Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Cripplingly slow performance


  • Please log in to reply

#1
Lockbolt

Lockbolt

    Member

  • Member
  • PipPip
  • 10 posts
A while back, my computer was experiencing a problem where I could continue to move the cursor, but NONE of my windows were responding. These hangs happened in bursts, until eventually the system would not boot any longer and give a boot disk error. The hard drive was reinstalled from the OS up (at least i'm guessing that's what happened, since it needed the boot disk and all the files on the computer were gone when it was done, aside the OS. Things ran relatively smoothly afterwards, but now i'm having a problem where my windows won't freeze, but sometimes, when I give them a command, even a small one like typing a message in skype, It'll cause the entire application to hang for up to 2 minutes (And other times, the applications run just fine.). I'm not sure if it could be malware, but I figure this is the place to go to find out, and get it solved if it happens to be the problem.

>>Registry backed up with Erunt<<



{{{{{Malwarebytes log}}}}}


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4863

Windows 6.0.6000
Internet Explorer 7.0.6000.16982

10/18/2010 8:29:03 PM
mbam-log-2010-10-18 (20-29-03).txt

Scan type: Quick scan
Objects scanned: 138112
Time elapsed: 12 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


{{AVG was run and reported no viruses.}}



{{{{Gmer Log}}}}}

GMER 1.0.15.15472 - http://www.gmer.net
Rootkit quick scan 2010-10-18 23:18:43
Windows 6.0.6000
Running: gmer.exe; Driver: C:\Users\Jeremy\AppData\Local\Temp\awliqpow.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver
AttachedDevice \Driver\tdx \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ,

---- EOF - GMER 1.0.15 ----




{{{{{OTL Log}}}}}}

OTL logfile created on: 10/18/2010 9:21:51 PM - Run 1
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Users\Jeremy\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.47 Gb Total Space | 200.39 Gb Free Space | 69.47% Space Free | Partition Type: NTFS
Drive D: | 9.62 Gb Total Space | 1.30 Gb Free Space | 13.51% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 230.45 Gb Free Space | 77.31% Space Free | Partition Type: NTFS

Computer Name: JEREMY-PC | User Name: Jeremy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/18 20:14:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Jeremy\Desktop\OTL.exe
PRC - [2010/10/06 04:39:27 | 002,002,728 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010/09/11 03:25:37 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/09/10 18:22:31 | 000,039,408 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2010/09/10 14:56:04 | 001,245,064 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PRC - [2010/09/10 01:45:22 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/09/10 01:45:18 | 003,210,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgfws.exe
PRC - [2010/09/10 01:44:22 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/09/09 04:46:42 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/09/07 03:50:58 | 001,065,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2010/09/07 03:50:22 | 001,047,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2010/09/07 03:50:14 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/09/07 03:50:08 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
PRC - [2009/01/14 17:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2008/05/24 15:02:50 | 000,417,792 | ---- | M] () -- C:\Program Files\Icecast2 Win32\icecastService.exe
PRC - [2007/10/25 06:52:08 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/08/24 08:07:00 | 000,149,864 | ---- | M] (Symantec Corporation) -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/05/07 10:35:56 | 001,273,856 | ---- | M] () -- C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe
PRC - [2007/04/18 08:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
PRC - [2007/02/15 04:59:00 | 000,118,784 | ---- | M] (OsdMaestro) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2006/11/02 02:45:39 | 000,150,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe


========== Modules (SafeList) ==========

MOD - [2010/10/18 20:14:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Jeremy\Desktop\OTL.exe
MOD - [2006/11/02 02:44:49 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2006/11/02 02:38:57 | 001,648,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/10/13 01:02:51 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/10/06 04:39:27 | 002,002,728 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe -- (TeamViewer5)
SRV - [2010/09/24 13:19:16 | 000,444,656 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV - [2010/09/24 13:19:16 | 000,268,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV - [2010/09/24 13:19:08 | 006,351,600 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV - [2010/09/10 14:56:04 | 001,245,064 | ---- | M] () [On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC)
SRV - [2010/09/10 14:46:32 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/09/10 01:45:22 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/10 01:45:18 | 003,210,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgfws.exe -- (avgfws)
SRV - [2010/09/03 10:35:50 | 006,104,144 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/07/09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/03/18 16:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpActivator)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetPipeActivator)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetMsmqActivator)
SRV - [2010/01/15 05:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/01/14 17:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2008/05/24 15:02:50 | 000,417,792 | ---- | M] () [Auto | Running] -- C:\Program Files\Icecast2 Win32\icecastService.exe -- (Icecast-trunk)
SRV - [2007/08/24 08:07:00 | 000,149,864 | ---- | M] (Symantec Corporation) [Auto | Running] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (LiveUpdate Notice)
SRV - [2007/08/24 08:07:00 | 000,149,864 | ---- | M] (Symantec Corporation) [Auto | Running] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (CLTNetCnService)
SRV - [2007/08/24 08:07:00 | 000,149,864 | ---- | M] (Symantec Corporation) [Auto | Running] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccSetMgr)
SRV - [2007/08/24 08:07:00 | 000,149,864 | ---- | M] (Symantec Corporation) [Auto | Running] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe -- (ccEvtMgr)
SRV - [2007/08/22 23:35:00 | 003,192,184 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- c:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)
SRV - [2007/08/22 23:35:00 | 000,243,064 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- c:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2007/08/21 10:21:00 | 000,055,640 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe -- (comHost)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2010/09/13 16:27:40 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/10 14:57:49 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/09/07 03:49:00 | 000,298,448 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 21:42:38 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 21:42:38 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/19 21:42:36 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/07/12 04:34:02 | 000,054,112 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgfwd6x.sys -- (Avgfwfd)
DRV - [2010/07/09 15:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/02/11 12:38:14 | 002,324,512 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/14 03:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2007/10/26 04:51:22 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007/10/10 02:00:00 | 000,865,904 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20071010.023\NAVEX15.SYS -- (NAVEX15)
DRV - [2007/10/10 02:00:00 | 000,081,232 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Symantec\Definitions\VirusDefs\20071010.023\NAVENG.SYS -- (NAVENG)
DRV - [2007/09/10 13:17:40 | 001,035,168 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007/09/07 07:36:08 | 000,156,928 | ---- | M] (ViXS Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\xcbda.sys -- (xcbdaNtsc) ViXS Tuner Card (NTSC)
DRV - [2007/08/17 00:23:00 | 000,446,512 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys -- (SPBBCDrv)
DRV - [2007/08/15 00:27:00 | 000,180,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20070823.002\IDSvix86.sys -- (IDSvix86)
DRV - [2007/08/12 23:50:00 | 000,188,464 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2007/08/12 23:50:00 | 000,022,320 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2007/08/09 03:27:00 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SymIM.sys -- (SymIMMP)
DRV - [2007/08/09 03:27:00 | 000,031,280 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SymIM.sys -- (SymIM)
DRV - [2007/08/08 02:39:00 | 000,036,056 | ---- | M] (Symantec Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CO_Mon.sys -- (CO_Mon)
DRV - [2007/07/30 09:43:00 | 000,317,616 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\srtspl.sys -- (SRTSPL)
DRV - [2007/07/30 09:43:00 | 000,278,576 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\srtsp.sys -- (SRTSP)
DRV - [2007/07/30 09:43:00 | 000,043,696 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\srtspx.sys -- (SRTSPX)
DRV - [2006/11/02 02:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 02:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 02:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 02:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 02:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 02:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 02:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 02:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 02:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 02:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 02:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 02:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 02:50:24 | 000,088,680 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2006/11/02 02:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 02:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 02:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 02:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2006/11/02 02:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 02:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 02:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 02:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 02:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 02:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 02:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 02:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 02:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 02:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 02:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 02:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 02:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 02:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 02:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 02:49:30 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2006/11/02 02:49:28 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2006/11/02 02:49:20 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2006/11/02 01:55:05 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/11/02 01:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 01:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 01:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 01:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 01:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 01:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 00:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 00:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2006/11/02 00:30:53 | 000,464,384 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\BCMWL6.SYS -- (BCM43XV)
DRV - [2005/12/12 10:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...lion&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox...aspx?tbid=80051
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox...id=80051&lng=en
IE - HKLM\..\URLSearchHook: {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRune.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.inbox.com...id=80051&lng=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://search.condui...&ctid=CT2680363
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/10/18 17:24:28 | 000,000,000 | ---D | M]

[2010/09/10 21:07:19 | 000,000,000 | ---D | M] -- C:\Users\Jeremy\AppData\Roaming\Mozilla\Extensions

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Runescape Toolbar) - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRune.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Runescape Toolbar) - {a8864317-e18b-4292-99d9-e6e65ab905d3} - C:\Program Files\Runescape\tbRune.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Runescape Toolbar) - {A8864317-E18B-4292-99D9-E6E65AB905D3} - C:\Program Files\Runescape\tbRune.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ccApp] c:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [isCfgWiz] c:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe (Symantec Corporation)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [Steam] e:\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll (Google Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Jeremy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Jeremy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/10 14:41:36 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/07/18 16:45:31 | 000,000,000 | ---D | M] - E:\Autorun -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/18 21:21:37 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\Desktop\gmer
[2010/10/18 20:14:07 | 000,574,464 | ---- | C] (OldTimer Tools) -- C:\Users\Jeremy\Desktop\OTL.exe
[2010/10/18 17:28:20 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\AVG10
[2010/10/18 17:26:24 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2010/10/18 17:23:59 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG10
[2010/10/18 17:23:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG
[2010/10/18 17:22:49 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/10/18 17:16:19 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010/10/18 17:15:44 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2010/10/18 17:15:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2010/10/18 17:15:34 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\Winamp
[2010/10/18 17:15:34 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp
[2010/10/18 17:14:09 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2010/10/18 17:02:24 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/10/17 13:15:42 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\Malwarebytes
[2010/10/17 13:15:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/10/17 13:15:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/10/17 13:15:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/17 13:15:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/10/15 18:03:27 | 000,000,000 | ---D | C] -- C:\Program Files\Zune
[2010/10/15 18:01:47 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2010/10/15 16:42:28 | 000,038,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2010/10/15 16:40:03 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2010/10/15 16:40:02 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2010/10/15 16:40:02 | 000,162,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2010/10/15 15:10:39 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\fretsonfire
[2010/10/15 15:10:14 | 000,000,000 | ---D | C] -- C:\Program Files\Frets on Fire
[2010/10/15 14:53:23 | 000,000,000 | ---D | C] -- C:\Program Files\Inbox Toolbar
[2010/10/13 21:23:09 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\.minecraft
[2010/10/13 21:22:58 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\Desktop\MCRF
[2010/10/13 20:48:21 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010/10/13 20:48:20 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/10/13 20:48:20 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/10/13 20:48:17 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/10/12 21:06:54 | 000,000,000 | ---D | C] -- C:\ZDaemon
[2010/10/10 19:24:02 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\TeamViewer
[2010/10/10 19:23:56 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2010/10/07 19:44:45 | 000,000,000 | ---D | C] -- C:\Program Files\Utherverse Digital Inc
[2010/10/07 19:40:18 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\Imprudence
[2010/10/07 19:40:18 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Local\Imprudence
[2010/10/07 19:39:23 | 000,000,000 | ---D | C] -- C:\Program Files\Imprudence
[2010/10/07 18:07:55 | 000,000,000 | ---D | C] -- C:\Program Files\W3i, LLC
[2010/10/07 11:21:30 | 000,117,760 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\System32\hpz3l4v2.dll
[2010/10/06 03:33:12 | 000,000,000 | ---D | C] -- C:\Program Files\Phoenix Viewer
[2010/10/03 18:49:42 | 000,000,000 | ---D | C] -- C:\Program Files\Search Toolbar
[2010/10/02 14:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Procaster
[2010/09/28 16:42:02 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\Template
[2010/09/27 23:08:45 | 000,839,680 | ---- | C] (http://www.mp3dev.org/) -- C:\Windows\System32\lameACM.acm
[2010/09/27 23:08:45 | 000,151,552 | ---- | C] (fccHandler) -- C:\Windows\System32\ac3acm.acm
[2010/09/27 23:08:44 | 000,217,088 | ---- | C] (www.helixcommunity.org) -- C:\Windows\System32\yv12vfw.dll
[2010/09/27 23:08:38 | 000,000,000 | ---D | C] -- C:\Program Files\K-Lite Codec Pack
[2010/09/27 08:24:29 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2010/09/27 08:24:29 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2010/09/27 08:24:28 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2010/09/27 08:24:27 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010/09/27 08:24:27 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010/09/27 08:24:26 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010/09/27 08:24:26 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010/09/27 08:24:24 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010/09/27 08:24:24 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010/09/27 08:24:23 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010/09/27 08:24:22 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2010/09/27 08:24:22 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2010/09/27 08:24:21 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2010/09/27 07:54:33 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Local\Oblivion
[2010/09/26 10:00:26 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\Desktop\fose_v1_2_beta2
[2010/09/25 16:23:15 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Local\Fallout3
[2010/09/25 16:22:39 | 000,000,000 | ---D | C] -- C:\Windows\System32\xlive
[2010/09/25 16:22:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games for Windows - LIVE
[2010/09/25 16:20:54 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2010/09/25 16:20:54 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2010/09/25 16:20:53 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2010/09/25 16:20:53 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2010/09/25 16:20:52 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2010/09/25 16:20:52 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2010/09/25 16:20:51 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2010/09/25 16:20:50 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2010/09/25 16:20:49 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2010/09/25 16:20:49 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2010/09/25 16:20:48 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2010/09/25 16:20:48 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2010/09/25 16:20:46 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2010/09/25 16:20:46 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2010/09/25 16:20:41 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2010/09/25 16:20:41 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2010/09/25 16:20:40 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2010/09/25 16:20:39 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2010/09/25 16:20:38 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2010/09/25 16:20:37 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2010/09/25 16:20:36 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2010/09/25 16:20:35 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2010/09/25 16:20:35 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2010/09/25 16:20:35 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2010/09/25 16:20:34 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2010/09/25 16:20:34 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2010/09/25 16:20:33 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2010/09/25 16:20:32 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2010/09/25 16:20:31 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2010/09/25 16:20:31 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2010/09/25 16:20:30 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2010/09/25 16:20:29 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2010/09/25 16:20:28 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2010/09/25 16:20:27 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2010/09/25 16:20:26 | 003,426,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_32.dll
[2010/09/25 16:20:25 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2010/09/25 16:20:25 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2010/09/25 16:20:24 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2010/09/25 16:20:24 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2010/09/25 16:20:23 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2010/09/25 16:20:22 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2010/09/25 16:20:22 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2010/09/25 16:20:21 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2010/09/25 16:20:13 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_30.dll
[2010/09/25 16:20:13 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2010/09/25 16:20:13 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2010/09/25 16:20:12 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2010/09/25 16:20:11 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2010/09/25 16:20:10 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2010/09/25 16:20:09 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2010/09/25 16:20:08 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2010/09/25 16:20:07 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2010/09/25 16:19:11 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\Documents\My Games
[2010/09/25 16:16:26 | 000,000,000 | ---D | C] -- C:\fomm
[2010/09/24 13:19:16 | 000,444,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneWlanCfgSvc.exe
[2010/09/24 12:11:44 | 000,365,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneNetProxy.dll
[2010/09/24 12:11:44 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneUsbTransport.dll
[2010/09/24 12:11:44 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneTcp2Udp.dll
[2010/09/24 12:11:44 | 000,058,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneRegUtil.dll
[2010/09/24 12:11:44 | 000,046,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZunePTDNS.dll
[2010/09/24 12:11:42 | 000,205,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneCoInst.dll
[2010/09/24 12:11:42 | 000,203,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ZuneMTPZ.dll
[2010/09/24 11:31:26 | 001,837,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFUpdate_01009.dll
[2010/09/24 11:31:24 | 001,461,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01009.dll
[2010/09/23 09:26:00 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\Documents\StarCraft II
[2010/09/23 09:26:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2010/09/23 09:26:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2010/09/23 05:31:04 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\SC2-WingsOfLiberty-enUS-Installer
[2010/09/21 13:40:09 | 000,000,000 | ---D | C] -- C:\Program Files\Nox
[2010/09/21 11:37:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/09/21 11:35:37 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2010/09/21 11:35:37 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2010/09/21 11:35:37 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2010/09/21 11:32:32 | 000,000,000 | ---D | C] -- C:\Program Files\Icecast2 Win32
[2010/09/20 10:24:07 | 000,000,000 | ---D | C] -- C:\Users\Jeremy\AppData\Roaming\Ventrilo
[2010/09/20 10:20:53 | 000,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2010/09/20 10:19:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard

========== Files - Modified Within 30 Days ==========

[2010/10/18 21:20:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-623764682-1910492993-2792600819-1000UA.job
[2010/10/18 21:19:27 | 000,037,013 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/10/18 21:19:26 | 000,037,013 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/10/18 21:19:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/10/18 20:41:01 | 000,003,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/18 20:41:01 | 000,003,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/18 20:33:06 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/10/18 20:14:08 | 000,574,464 | ---- | M] (OldTimer Tools) -- C:\Users\Jeremy\Desktop\OTL.exe
[2010/10/18 20:13:33 | 000,286,338 | ---- | M] () -- C:\Users\Jeremy\Desktop\gmer.zip
[2010/10/18 19:53:31 | 000,662,868 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/10/18 19:53:31 | 000,120,830 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/10/18 19:41:04 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/10/18 19:15:46 | 000,000,099 | ---- | M] () -- C:\Users\Jeremy\jagex_runescape_preferences2.dat
[2010/10/18 18:53:16 | 000,000,046 | ---- | M] () -- C:\Users\Jeremy\jagex_runescape_preferences.dat
[2010/10/18 18:00:53 | 000,000,024 | ---- | M] () -- C:\Users\Jeremy\jagexappletviewer.preferences
[2010/10/18 17:29:07 | 097,130,709 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/10/18 17:29:07 | 000,624,891 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2010/10/18 17:26:05 | 000,000,832 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/10/18 17:16:51 | 000,000,778 | ---- | M] () -- C:\Users\Public\Desktop\Winamp.lnk
[2010/10/18 17:02:24 | 215,315,326 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/10/18 13:20:14 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-623764682-1910492993-2792600819-1000Core.job
[2010/10/18 03:11:34 | 000,000,666 | ---- | M] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Phoenix - Shortcut.lnk
[2010/10/17 23:13:25 | 000,575,834 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_006.png
[2010/10/17 17:08:19 | 000,000,680 | ---- | M] () -- C:\Users\Jeremy\AppData\Local\d3d9caps.dat
[2010/10/17 13:15:37 | 000,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/16 21:37:46 | 000,044,916 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_20101017.jpg
[2010/10/15 18:16:19 | 000,005,120 | ---- | M] () -- C:\Users\Jeremy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/15 18:03:33 | 000,000,840 | ---- | M] () -- C:\Users\Public\Desktop\Zune.lnk
[2010/10/15 17:42:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2010/10/15 16:42:46 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2010/10/15 16:42:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/10/15 14:50:08 | 000,553,269 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_018.png
[2010/10/13 20:47:58 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010/10/13 20:47:58 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/10/13 20:47:58 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/10/13 20:47:58 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/10/13 04:43:40 | 000,001,052 | ---- | M] () -- C:\Users\Public\Desktop\The Weather Channel Desktop .lnk
[2010/10/12 22:57:00 | 001,099,378 | ---- | M] () -- C:\Users\Jeremy\Documents\fioxchap.jpg
[2010/10/12 21:07:01 | 000,000,556 | ---- | M] () -- C:\Users\Public\Desktop\ZDaemon Game Launcher.lnk
[2010/10/12 20:55:14 | 000,000,499 | ---- | M] () -- C:\Users\Jeremy\Desktop\external.lnk
[2010/10/11 17:34:05 | 000,171,106 | ---- | M] () -- C:\Users\Jeremy\Documents\Picture 1.png
[2010/10/10 19:24:01 | 000,000,957 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010/10/10 00:53:35 | 000,034,086 | ---- | M] () -- C:\Users\Jeremy\swordskatana.jpg
[2010/10/10 00:53:35 | 000,032,324 | ---- | M] () -- C:\Users\Jeremy\swordsnecklace.jpg
[2010/10/10 00:53:35 | 000,032,050 | ---- | M] () -- C:\Users\Jeremy\swordskatana2.jpg
[2010/10/10 00:53:35 | 000,031,269 | ---- | M] () -- C:\Users\Jeremy\swordsskullsword2.jpg
[2010/10/10 00:53:35 | 000,030,717 | ---- | M] () -- C:\Users\Jeremy\swordsdagger.jpg
[2010/10/10 00:53:35 | 000,027,453 | ---- | M] () -- C:\Users\Jeremy\swordsskullsword.jpg
[2010/10/09 06:46:57 | 001,167,543 | ---- | M] () -- C:\Users\Jeremy\Documents\banevserith_001.png
[2010/10/09 06:33:37 | 001,501,478 | ---- | M] () -- C:\Users\Jeremy\Documents\Bane_001.png
[2010/10/07 19:40:16 | 000,000,940 | ---- | M] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Imprudence (2).lnk
[2010/10/07 19:40:03 | 000,000,924 | ---- | M] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Imprudence.lnk
[2010/10/07 19:40:03 | 000,000,900 | ---- | M] () -- C:\Users\Public\Desktop\Imprudence.lnk
[2010/10/06 02:46:31 | 001,536,122 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_005.png
[2010/10/06 02:33:05 | 000,971,714 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_012.png
[2010/10/06 02:32:56 | 000,790,372 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_013.png
[2010/10/06 02:28:44 | 001,880,821 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_015.png
[2010/10/04 10:40:26 | 000,191,879 | ---- | M] () -- C:\Users\Jeremy\Documents\Soren (Science mode 8D).jpg
[2010/10/04 10:39:39 | 001,721,275 | ---- | M] () -- C:\Users\Jeremy\Documents\Snapshot_004.png
[2010/10/02 14:56:56 | 000,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Livestream Procaster.lnk
[2010/09/30 11:50:13 | 000,092,109 | ---- | M] () -- C:\Users\Jeremy\Picture 4.png
[2010/09/30 11:50:11 | 000,095,006 | ---- | M] () -- C:\Users\Jeremy\Picture 8.png
[2010/09/28 16:42:26 | 000,000,226 | ---- | M] () -- C:\Users\Jeremy\AppData\Roaming\wklnhst.dat
[2010/09/28 16:35:09 | 000,019,510 | ---- | M] () -- C:\Users\Jeremy\Documents\MetlassaDanteBattle.docx
[2010/09/26 12:45:48 | 004,521,856 | ---- | M] () -- C:\Users\Jeremy\Documents\89.mp3
[2010/09/24 13:25:18 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\pt-PT\ZuneDriver.dll.mui
[2010/09/24 13:25:10 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\pt-BR\ZuneDriver.dll.mui
[2010/09/24 13:25:02 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\nl-NL\ZuneDriver.dll.mui
[2010/09/24 13:24:56 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\it-IT\ZuneDriver.dll.mui
[2010/09/24 13:24:48 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\fr-FR\ZuneDriver.dll.mui
[2010/09/24 13:24:42 | 000,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\es-ES\ZuneDriver.dll.mui
[2010/09/24 13:24:34 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\de-DE\ZuneDriver.dll.mui
[2010/09/24 13:19:16 | 000,444,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneWlanCfgSvc.exe
[2010/09/24 12:14:48 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\en-US\ZuneDriver.dll.mui
[2010/09/24 12:11:44 | 000,365,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneNetProxy.dll
[2010/09/24 12:11:44 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneUsbTransport.dll
[2010/09/24 12:11:44 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneTcp2Udp.dll
[2010/09/24 12:11:44 | 000,058,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneRegUtil.dll
[2010/09/24 12:11:44 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZunePTDNS.dll
[2010/09/24 12:11:42 | 000,796,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\UMDF\ZuneDriver.dll
[2010/09/24 12:11:42 | 000,205,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneCoInst.dll
[2010/09/24 12:11:42 | 000,203,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ZuneMTPZ.dll
[2010/09/24 11:31:26 | 001,837,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WUDFUpdate_01009.dll
[2010/09/24 11:31:24 | 001,461,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01009.dll
[2010/09/23 21:03:41 | 000,002,049 | ---- | M] () -- C:\Users\Jeremy\Desktop\Google Chrome.lnk
[2010/09/23 21:03:41 | 000,002,011 | ---- | M] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/09/23 09:35:09 | 000,000,577 | ---- | M] () -- C:\Users\Public\Desktop\StarCraft II.lnk
[2010/09/21 11:32:33 | 000,000,863 | ---- | M] () -- C:\Users\Jeremy\Desktop\Icecast2 Win32.lnk
[2010/09/20 10:21:06 | 000,000,262 | ---- | M] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/09/20 10:20:58 | 000,000,754 | ---- | M] () -- C:\Users\Public\Desktop\Ventrilo.lnk

========== Files Created - No Company Name ==========

[2010/10/18 20:13:31 | 000,286,338 | ---- | C] () -- C:\Users\Jeremy\Desktop\gmer.zip
[2010/10/18 17:29:07 | 097,130,709 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2010/10/18 17:29:07 | 000,624,891 | ---- | C] () -- C:\Windows\System32\drivers\AVG\iavifw.avm
[2010/10/18 17:26:05 | 000,000,832 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2011.lnk
[2010/10/18 17:16:51 | 000,000,778 | ---- | C] () -- C:\Users\Public\Desktop\Winamp.lnk
[2010/10/18 17:02:07 | 215,315,326 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/10/18 03:11:34 | 000,000,666 | ---- | C] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Phoenix - Shortcut.lnk
[2010/10/17 23:13:01 | 000,575,834 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_006.png
[2010/10/17 13:15:37 | 000,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/16 21:37:43 | 000,044,916 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_20101017.jpg
[2010/10/15 18:03:33 | 000,000,840 | ---- | C] () -- C:\Users\Public\Desktop\Zune.lnk
[2010/10/15 17:42:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2010/10/15 16:42:46 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2010/10/15 16:42:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/10/15 16:42:29 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2010/10/15 14:49:45 | 000,553,269 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_018.png
[2010/10/13 04:41:04 | 000,000,680 | ---- | C] () -- C:\Users\Jeremy\AppData\Local\d3d9caps.dat
[2010/10/12 22:54:24 | 001,099,378 | ---- | C] () -- C:\Users\Jeremy\Documents\fioxchap.jpg
[2010/10/12 21:07:01 | 000,000,556 | ---- | C] () -- C:\Users\Public\Desktop\ZDaemon Game Launcher.lnk
[2010/10/12 20:55:16 | 000,000,499 | ---- | C] () -- C:\Users\Jeremy\Desktop\external.lnk
[2010/10/11 17:34:01 | 000,171,106 | ---- | C] () -- C:\Users\Jeremy\Documents\Picture 1.png
[2010/10/10 19:24:01 | 000,000,957 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 5.lnk
[2010/10/10 00:53:34 | 000,034,086 | ---- | C] () -- C:\Users\Jeremy\swordskatana.jpg
[2010/10/10 00:53:34 | 000,032,324 | ---- | C] () -- C:\Users\Jeremy\swordsnecklace.jpg
[2010/10/10 00:53:34 | 000,032,050 | ---- | C] () -- C:\Users\Jeremy\swordskatana2.jpg
[2010/10/10 00:53:34 | 000,031,269 | ---- | C] () -- C:\Users\Jeremy\swordsskullsword2.jpg
[2010/10/10 00:53:34 | 000,030,717 | ---- | C] () -- C:\Users\Jeremy\swordsdagger.jpg
[2010/10/10 00:53:34 | 000,027,453 | ---- | C] () -- C:\Users\Jeremy\swordsskullsword.jpg
[2010/10/09 06:46:57 | 001,167,543 | ---- | C] () -- C:\Users\Jeremy\Documents\banevserith_001.png
[2010/10/09 06:33:37 | 001,501,478 | ---- | C] () -- C:\Users\Jeremy\Documents\Bane_001.png
[2010/10/07 19:40:16 | 000,000,940 | ---- | C] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Imprudence (2).lnk
[2010/10/07 19:40:03 | 000,000,924 | ---- | C] () -- C:\Users\Jeremy\Application Data\Microsoft\Internet Explorer\Quick Launch\Imprudence.lnk
[2010/10/07 19:40:03 | 000,000,900 | ---- | C] () -- C:\Users\Public\Desktop\Imprudence.lnk
[2010/10/07 11:18:33 | 000,005,120 | ---- | C] () -- C:\Users\Jeremy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/06 02:45:53 | 001,536,122 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_005.png
[2010/10/06 02:32:26 | 000,971,714 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_012.png
[2010/10/06 02:32:18 | 000,790,372 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_013.png
[2010/10/06 02:27:53 | 001,880,821 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_015.png
[2010/10/04 10:40:25 | 000,191,879 | ---- | C] () -- C:\Users\Jeremy\Documents\Soren (Science mode 8D).jpg
[2010/10/04 10:39:39 | 001,721,275 | ---- | C] () -- C:\Users\Jeremy\Documents\Snapshot_004.png
[2010/10/02 14:56:56 | 000,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Livestream Procaster.lnk
[2010/09/30 11:50:08 | 000,095,006 | ---- | C] () -- C:\Users\Jeremy\Picture 8.png
[2010/09/30 11:50:08 | 000,092,109 | ---- | C] () -- C:\Users\Jeremy\Picture 4.png
[2010/09/28 16:42:00 | 000,000,226 | ---- | C] () -- C:\Users\Jeremy\AppData\Roaming\wklnhst.dat
[2010/09/28 16:35:07 | 000,019,510 | ---- | C] () -- C:\Users\Jeremy\Documents\MetlassaDanteBattle.docx
[2010/09/27 23:08:48 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/09/27 23:08:47 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010/09/27 23:08:45 | 000,000,414 | ---- | C] () -- C:\Windows\System32\lame_acm.xml
[2010/09/27 23:08:44 | 000,790,528 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/09/27 23:08:44 | 000,134,144 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/09/27 23:08:42 | 000,108,032 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2010/09/26 12:35:19 | 004,521,856 | ---- | C] () -- C:\Users\Jeremy\Documents\89.mp3
[2010/09/23 09:26:00 | 000,000,577 | ---- | C] () -- C:\Users\Public\Desktop\StarCraft II.lnk
[2010/09/21 11:32:33 | 000,000,863 | ---- | C] () -- C:\Users\Jeremy\Desktop\Icecast2 Win32.lnk
[2010/09/20 10:20:58 | 000,000,754 | ---- | C] () -- C:\Users\Public\Desktop\Ventrilo.lnk
[2010/09/20 10:20:47 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/09/12 01:37:09 | 000,037,013 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/09/12 01:37:08 | 000,037,013 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/09/10 18:26:59 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/09/10 14:33:50 | 000,000,342 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010/09/10 14:14:42 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2010/09/10 14:14:42 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2008/10/22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2004/04/29 14:24:04 | 000,028,672 | ---- | C] () -- C:\Windows\System32\vorbisfile.dll
[2004/04/29 14:24:02 | 000,974,848 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2004/04/29 14:24:00 | 000,049,152 | ---- | C] () -- C:\Windows\System32\ogg.dll

< End of report >



Thanks in advance for taking the time to read and help with this problem.
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,187 posts
  • MVP
Appears you are running two anti-viruses. This alone can result in "Cripplingly slow performance"

Uninstall Norton/Symantec then run the Norton/Symantec removal tool

ftp://ftp.symantec.com/public/english_us_canada/removal_tools/Norton_Removal_Tool.exe

You would also be wise to uninstall utorrent. P2P programs are very dangerous and a resource hog if you let them run all the time.

If it's still slow after uninstalling Norton and utorrent then run another OTL QuickScan and post the log then download and run

ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Rename this file -- (call it george.exe ) to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Doubleclick on george to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Re-activate your protection programs at this time :!:


Ron
  • 0

#3
Lockbolt

Lockbolt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Hello, Ron!


Things went a little bit differently than predicted, so i'm thinking it best to tell you what happened and wait before touching anything. I uninstalled the two programs, (norton and utorrent), and experienced no lag loss, once I ran combofix the computer actually memory dumped, and once it started up again the lag was gone. Everything's running nicely now, malwarebytes found and deleted 5 threats upon startup without me asking it to scan.


Help is appreciated, i'll stick around till you give the all clear.

Lockbolt

P.S - Combofix didn't create a log from what I can see.

Edited by Lockbolt, 22 October 2010 - 01:38 AM.

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,187 posts
  • MVP
I'm glad things have improved but I'm not happy that Combofix didn't run. Did it leave a file at
C:\Combofix.txt.

Ron
  • 0

#5
Lockbolt

Lockbolt

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
No such luck. It went to the window where it said it was preparing to run, I'd not touched anything since it started, but it memory dumped shortly after.

No log at that location.

Lockbolt
  • 0

#6
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,187 posts
  • MVP
Did you remember to turn off AVG when downloading and running? AVG9 was very hard to turn off. Don't know about AVG10.

Did you right click to Run As Administrator?

Try downloading it again but this time rename it to paul.exe

Run OTL by right clicking and Run As Admin then hit QuickScan and post the log.

Close all programs. Right click on a browser (IE or Firefox) and Run As Admin then go to

quickscan.bitdefender.com/

When it finishes there is a report option. Click on it and copy and paste the report (even if it says nothing found).

Download

http://ad13.geekstogo.com/MBRCheck.exe

Save it and run it by right clicking and Run As Admin. It will produce a log MBRCheck(date).txt on your desktop. Copy and paste it into a reply.

  • Go to this page and Download TDSSKiller.zip to your Desktop.
  • Extract its contents to your desktop and drag TDSSKiller.exe on the desktop, not in the folder.
  • Rightclick on TDSSKiller.exe and Run As Admin
  • If TDSSKiller alerts you that the system needs to reboot, please consent.
  • When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.



Ron
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP