13 - Run 35
OTListIt2 by OldTimer - Version 2.0.0.7 Folder = C:\Documents and Settings\satnam\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18372)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 473.64 Mb Available Physical Memory | 46.28% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.35% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 117.12 Gb Free Space | 76.72% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: P-22BBV8YGR7VMK
Current User Name: satnam
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Creative\Shared Files\CamTray.exe (Creative Technology Ltd)
PRC - C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WLService.exe (GEMTEKS)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
PRC - C:\Program Files\Wireless-G PCI Adapter with RangeBooster\WMP54GR.exe (Linksys)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\satnam\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ForceWare Intelligent Application Manager (IAM) [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe ()
SRV - (ForcewareWebInterface [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe (Apache Software Foundation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (hpqcxs08 [On_Demand | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc [Auto | Running]) – C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Auto | Running]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Stopped]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (nSvcIp [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe (NVIDIA)
SRV - (nSvcLog [Auto | Running]) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (usnjsvc [On_Demand | Running]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (WMP54GRSVC [Auto | Running]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (asuskbnt [System | Running]) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (k750bus [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\drivers\Lbd.sys (Lavasoft AB)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (MTsensor [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (nvata [Boot | Running]) – C:\WINDOWS\system32\drivers\nvata.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVTCP [System | Running]) – C:\WINDOWS\system32\drivers\NVTCP.SYS (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (RT61 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (StarOpen [System | Running]) – C:\WINDOWS\system32\drivers\StarOpen.sys ()
DRV - (V0080Dev [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\V0080Dev.sys (Creative Technology Ltd.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
IE - URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

O1 HOSTS File: (292138 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe ()
O4 - HKLM..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install (NVIDIA Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" File not found
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\WINDOWS\system32\nvappfilter.dll (NVIDIA)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 89 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\xxyYoNfd: DllName - xxyYoNfd.dll - File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[3 C:\WINDOWS\*.tmp files]
[2009/02/06 12:50:03 | 00,488,960 | —- | C] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/05 10:13:05 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/01 19:13:29 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/01/31 12:34:49 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2009/01/31 12:32:38 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\satnam\Local Settings\Application Data\TVU Networks
[2009/01/28 21:08:20 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/01/25 20:54:18 | 00,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/25 20:54:16 | 00,000,000 | —D | C] – C:\Program Files\MSN Messenger
[2009/01/23 17:22:26 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/01/23 17:22:26 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/01/22 22:51:09 | 20,853,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/01/22 22:34:45 | 00,000,000 | —D | C] – C:\1b2a9624b4e5549ce91d3dd8
[2009/01/20 23:01:32 | 00,015,688 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/20 18:31:49 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/20 18:31:36 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/20 18:29:59 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/01/20 18:29:58 | 00,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/15 02:22:00 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/11 11:52:00 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/01/11 11:51:50 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office Outlook Connector
[2009/01/11 11:50:58 | 03,426,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/11 11:50:49 | 00,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2009/01/11 11:48:40 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/01/11 11:48:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2009/01/11 11:48:18 | 00,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2009/01/11 11:36:34 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/07 11:16:58 | 32,862,719 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/07 11:16:58 | 00,088,982 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/07 11:15:56 | 00,000,581 | —- | M] () – C:\Documents and Settings\satnam\My Documents\My Sharing Folders.lnk
[2009/02/07 11:15:03 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/07 11:14:51 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/02/07 11:14:36 | 00,026,682 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/02/07 11:14:27 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/07 11:14:23 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/06 21:03:21 | 04,819,900 | -H– | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\IconCache.db
[2009/02/06 19:59:11 | 00,002,497 | —- | M] () – C:\Documents and Settings\satnam\Desktop\Microsoft Office Word 2003.lnk
[2009/02/06 13:03:39 | 00,002,137 | —- | M] () – C:\Documents and Settings\satnam\Desktop\iTunes.lnk
[2009/02/06 12:50:29 | 00,488,960 | —- | M] (OldTimer Tools) – C:\Documents and Settings\satnam\Desktop\OTListIt22.exe
[2009/02/04 16:41:29 | 00,292,138 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/31 13:50:27 | 00,015,688 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2009/01/31 12:37:47 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\satnam\My Documents\desktop.ini
[2009/01/31 12:35:37 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/29 20:16:18 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-164129.backup
[2009/01/29 20:16:09 | 00,291,996 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201618.backup
[2009/01/28 18:52:34 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/28 18:52:34 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/28 18:52:34 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/28 18:52:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/01/25 20:54:18 | 00,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Windows Live Messenger.lnk
[2009/01/23 17:22:26 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/01/21 18:45:57 | 00,291,722 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090129-201609.backup
[2009/01/20 18:29:58 | 00,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/01/18 21:30:13 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll.mui
[2009/01/15 02:22:22 | 01,228,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/15 02:22:00 | 00,049,152 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll.mui
[2009/01/15 02:21:44 | 00,002,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe.mui
[2009/01/15 02:19:22 | 00,010,240 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll.mui
[2009/01/15 02:19:22 | 00,004,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe.mui
[2009/01/15 02:19:02 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll.mui
[2009/01/15 02:17:22 | 00,636,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iexplore.exe
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2009/01/15 02:17:22 | 00,392,040 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.dll
[2009/01/15 02:13:18 | 05,888,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieframe.dll
[2009/01/15 02:12:12 | 10,963,968 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/15 02:07:16 | 00,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\urlmon.dll
[2009/01/15 02:06:48 | 01,182,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2009/01/15 02:06:44 | 01,467,392 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2009/01/15 02:06:22 | 00,208,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\WinFXDocObj.exe
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\webcheck.dll
[2009/01/15 02:06:08 | 00,236,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2009/01/15 02:06:00 | 00,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wininet.dll
[2009/01/15 02:05:42 | 00,911,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2009/01/15 02:05:34 | 00,193,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\occache.dll
[2009/01/15 02:05:34 | 00,109,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\licmgr10.dll
[2009/01/15 02:05:34 | 00,043,008 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\licmgr10.dll
[2009/01/15 02:04:56 | 00,755,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\VGX.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2009/01/15 02:04:28 | 00,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2009/01/15 02:04:16 | 00,025,600 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jscript.dll
[2009/01/15 02:03:58 | 00,724,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jscript.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2009/01/15 02:03:50 | 00,228,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2009/01/15 02:03:42 | 00,125,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\vbscript.dll
[2009/01/15 02:03:36 | 00,420,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vbscript.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admparse.dll
[2009/01/15 02:03:32 | 00,072,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\admparse.dll
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2009/01/15 02:03:28 | 00,172,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakui.dll
[2009/01/15 02:03:20 | 00,163,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakui.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iesetup.dll
[2009/01/15 02:03:18 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iesetup.dll
[2009/01/15 02:03:18 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inseng.dll
[2009/01/15 02:03:14 | 00,094,720 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inseng.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2009/01/15 02:03:14 | 00,055,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2009/01/15 02:03:12 | 00,128,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\advpack.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iertutil.dll
[2009/01/15 02:02:50 | 01,975,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2009/01/15 02:02:40 | 00,593,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2009/01/15 02:02:20 | 00,611,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2009/01/15 02:01:52 | 00,183,808 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2009/01/15 02:01:42 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedssync.exe
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\icardie.dll
[2009/01/15 02:01:40 | 00,059,904 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2009/01/15 02:01:40 | 00,054,272 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\imgutil.dll
[2009/01/15 02:01:26 | 00,034,304 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\imgutil.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2009/01/15 02:01:22 | 00,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2009/01/15 02:01:18 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2009/01/15 02:01:16 | 00,216,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmled.dll
[2009/01/15 02:01:06 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtmler.dll
[2009/01/15 02:00:46 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmler.dll
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshtml.tlb
[2009/01/15 02:00:40 | 01,639,936 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.tlb
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mshta.exe
[2009/01/15 02:00:38 | 00,045,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshta.exe
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\tdc.ocx
[2009/01/15 02:00:36 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tdc.ocx
[2009/01/15 01:53:40 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hmmapi.dll
[2009/01/15 01:50:50 | 00,164,352 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieui.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msls31.dll
[2009/01/15 01:50:38 | 00,156,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msls31.dll
[2009/01/15 01:39:06 | 00,057,667 | —- | M] () – C:\WINDOWS\System32\ieuinit.inf
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2009/01/15 01:35:10 | 00,445,440 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/14 17:00:24 | 00,291,222 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090121-184557.backup
[2009/01/14 16:11:32 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/14 16:11:28 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 19:48:59 | 00,205,712 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/12 17:47:54 | 00,045,624 | —- | M] () – C:\Documents and Settings\satnam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/11 12:08:07 | 00,456,008 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/11 12:08:07 | 00,391,606 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/01/11 12:08:07 | 00,057,896 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/01/11 05:00:34 | 00,079,360 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iecompat.dll
[2009/01/09 17:35:30 | 20,853,704 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe

========== LOP Check ==========

[2009/01/28 21:08:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/20 18:29:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2007/05/15 21:09:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/05/12 18:39:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/28 18:47:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/12/20 17:43:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2007/07/16 16:46:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/11/15 21:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
[2007/11/15 21:26:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2007/11/15 21:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
[2009/02/07 11:20:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/07/17 17:15:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/01/07 20:24:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/22 22:59:38 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/07 14:02:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2009/01/05 21:44:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/28 21:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TVU Networks
[2007/11/15 21:30:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WEBREG
[2007/06/23 16:11:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/02/26 19:34:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/02/05 18:46:34 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data
[2008/12/21 19:48:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Adobe
[2007/05/15 21:09:14 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeAUM
[2007/05/19 21:19:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AdobeUM
[2007/07/02 13:09:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Apple Computer
[2009/02/05 18:46:54 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\AVGTOOLBAR
[2008/04/01 19:00:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\BitTorrent
[2007/10/27 10:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Creative
[2008/08/02 19:08:56 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DivX
[2008/07/15 21:03:33 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\DNA
[2008/02/10 20:53:46 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Google
[2007/06/23 21:07:03 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Help
[2007/11/15 21:38:22 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\HP
[2007/05/07 13:35:08 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Identities
[2007/05/12 17:11:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Lavasoft
[2007/05/13 15:40:27 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Leadertech
[2007/05/07 15:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Macromedia
[2009/01/07 20:24:44 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Malwarebytes
[2009/01/07 20:05:29 | 00,000,000 | –SD | M] – C:\Documents and Settings\satnam\Application Data\Microsoft
[2009/01/06 21:19:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Mozilla
[2007/05/07 14:53:19 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\MSN6
[2007/06/23 16:22:13 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\NetMedia Providers
[2007/06/23 16:22:12 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Publish Providers
[2007/05/09 16:58:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Real
[2009/01/06 21:47:28 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Samsung
[2007/10/19 16:53:04 | 00,000,000 | RH-D | M] – C:\Documents and Settings\satnam\Application Data\SecuROM
[2007/06/23 16:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sonic Foundry
[2007/10/19 16:53:15 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sports Interactive
[2007/05/29 20:52:16 | 00,000,000 | —D | M] – C:\Documents and Settings\satnam\Application Data\Sun
[2009/01/27 18:31:06 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2002/08/29 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/07 11:14:27 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
Ok sorry about that

Delete OTList2.exe and do this

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI