hey...the IE tweak didn't change anything and with the Malware cleaning guide..i can't download anything after step one other then OTL..here's the log..
Extras.txtOTL Extras logfile created on: 2/7/2010 11:41:04 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 20.44 Gb Total Space | 2.12 Gb Free Space | 10.37% Space Free | Partition Type: NTFS
Drive D: | 147.24 Gb Total Space | 4.15 Gb Free Space | 2.82% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 146.48 Gb Total Space | 28.54 Gb Free Space | 19.49% Space Free | Partition Type: NTFS
Drive J: | 151.60 Gb Total Space | 146.26 Gb Free Space | 96.47% Space Free | Partition Type: NTFS
Computer Name: USER-6842731F9F
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] -- "C:\Program Files\ACD Systems\ACDSee\7.0\ACDSee7.exe" "%1" (ACD Systems Ltd.)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
"C:\Program Files\DC++\DCPlusPlus.exe" = C:\Program Files\DC++\DCPlusPlus.exe:*:Enabled:DC++ -- ()
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"D:\mIRC\sysreset\mirc.exe" = D:\mIRC\sysreset\mirc.exe:*:Enabled:mIRC -- File not found
"C:\Program Files\DC++\Downloads\mIRC V5 @ soul.UTPChat.net\mirc.exe" = C:\Program Files\DC++\Downloads\mIRC V5 @ soul.UTPChat.net\mirc.exe:*:Enabled:mIRC -- File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- (Microsoft Corporation)
"C:\Program Files\AVG\AVG8\avgam.exe" = C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe" = D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe:*:Enabled:TwonkyMedia -- File not found
"D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe" = D:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymediaserver.exe:*:Enabled:TwonkyMediaServer -- File not found
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0C973594-7DDF-4BD0-84ED-3517F7622037}" = PC Connectivity Solution
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{23170F69-40C1-2701-0442-000001000000}" = 7-Zip 4.42
"{3248F0A8-6813-11D6-A77B-00B0D0150010}" = J2SE Runtime Environment 5.0 Update 1
"{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"{39930321-4C58-4B8B-BCBF-342698C9801D}" = Max Payne
"{3D1B20A6-E31D-4BB5-BC5C-DDD3B0D91728}" = Intel Audio Studio 2.0
"{3D39E775-DDDA-4327-B747-0BDC5F191331}" = Nokia PC Suite
"{42B74521-4706-412A-9A27-AED12B83E886}" = Nokia Ovi Application Installer
"{52D02A2B-03D2-4E34-A358-DC5D951FD296}" = Nokia Connectivity Cable Driver
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5783F2D7-0201-0409-0002-0060B0CE6BBA}" = AutoCAD 2004
"{5783F2D7-0211-0409-0000-0060B0CE6BBA}" = AutoCAD Express Tools Volumes 1-9
"{6442DEDF-AC2F-4CBA-85DE-42E459C5006C}" = Nokia Ovi Content Copier
"{67F5E390-8E09-4AE4-B7F2-705AFD23D86D}" = WinAutomation
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
"{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}" = LIVE gaming on Windows Runtime Version 1.0.6027
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A81BFACE-B1CF-4AF0-B4D7-1A1256512116}" = Intel Audio Studio 2.0
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{B0625F16-B742-4F75-9FD8-20B47ACC7DE2}" = ACDSee 7.0 PowerPack
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{BED97FB6-E9E2-4DEC-009D-9950236206DA}" = Harry Potter - Quidditch World Cup
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C9AF27-9414-46C8-B9D8-D878BA041033}" = Nero 8
"{DC432844-6914-4421-910C-F1B05B3A761C}" = Nokia Music
"{DD3DAD13-289E-440E-A5D3-3EFB25305018}_is1" = John's Background Switcher 4.0
"{DE1FD294-CF2A-4936-92F4-B1B778371627}" = Intel® Desktop Utilities
"{F9EA1C47-64A6-45E4-9A80-8CC1575B971D}" = Nokia Ovi System Utilities
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Office Password Recovery" = Advanced Office Password Recovery (remove only)
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Autodesk Express Viewer" = Autodesk Express Viewer
"AVG8Uninstall" = AVG 8.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"BitComet" = BitComet 0.89
"CdaC13Ba" = SafeCast Shared Components
"CDisplay_is1" = CDisplay 1.8
"Crayon Physics Deluxe_is1" = Crayon Physics Deluxe - release 51
"DC++" = DC++ 0.687
"DFX for Winamp" = DFX for Winamp
"E8A6D621B6D3FC5D43C68C549D959DE76EEF5D84" = Windows Driver Package - Nokia Modem (06/01/2009 4.1)
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"F779F5541ABD99C95C03B0FD5E3C058B22DA0FF7" = Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
"Game Booster_is1" = Game Booster
"GameSpy Arcade" = GameSpy Arcade
"Garena" = Garena
"Halo" = Microsoft Halo
"Hamachi" = Hamachi 1.0.3.0
"InstallShield_{385979FE-DC4F-4140-8EAD-A59625000D72}" = NTI Backup NOW! 4
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.4.5 (Full)
"Lexmark 4200 Series" = Lexmark 4200 Series
"Malfreemaps MY/SG/BN Map_is1" = MFM v1.72
"MEGAMAN X4DeinstKey" = MEGAMAN X4
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"Need For Speed III" = Need For Speed III
"Nero8Lite_is1" = Nero 8 Micro 8.2.8.0
"Nokia Ovi Application Installer" = Nokia Ovi Application Installer 6.85.3011
"Nokia Ovi Content Copier" = Nokia Ovi Content Copier 6.85.3011
"Nokia Ovi System Utilities" = Nokia Ovi System Utilities 6.85.3018
"Nokia PC Suite" = Nokia PC Suite
"PROSet" = Intel® PRO Network Connections Drivers
"Proxy+" = Proxy+
"PSpice Student" = PSpice Student 9.1
"RealAlt_is1" = Real Alternative 1.52
"Registry Mechanic_is1" = Registry Mechanic 6.0
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Simba's Pride GameBreak" = Disney's Simba's Pride GameBreak
"The Incredible Hulk" = The Incredible Hulk
"Transformers Screensaver" = Transformers Screensaver
"VLC media player" = VLC media player 1.0.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"WinAutomation" = WinAutomation
"WinRAR archiver" = WinRAR archiver
"WITNESS 2003 Release 2 Educational" = WITNESS 2003 Release 2 Educational
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7
"X-Men Legends 2_is1" = X-Men Legends 2
"Yahoo! Anti-Spy" = Yahoo! Anti-Spy
"Yahoo! Messenger" = Yahoo! Messenger
"Zuma_Deluxe!_1.0" = Zuma Deluxe! 1.0
========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{DFFE2B1F-07E0-45A9-8801-CD8514CAA876}" = Prince of Persia T2T
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 12/20/2009 7:51:42 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/20/2009 7:53:42 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/20/2009 9:32:42 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/20/2009 9:42:42 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/21/2009 2:19:56 PM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/21/2009 2:19:56 PM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/22/2009 12:05:48 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/22/2009 12:05:49 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/22/2009 1:36:48 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
Error - 12/22/2009 1:50:49 AM | Computer Name = USER-6842731F9F | Source = Userenv | ID = 1090
Description = Windows couldn't log the RSoP (Resultant Set of Policies) session
status. An attempt to connect to WMI failed. No more RSoP logging will be done for
this application of policy.
[ System Events ]
Error - 2/6/2010 11:29:00 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The AVG8 Firewall service terminated unexpectedly. It has done this
1 time(s).
Error - 2/6/2010 11:29:00 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The C-DillaCdaC11BA service terminated unexpectedly. It has done
this 1 time(s).
Error - 2/6/2010 11:29:00 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The Nero BackItUp Scheduler 3 service terminated unexpectedly. It
has done this 1 time(s).
Error - 2/6/2010 11:29:00 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The PLFlash DeviceIoControl Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 2/6/2010 11:29:00 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The SmartLinkService service terminated unexpectedly. It has done
this 1 time(s).
Error - 2/6/2010 11:29:01 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The NMIndexingService service terminated unexpectedly. It has done
this 1 time(s).
Error - 2/6/2010 11:29:01 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7034
Description = The WinAutomation Service service terminated unexpectedly. It has
done this 1 time(s).
Error - 2/6/2010 11:36:01 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7023
Description = The Logon Network service terminated with the following error: %%1114
Error - 2/6/2010 11:36:01 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Intel® Desktop Utilities
Service service to connect.
Error - 2/6/2010 11:36:01 PM | Computer Name = USER-6842731F9F | Source = Service Control Manager | ID = 7023
Description = The SSHNAS service terminated with the following error: %%2
< End of report >
OTL.txtOTL logfile created on: 2/7/2010 11:41:04 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\user\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 75.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 20.44 Gb Total Space | 2.12 Gb Free Space | 10.37% Space Free | Partition Type: NTFS
Drive D: | 147.24 Gb Total Space | 4.15 Gb Free Space | 2.82% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 146.48 Gb Total Space | 28.54 Gb Free Space | 19.49% Space Free | Partition Type: NTFS
Drive J: | 151.60 Gb Total Space | 146.26 Gb Free Space | 96.47% Space Free | Partition Type: NTFS
Computer Name: USER-6842731F9F
Current User Name: user
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/02/07 11:39:37 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\My Documents\Downloads\OTL.exe
PRC - [2010/01/25 22:09:36 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
PRC - [2009/11/19 11:17:47 | 000,054,784 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE
PRC - [2009/09/24 07:25:28 | 000,119,104 | ---- | M] (johnsadventures.com) -- C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe
PRC - [2009/09/15 17:51:15 | 000,147,096 | ---- | M] (Softomotive) -- C:\Program Files\WinAutomation\WinAutomation.ServiceAgent.exe
PRC - [2009/09/15 17:50:59 | 000,171,672 | ---- | M] (Softomotive) -- C:\Program Files\WinAutomation\WinAutomation.DIAgent.exe
PRC - [2009/08/11 21:22:19 | 003,114,416 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2009/03/18 03:25:47 | 000,408,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/03/18 03:25:46 | 000,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/03/18 03:25:36 | 001,235,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/03/18 03:25:34 | 001,212,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgfws8.exe
PRC - [2009/03/18 03:25:34 | 000,638,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgam.exe
PRC - [2009/03/18 03:25:34 | 000,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2008/06/24 16:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
PRC - [2008/06/24 16:05:56 | 000,537,896 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
PRC - [2008/06/08 09:31:04 | 000,877,864 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
PRC - [2008/02/18 21:01:01 | 000,251,312 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2007/07/22 19:31:34 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/02 05:22:02 | 003,739,648 | ---- | M] (Google) -- C:\Program Files\Google\Google Talk\googletalk.exe
PRC - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\WINDOWS\system32\IoctlSvc.exe
PRC - [2005/08/05 21:05:00 | 000,344,064 | ---- | M] (ATI Technologies, Inc.) -- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
PRC - [2005/08/04 11:02:58 | 000,380,928 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
PRC - [2004/08/04 08:56:58 | 000,073,796 | ---- | M] (Smart Link) -- C:\WINDOWS\system32\slserv.exe
PRC - [2004/01/13 18:00:02 | 000,311,296 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXBCES.EXE
PRC - [2004/01/13 17:55:52 | 000,174,592 | ---- | M] (Lexmark International, Inc.) -- C:\WINDOWS\system32\LEXPPS.EXE
========== Modules (SafeList) ========== MOD - [2010/02/07 11:39:37 | 000,549,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\My Documents\Downloads\OTL.exe
MOD - [2009/03/26 23:35:39 | 000,034,224 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\idmmkb.dll
MOD - [2009/03/18 03:26:18 | 000,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\avgrsstx.dll
MOD - [2007/07/22 19:17:19 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - [2009/11/19 11:17:47 | 000,054,784 | ---- | M] (Macrovision) [Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2009/09/15 17:51:15 | 000,147,096 | ---- | M] (Softomotive) [Auto | Running] -- C:\Program Files\WinAutomation\WinAutomation.ServiceAgent.exe -- (WinAutomation Service)
SRV - [2009/06/02 10:10:08 | 000,637,952 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2009/03/18 03:25:34 | 001,212,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgfws8.exe -- (avgfws8)
SRV - [2009/03/18 03:25:34 | 000,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2009/03/10 01:51:17 | 000,069,632 | ---- | M] (Adobe Systems) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008/06/24 16:05:56 | 000,537,896 | ---- | M] (Nero AG) [On_Demand | Running] -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2008/06/08 09:31:04 | 000,877,864 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe -- (Nero BackItUp Scheduler 3)
SRV - [2007/01/19 12:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
SRV - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\WINDOWS\system32\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
SRV - [2006/10/26 19:49:34 | 000,441,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2006/10/26 14:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/08/05 21:05:00 | 000,516,096 | ---- | M] () [Auto | Stopped] -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart)
SRV - [2005/08/04 11:02:58 | 000,380,928 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller)
SRV - [2005/04/29 20:07:00 | 001,302,016 | ---- | M] (OSA Technologies, Inc.) [Auto | Stopped] -- C:\Program Files\Intel\IDU\IDUServ.exe -- (iHCService) Intel®
SRV - [2004/08/04 08:56:58 | 000,073,796 | ---- | M] (Smart Link) [Auto | Running] -- C:\WINDOWS\System32\slserv.exe -- (SLService)
SRV - [2004/01/13 18:00:02 | 000,311,296 | ---- | M] (Lexmark International, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LEXBCES.EXE -- (LexBceS)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapp...//www.yahoo.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo....e...-8&fr=b1ie7IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:9666
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.searchsla...ef=home&id=146"FF - prefs.js..extensions.enabledItems:
[email protected]:1.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.7
FF - prefs.js..extensions.enabledItems:
[email protected]:2.16.1
FF - prefs.js..extensions.enabledItems:
[email protected]:6.5
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.3.20091122_AMO
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 9666
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 9666
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/03/18 03:25:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/09/05 19:45:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox 3 Beta 2\components [2010/01/26 02:27:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox 3 Beta 2\plugins [2010/01/25 22:23:40 | 000,000,000 | ---D | M]
[2009/03/31 06:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Extensions
[2010/02/06 22:45:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions
[2009/12/03 12:58:22 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/11/27 13:57:40 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2009/11/17 01:12:00 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/08 18:13:07 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/11/06 13:02:17 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/12/03 12:58:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\
[email protected][2009/11/06 02:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\
[email protected][2009/12/03 12:58:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\SkipScreen@SkipScreen
[2009/09/14 21:46:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\
[email protected][2009/11/06 02:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\4rrbu5b7.default\extensions\
[email protected] O1 HOSTS File: ([2009/01/23 11:38:49 | 000,000,832 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 support.alcohol-soft.com
O1 - Hosts: 127.0.0.1 serial.alcohol-soft.com
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: AmsServer
O1 - Hosts:
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.5.19.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [IntelAudioStudio] C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe (Intel Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [WinAutomation Agent] C:\Program Files\WinAutomation\WinAutomation.DIAgent.exe (Softomotive)
O4 - HKCU..\Run: [BackgroundSwitcher] C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe (johnsadventures.com)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\user\Start Menu\Programs\Startup\rncsys32.exe (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\NPJPI150_01.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_01)
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_01)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\winqto32: DllName - winqto32.dll - C:\WINDOWS\System32\winqto32.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\user\Application Data\johnsadventures.com\Background Switcher\ActiveBackground.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user\Application Data\johnsadventures.com\Background Switcher\ActiveBackground.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/01/01 00:48:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/10/03 17:13:43 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2004/01/01 05:29:01 | 000,000,874 | ---- | M] () - C:\AutoSetup.log -- [ NTFS ]
O32 - AutoRun File - [2009/10/03 17:13:43 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/02/02 15:36:23 | 000,000,099 | ---- | M] () - I:\autorun.inf.vir -- [ NTFS ]
O32 - AutoRun File - [2010/02/02 15:36:41 | 000,000,099 | ---- | M] () - J:\autorun.inf.vir -- [ NTFS ]
O33 - MountPoints2\{01698593-f1c2-11dd-8b4a-00167671f6b1}\Shell - "" = AutoRun
O33 - MountPoints2\{01698593-f1c2-11dd-8b4a-00167671f6b1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{19f3d254-e2cf-11dd-8b3b-00167671f6b1}\Shell - "" = AutoRun
O33 - MountPoints2\{19f3d254-e2cf-11dd-8b3b-00167671f6b1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{19f3d255-e2cf-11dd-8b3b-00167671f6b1}\Shell - "" = AutoRun
O33 - MountPoints2\{19f3d255-e2cf-11dd-8b3b-00167671f6b1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{214b9bc0-4f61-11de-8b83-00167671f6b1}\Shell\AutoRun\command - "" = F:\tmp\winfix.exe -- File not found
O33 - MountPoints2\{214b9bc0-4f61-11de-8b83-00167671f6b1}\Shell\OpEn\cOMmAnD - "" = F:\tmp\winfix.exe -- File not found
O33 - MountPoints2\{a564abfa-1513-11de-8b62-00167671f6b1}\Shell - "" = AutoRun
O33 - MountPoints2\{a564abfa-1513-11de-8b62-00167671f6b1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c4c1904c-3475-11de-8b6e-00167671f6b1}\Shell - "" = AutoRun
O33 - MountPoints2\{c4c1904c-3475-11de-8b6e-00167671f6b1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d8234ac8-c756-11de-8c54-00167671f6b1}\Shell\AutoRun\command - "" = tmp\winfix.exe
O33 - MountPoints2\{d8234ac8-c756-11de-8c54-00167671f6b1}\Shell\OpEn\cOMmAnD - "" = tmp\winfix.exe
O33 - MountPoints2\{dc262567-0e23-11df-8cf9-00167671f6b1}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe -- File not found
O33 - MountPoints2\{dc262567-0e23-11df-8cf9-00167671f6b1}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe -- File not found
O33 - MountPoints2\{e42c2609-8a8e-11de-8c1f-00167671f6b1}\Shell\AutoRun\command - "" = J:\tmp\winfix.exe -- File not found
O33 - MountPoints2\{e42c2609-8a8e-11de-8c1f-00167671f6b1}\Shell\OpEn\cOMmAnD - "" = J:\tmp\winfix.exe -- File not found
O33 - MountPoints2\{f53127ef-4ea3-11de-8b80-00167671f6b1}\Shell\AutoRun\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe -- File not found
O33 - MountPoints2\{f53127ef-4ea3-11de-8b80-00167671f6b1}\Shell\open\command - "" = J:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\isi32.exe -- File not found
O33 - MountPoints2\{f63ed81b-8501-11de-8c1b-00167671f6b1}\Shell\AutoRun\command - "" = I:\tmp\winfix.exe -- File not found
O33 - MountPoints2\{f63ed81b-8501-11de-8c1b-00167671f6b1}\Shell\OpEn\cOMmAnD - "" = I:\tmp\winfix.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/01/01 00:48:17 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: fgzctq - C:\WINDOWS\system32\giuks.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17173366603513856)
========== Files/Folders - Created Within 14 Days ========== [2010/02/03 00:26:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/02/03 00:26:09 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/02/02 23:54:43 | 000,000,000 | ---D | C] -- C:\SDFix
[2010/02/02 23:26:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/02/02 23:25:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\Simply Super Software
[2010/02/02 23:24:33 | 000,000,000 | ---D | C] -- C:\Program Files\Trojan Remover
[2010/02/02 23:24:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Simply Super Software
[2010/02/02 23:24:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/02/01 14:02:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\Emulators
[2010/01/26 23:23:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\Surat PM
[2010/01/26 22:41:14 | 000,026,112 | ---- | C] (NirSoft) -- C:\WINDOWS\System32\nircmd.exe
[2010/01/25 22:29:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\Desktop
[2010/01/25 22:09:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Temp
[2009/05/06 12:15:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Nokia
[2009/05/06 12:02:26 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/03/18 03:24:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/03/18 03:24:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/03/18 03:24:07 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/01/23 11:50:13 | 000,159,616 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\Vax347b.sys
[2009/01/23 11:50:13 | 000,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\Vax347s.sys
[1 C:\Documents and Settings\user\*.tmp files -> C:\Documents and Settings\user\*.tmp -> ]
========== Files - Modified Within 14 Days ========== [2010/02/07 11:34:30 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/02/07 11:34:23 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/02/07 11:34:20 | 2145,443,840 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/07 11:31:44 | 015,466,496 | ---- | M] () -- C:\Documents and Settings\user\NTUSER.DAT
[2010/02/07 11:31:44 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\user\ntuser.ini
[2010/02/07 11:14:02 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1614895754-839522115-1003UA.job
[2010/02/06 22:14:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1614895754-839522115-1003Core.job
[2010/02/06 21:19:31 | 000,000,460 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2010/02/04 23:26:56 | 000,011,811 | ---- | M] () -- C:\SK SERI MAWAR.docx
[2010/02/04 12:01:19 | 000,046,080 | ---- | M] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/04 02:12:43 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/02/03 21:41:49 | 000,000,763 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Lexmark 4200 Series All-In-One Center.lnk
[2010/02/03 21:41:33 | 000,014,283 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Name List Science.docx
[2010/02/03 00:26:26 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/01 23:31:09 | 000,014,484 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Kamalini's surat to perdana menteri.docx
[2010/02/01 23:15:35 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\user\Desktop\MINIT CURAI.doc
[2010/02/01 21:29:43 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Ceramah Alam Sekitar.doc
[2010/01/31 22:39:24 | 000,015,913 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Name List Mathematics.docx
[2010/01/30 22:25:47 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/01/28 02:19:22 | 000,036,864 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Sundraj.doc
[2010/01/27 23:00:38 | 000,020,263 | ---- | M] () -- C:\Documents and Settings\user\My Documents\Bagai aur dengan tebing.docx
[2010/01/26 21:18:40 | 000,012,748 | ---- | M] () -- C:\Documents and Settings\user\My Documents\nama murid....docx
[2010/01/25 00:29:30 | 000,012,682 | ---- | M] () -- C:\Documents and Settings\user\My Documents\surat.docx
[2010/01/25 00:29:25 | 000,012,034 | ---- | M] () -- C:\Documents and Settings\user\My Documents\surat.docxh.docx
[1 C:\Documents and Settings\user\*.tmp files -> C:\Documents and Settings\user\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/02/05 13:13:07 | 000,728,161 | ---- | C] () -- C:\Documents and Settings\user\Desktop\05082009158.jpg
[2010/02/05 13:13:07 | 000,683,478 | ---- | C] () -- C:\Documents and Settings\user\Desktop\05082009157.jpg
[2010/02/05 13:13:06 | 000,532,187 | ---- | C] () -- C:\Documents and Settings\user\Desktop\05082009159.jpg
[2010/02/04 23:26:55 | 000,011,811 | ---- | C] () -- C:\SK SERI MAWAR.docx
[2010/02/03 21:41:49 | 000,000,763 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Lexmark 4200 Series All-In-One Center.lnk
[2010/02/03 00:26:26 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\user\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/02/02 23:24:37 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2010/02/02 23:24:37 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2010/02/02 23:24:37 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2010/02/01 23:15:34 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\user\Desktop\MINIT CURAI.doc
[2010/02/01 21:29:42 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Ceramah Alam Sekitar.doc
[2010/01/31 22:17:57 | 000,015,913 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Name List Mathematics.docx
[2010/01/31 22:13:47 | 000,014,283 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Name List Science.docx
[2010/01/31 15:54:08 | 000,014,484 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Kamalini's surat to perdana menteri.docx
[2010/01/28 02:19:21 | 000,036,864 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Sundraj.doc
[2010/01/27 23:00:37 | 000,020,263 | ---- | C] () -- C:\Documents and Settings\user\My Documents\Bagai aur dengan tebing.docx
[2010/01/26 21:18:39 | 000,012,748 | ---- | C] () -- C:\Documents and Settings\user\My Documents\nama murid....docx
[2010/01/25 22:09:53 | 000,000,974 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1614895754-839522115-1003UA.job
[2010/01/25 22:09:51 | 000,000,922 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-299502267-1614895754-839522115-1003Core.job
[2010/01/25 00:29:23 | 000,012,034 | ---- | C] () -- C:\Documents and Settings\user\My Documents\surat.docxh.docx
[2010/01/24 20:15:44 | 000,012,682 | ---- | C] () -- C:\Documents and Settings\user\My Documents\surat.docx
[2010/01/08 20:03:47 | 000,000,025 | ---- | C] () -- C:\WINDOWS\GECKOS.INI
[2009/12/02 18:06:52 | 000,000,090 | ---- | C] () -- C:\WINDOWS\WA.INI
[2009/12/01 23:04:09 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\winqto32.dll
[2009/12/01 23:03:30 | 000,037,888 | ---- | C] () -- C:\WINDOWS\System32\winfuq32.dll
[2009/11/27 18:13:59 | 000,000,131 | ---- | C] () -- C:\WINDOWS\chess.ini
[2009/11/27 18:10:28 | 000,000,221 | ---- | C] () -- C:\WINDOWS\emsoft.ini
[2009/11/27 18:10:07 | 000,000,028 | ---- | C] () -- C:\WINDOWS\boxworld.ini
[2009/09/05 18:29:37 | 000,961,696 | ---- | C] () -- C:\Documents and Settings\user\Application Data\8d51356f4bb435f1b6f84a242a76b34c-i686.cache-2
[2009/08/13 17:34:59 | 000,001,753 | ---- | C] () -- C:\WINDOWS\aopr.ini
[2009/06/20 13:18:36 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\user\Application Data\wiaserva.log
[2009/06/17 22:09:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\WORDSE~1.INI
[2009/06/17 00:47:15 | 000,000,460 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2009/06/17 00:46:45 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbmvs.dll
[2009/06/17 00:46:23 | 000,000,187 | ---- | C] () -- C:\WINDOWS\System32\lxbmcoin.ini
[2009/06/17 00:46:18 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\LXBMLCNP.DLL
[2009/06/15 21:40:08 | 000,000,304 | ---- | C] () -- C:\WINDOWS\TetrisPk.ini
[2009/06/08 15:22:14 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2009/06/08 15:22:14 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2009/06/04 22:39:29 | 000,000,022 | ---- | C] () -- C:\WINDOWS\WINTOYS.INI
[2009/05/06 11:37:43 | 000,369,776 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/04/30 15:07:28 | 000,006,009 | ---- | C] () -- C:\WINDOWS\PSPICEEV.INI
[2009/04/30 15:07:23 | 000,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil60n.dll
[2009/04/30 15:07:23 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll
[2009/04/30 15:07:22 | 000,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll
[2009/04/30 15:07:22 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll
[2009/04/30 15:07:22 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll
[2009/04/30 15:07:22 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll
[2009/04/30 15:07:22 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll
[2009/04/30 15:07:22 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll
[2009/04/30 15:07:22 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll
[2009/04/30 15:07:21 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll
[2009/04/30 15:07:21 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll
[2009/04/30 15:07:21 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll
[2009/04/30 15:07:21 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll
[2009/04/30 15:07:21 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll
[2009/04/30 15:07:21 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll
[2009/04/30 15:07:21 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\implode.dll
[2009/03/18 03:20:06 | 000,084,418 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
[2009/03/17 13:54:17 | 000,103,424 | RHS- | C] () -- C:\WINDOWS\System32\giuks.dll
[2009/03/13 12:04:36 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/03/13 12:04:33 | 002,330,643 | ---- | C] () -- C:\WINDOWS\System32\x264vfw.dll
[2009/03/13 12:04:33 | 000,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/03/13 12:04:33 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/03/13 12:04:32 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/03/13 12:04:31 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/03/13 12:04:31 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/02/11 23:36:25 | 000,001,026 | ---- | C] () -- C:\Documents and Settings\user\Application Data\alarms.ini
[2009/02/11 23:36:23 | 000,000,615 | ---- | C] () -- C:\Documents and Settings\user\Application Data\AtomicAlarmClock.ini
[2009/01/29 23:48:31 | 000,000,170 | ---- | C] () -- C:\WINDOWS\game.ini
[2009/01/23 11:53:22 | 000,646,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/04/17 15:34:40 | 000,135,716 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2004/12/17 17:14:44 | 000,013,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\UBHelper.sys
[2004/01/03 23:39:37 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2004/01/03 23:39:27 | 000,046,080 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/01/03 08:23:32 | 000,000,520 | ---- | C] () -- C:\WINDOWS\NSSHAFT.INI
[2004/01/01 05:45:38 | 000,001,024 | RH-- | C] () -- C:\WINDOWS\System32\NTIBUN4.dll
[2004/01/01 05:23:37 | 000,000,056 | ---- | C] () -- C:\Program Files\Common Files\appop.log
[2004/01/01 01:20:13 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2002/03/21 15:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL
========== LOP Check ========== [2009/01/05 23:03:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2009/11/19 11:13:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/06/24 12:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DFX
[2009/09/05 19:42:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/05/06 11:46:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaMusic
[2009/05/06 12:03:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/10/01 12:12:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\POPWWPROFILES
[2009/12/14 23:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2010/02/02 23:24:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2009/12/27 12:53:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Softomotive
[2010/02/03 11:51:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/27 12:53:25 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{9820EE16-436D-48D4-9946-D7517C5C1D73}
[2009/01/06 03:07:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\ACD Systems
[2009/01/29 23:49:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Activision
[2009/11/19 11:26:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Autodesk
[2009/09/08 20:49:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Crayon Physics Deluxe
[2010/02/07 11:34:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\DMCache
[2010/01/27 19:56:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\IDM
[2004/01/01 05:32:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Intervideo
[2009/11/27 14:02:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\johnsadventures.com
[2009/01/14 22:42:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Kingston
[2009/09/16 02:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Moyea
[2009/09/13 17:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Nokia
[2009/05/06 12:01:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Nseries
[2009/05/06 12:05:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\PC Suite
[2009/10/02 16:10:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\SEGA
[2010/02/02 23:24:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Simply Super Software
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: ATAPI.SYS >[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 05:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >[2004/08/04 07:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/04 07:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >[2004/08/04 07:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/04 07:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >[2004/08/04 07:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/04 07:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2007/07/22 19:13:56 | 000,346,624 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtmsft.dll
[2007/07/22 19:13:56 | 000,214,528 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\dxtrans.dll
[2009/03/17 13:54:17 | 000,103,424 | RHS- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\giuks.dll
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles >[2009/01/23 11:53:22 | 000,646,392 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >[2004/01/01 08:24:59 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/01/01 08:24:59 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/01/01 08:24:59 | 000,892,928 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ========== @Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
thanks in advance...oh and btw..i can currently view my hidden files after i managed to use Trojan Remover..