Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

FB Flash games; CPU Usage = 100%


  • Please log in to reply

#1
wake_me

wake_me

    New Member

  • Member
  • Pip
  • 1 posts
My parents have been playing Double Down casino on Facebook and it has been causing the computer to run loud.

I've opened task manager and as soon as the program starts running the CPU Usage jumps from about 7% to 90+%

I've been running defrag, AVG, limiting start up programs etc.

While researching I came across this site and thought if I posted this log I might gain some more information as I'm not terribly knowledgeable about computers myself.

thank you for your help.
-----------------------------------------------------------------
OTL logfile created on: 07/06/2011 8:31:29 AM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Dianne\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.87 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 32.87% Memory free
5.96 Gb Paging File | 4.15 Gb Available in Paging File | 69.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 363.03 Gb Total Space | 41.25 Gb Free Space | 11.36% Space Free | Partition Type: NTFS
Drive D: | 9.58 Gb Total Space | 1.31 Gb Free Space | 13.67% Space Free | Partition Type: NTFS
Drive E: | 159.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DIANNE-PC | User Name: Dianne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/07 08:30:52 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Dianne\Downloads\OTL.exe
PRC - [2011/06/05 05:47:22 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Users\Dianne\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe
PRC - [2011/03/26 10:50:41 | 000,079,872 | ---- | M] (SanDisk Corporation) -- C:\Users\Dianne\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2011/03/15 09:49:37 | 002,071,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/11/24 09:04:06 | 002,331,544 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgfws9.exe
PRC - [2010/11/24 09:04:06 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/09/20 10:37:14 | 000,621,920 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/08/26 17:15:58 | 000,028,766 | ---- | M] (iWon) -- C:\Program Files\iWonIE\bar\1.bin\idbarsvc.exe
PRC - [2010/08/26 17:15:58 | 000,020,480 | ---- | M] (iWon) -- C:\Program Files\iWonIE\bar\1.bin\idbrmon.exe
PRC - [2010/07/21 09:06:19 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/07/01 12:17:17 | 001,352,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/06/22 10:56:01 | 000,515,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/22 10:55:59 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/22 10:55:51 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/22 10:55:50 | 000,842,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/06/17 12:21:17 | 001,509,384 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
PRC - [2010/06/17 12:21:15 | 000,864,112 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/04/11 02:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe
PRC - [2008/01/19 03:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/19 03:33:05 | 000,671,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dfrgui.exe
PRC - [2008/01/19 03:33:05 | 000,226,816 | ---- | M] (Microsoft Corp.) -- C:\WINDOWS\System32\Defrag.exe
PRC - [2008/01/19 03:33:05 | 000,163,840 | ---- | M] (Microsoft Corp.) -- C:\WINDOWS\System32\DfrgNtfs.exe
PRC - [2007/10/25 09:52:08 | 004,702,208 | ---- | M] (Realtek Semiconductor) -- C:\WINDOWS\RtHDVCpl.exe
PRC - [2007/04/18 11:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
PRC - [2007/02/15 07:59:00 | 000,118,784 | ---- | M] (OsdMaestro) -- C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe


========== Modules (SafeList) ==========

MOD - [2011/06/07 08:30:52 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Dianne\Downloads\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2010/06/22 10:56:01 | 000,012,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/03/18 08:11:02 | 000,947,528 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2010/11/24 16:33:26 | 000,921,600 | ---- | M] () [On_Demand | Stopped] -- C:\ProgramData\TVersity\Media Server\MediaServer.exe -- (TVersityMediaServer)
SRV - [2010/11/24 09:04:06 | 002,331,544 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgfws9.exe -- (avgfws9)
SRV - [2010/08/26 17:15:58 | 000,028,766 | ---- | M] (iWon) [Auto | Running] -- C:\Program Files\iWonIE\bar\1.bin\idbarsvc.exe -- (iWonIEService)
SRV - [2010/07/21 09:06:19 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/07/01 12:17:17 | 001,352,832 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/06/22 10:55:59 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/06/22 10:55:55 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - [2011/05/05 11:41:25 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/11/10 03:49:50 | 004,323,040 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\lvuvc.sys -- (LVUVC) Logitech Webcam 250(UVC)
DRV - [2010/06/22 10:55:56 | 000,122,448 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys -- (AVGIDSDrivervtx)
DRV - [2010/06/22 10:55:56 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys -- (AVGIDSFiltervtx)
DRV - [2010/06/22 10:55:56 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys -- (AVGIDSShimvtx)
DRV - [2010/06/22 10:55:56 | 000,025,168 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\AVGIDSvx.sys -- (AVGIDSErHrvtx)
DRV - [2010/06/22 10:55:52 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/06/03 12:18:37 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010/06/01 09:26:28 | 000,029,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/04/12 12:38:25 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2010/04/12 12:37:45 | 000,024,856 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\avgfwd6x.sys -- (Avgfwfd)
DRV - [2008/05/22 14:49:00 | 007,465,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/05/08 05:05:18 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2008/05/08 05:03:18 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2007/10/26 07:51:22 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2007/10/18 07:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/09/10 16:17:40 | 001,035,168 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2005/12/12 13:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\PS2.sys -- (Ps2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...lion&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...lion&pf=desktop
IE - HKLM\..\URLSearchHook: {1e7e4de1-5ef4-4baa-9250-c26258dc499a} - C:\Program Files\MapNeto_1\tbMap0.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {d5f7c10d-2f86-4e99-90da-25f8b0400992} - C:\Program Files\Mapit_1\prxtbMap0.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT3008660
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {1e7e4de1-5ef4-4baa-9250-c26258dc499a} - C:\Program Files\MapNeto_1\tbMap0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {70bd8aab-ad49-42f5-b1bd-240f078c1a11} - C:\Program Files\iWonIE\bar\1.bin\idSrcAs.dll (iWon)
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {d5f7c10d-2f86-4e99-90da-25f8b0400992} - C:\Program Files\Mapit_1\prxtbMap0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ask.com/?...7&l=dis&gct=hp"
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.11.0.100005
FF - prefs.js..extensions.enabledItems: [email protected]:6.103.018.001
FF - prefs.js..keyword.URL: "http://search.avg.co...a&lng=en-US&q="
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVG\AVG9\Toolbar\Firefox\[email protected] [2011/05/09 10:59:27 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/21 14:06:50 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/21 14:06:50 | 000,000,000 | ---D | M]

[2010/06/23 04:24:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dianne\AppData\Roaming\Mozilla\Extensions
[2010/06/23 04:24:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dianne\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/06/07 07:32:34 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dianne\AppData\Roaming\Mozilla\Firefox\Profiles\ja7mkpms.default\extensions
[2011/03/18 12:49:18 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Dianne\AppData\Roaming\Mozilla\Firefox\Profiles\ja7mkpms.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/25 16:37:55 | 000,000,000 | ---D | M] ("Remove Photo Pos toolbar") -- C:\Users\Dianne\AppData\Roaming\Mozilla\Firefox\Profiles\ja7mkpms.default\extensions\[email protected]
[2011/06/06 22:47:15 | 000,002,570 | ---- | M] () -- C:\Users\Dianne\AppData\Roaming\Mozilla\Firefox\Profiles\ja7mkpms.default\searchplugins\askcom.xml
[2011/05/23 09:22:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/11 14:36:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/09 10:59:27 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="[email protected]" em:name="AVG Security Toolbar" em:version="6.103.018.001" em:displayname="AVG Security Toolbar" em:iconURL="chrome://tavgp/skin/logo.ico" em:creator="AVG Technologies" em:description="AVG Security Toolbar" em:homepageURL="http://www.avg.com" >) -- C:\PROGRAM FILES\AVG\AVG9\TOOLBAR\FIREFOX\[email protected]
[2010/06/17 13:39:05 | 000,000,000 | ---D | M] (PlaySushi TextLinks) -- C:\USERS\DIANNE\APPDATA\ROAMING\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[email protected]
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2006/09/18 17:41:30 | 000,000,761 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MapNeto 1 Toolbar) - {1e7e4de1-5ef4-4baa-9250-c26258dc499a} - C:\Program Files\MapNeto_1\tbMap0.dll (Conduit Ltd.)
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Photo Pos toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Mapit 1 Toolbar) - {d5f7c10d-2f86-4e99-90da-25f8b0400992} - C:\Program Files\Mapit_1\prxtbMap0.dll (Conduit Ltd.)
O2 - BHO: (Toolbar BHO) - {fc130ee2-5a2a-45a7-8e09-d2ca06c795a8} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O3 - HKLM\..\Toolbar: (MapNeto 1 Toolbar) - {1e7e4de1-5ef4-4baa-9250-c26258dc499a} - C:\Program Files\MapNeto_1\tbMap0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (iWon Toolbar) - {44843b6e-d44a-4b4f-bca4-559c86633dc6} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Photo Pos toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Mapit 1 Toolbar) - {d5f7c10d-2f86-4e99-90da-25f8b0400992} - C:\Program Files\Mapit_1\prxtbMap0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (MapNeto 1 Toolbar) - {1E7E4DE1-5EF4-4BAA-9250-C26258DC499A} - C:\Program Files\MapNeto_1\tbMap0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (iWon Toolbar) - {44843B6E-D44A-4B4F-BCA4-559C86633DC6} - C:\Program Files\iWonIE\bar\1.bin\idbar.dll (iWon)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Photo Pos toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Mapit 1 Toolbar) - {D5F7C10D-2F86-4E99-90DA-25F8B0400992} - C:\Program Files\Mapit_1\prxtbMap0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll ()
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Dianne\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Dianne\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/29 00:45:16 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/07 07:45:37 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/05/28 21:06:51 | 000,000,000 | ---D | C] -- C:\Users\Dianne\AppData\Local\Windows Live
[2011/05/28 15:22:20 | 000,000,000 | ---D | C] -- C:\Users\Dianne\AppData\Local\Conduit
[2011/05/28 15:22:03 | 000,000,000 | ---D | C] -- C:\Program Files\Mapit_1
[2011/05/13 14:21:06 | 000,000,000 | ---D | C] -- C:\Users\Dianne\AppData\Local\AVG Security Toolbar
[2011/05/12 04:50:57 | 000,000,000 | ---D | C] -- C:\8362c4106e620264baa7f797
[2010/04/12 13:06:50 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Dianne\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2011/06/07 07:54:03 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/07 07:52:01 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2724373424-230375089-4032628782-1000UA.job
[2011/06/07 07:14:14 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/07 07:14:14 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/07 07:14:14 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/07 07:14:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/07 07:13:50 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2011/06/07 05:31:58 | 077,362,468 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2011/06/06 05:52:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2724373424-230375089-4032628782-1000Core.job
[2011/06/05 21:53:04 | 000,002,049 | ---- | M] () -- C:\Users\Dianne\Desktop\Google Chrome.lnk
[2011/06/05 21:53:04 | 000,002,011 | ---- | M] () -- C:\Users\Dianne\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/06/04 06:14:38 | 000,045,568 | ---- | M] () -- C:\Users\Dianne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/04 06:00:44 | 003,889,526 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/04 06:00:43 | 001,768,804 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/03 17:03:30 | 000,654,320 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavifw.avm
[2011/05/31 12:51:01 | 000,001,326 | ---- | M] () -- C:\Users\Dianne\AppData\Roaming\wklnhst.dat
[2011/05/29 07:10:56 | 000,000,945 | ---- | M] () -- C:\Users\Dianne\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/28 21:06:13 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2011/05/28 21:06:13 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2011/05/28 21:06:06 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf

========== Files Created - No Company Name ==========

[2011/05/28 21:06:06 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2011/04/11 11:41:41 | 000,000,096 | -HS- | C] () -- C:\Windows\WSYS049.SYS
[2011/04/11 11:40:09 | 000,198,483 | ---- | C] () -- C:\Windows\Photo Pos Pro Uninstaller.exe
[2010/12/26 08:09:10 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/26 07:35:25 | 000,001,474 | ---- | C] () -- C:\Users\Dianne\AppData\Roaming\SAS7_000.DAT
[2010/11/10 03:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\System32\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\System32\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\System32\DevManagerCore.dll
[2010/11/10 03:31:42 | 000,026,286 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2010/06/27 11:01:13 | 000,000,058 | -H-- | C] () -- C:\ProgramData\Ts_infos.ini
[2010/05/04 06:05:46 | 000,163,142 | ---- | C] () -- C:\Windows\hpoins28.dat
[2010/05/04 06:05:46 | 000,000,796 | ---- | C] () -- C:\Windows\hpomdl28.dat
[2010/05/01 07:29:31 | 000,001,326 | ---- | C] () -- C:\Users\Dianne\AppData\Roaming\wklnhst.dat
[2010/04/24 03:01:53 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/04/23 15:12:56 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/04/23 15:12:56 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/04/20 08:51:38 | 000,045,568 | ---- | C] () -- C:\Users\Dianne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/12 13:06:50 | 000,087,608 | ---- | C] () -- C:\Users\Dianne\AppData\Roaming\inst.exe
[2010/04/12 13:06:50 | 000,007,887 | ---- | C] () -- C:\Users\Dianne\AppData\Roaming\pcouffin.cat
[2010/04/12 13:06:50 | 000,001,144 | ---- | C] () -- C:\Users\Dianne\AppData\Roaming\pcouffin.inf
[2010/04/12 12:24:52 | 000,015,880 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2010/04/12 12:04:31 | 000,000,680 | ---- | C] () -- C:\Users\Dianne\AppData\Local\d3d9caps.dat
[2010/04/06 06:10:15 | 000,225,411 | ---- | C] () -- C:\Windows\System32\PosPrKpLib.dll
[2010/04/06 06:10:07 | 000,020,480 | ---- | C] () -- C:\Windows\System32\PosTickerLib.dll
[2010/03/02 20:00:00 | 004,555,278 | ---- | C] () -- C:\Windows\System32\libavcodec.dll
[2010/03/02 20:00:00 | 001,449,935 | ---- | C] () -- C:\Windows\System32\ffmpegmt.dll
[2010/03/02 20:00:00 | 000,882,688 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/03/02 20:00:00 | 000,877,385 | ---- | C] () -- C:\Windows\System32\ff_x264.dll
[2010/03/02 20:00:00 | 000,556,491 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
[2010/03/02 20:00:00 | 000,336,384 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll
[2010/03/02 20:00:00 | 000,324,096 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2010/03/02 20:00:00 | 000,248,320 | ---- | C] () -- C:\Windows\System32\ff_kernelDeint.dll
[2010/03/02 20:00:00 | 000,216,576 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll
[2010/03/02 20:00:00 | 000,169,984 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll
[2010/03/02 20:00:00 | 000,151,552 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll
[2010/03/02 20:00:00 | 000,145,408 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2010/03/02 20:00:00 | 000,121,856 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll
[2010/03/02 20:00:00 | 000,116,736 | ---- | C] () -- C:\Windows\System32\ff_tremor.dll
[2010/03/02 20:00:00 | 000,100,864 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll
[2010/03/02 20:00:00 | 000,097,792 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll
[2010/03/02 20:00:00 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/11/14 14:37:08 | 000,154,112 | ---- | C] () -- C:\Windows\System32\ts.dll
[2009/11/14 14:33:40 | 000,357,888 | ---- | C] () -- C:\Windows\System32\gdsmux.exe
[2009/11/14 14:33:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll
[2009/11/14 14:11:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll
[2009/11/14 14:11:42 | 000,150,016 | ---- | C] () -- C:\Windows\System32\mkx.dll
[2009/11/14 14:11:42 | 000,141,824 | ---- | C] () -- C:\Windows\System32\mp4.dll
[2009/11/14 14:11:40 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll
[2009/11/14 14:11:40 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll
[2009/11/14 14:11:38 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll
[2009/11/14 14:11:36 | 000,136,704 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe
[2009/11/14 14:11:36 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe
[2009/11/14 14:11:32 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll
[2009/11/14 14:11:32 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll
[2009/08/11 17:21:26 | 000,087,552 | ---- | C] () -- C:\Windows\System32\ac3config.exe
[2009/06/07 12:24:04 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2009/01/10 18:15:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\mmfinfo.dll
[2008/11/06 12:37:32 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2007/11/29 00:38:28 | 000,102,451 | ---- | C] () -- C:\Windows\hpqins13.dat
[2007/11/29 00:25:22 | 000,061,440 | ---- | C] () -- C:\Windows\System32\OsdRemove.exe
[2007/11/29 00:22:37 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2007/11/29 00:22:37 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2007/10/13 05:30:20 | 000,000,137 | ---- | C] () -- C:\Windows\System32\Registration.ini
[2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 000,289,808 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 003,889,526 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 001,768,804 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2005/09/23 07:52:14 | 000,078,848 | ---- | C] () -- C:\Windows\System32\OneWay.dll
[2002/06/02 10:05:40 | 000,038,912 | ---- | C] () -- C:\Windows\System32\1Way.dll

========== LOP Check ==========

[2011/04/11 14:18:10 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\ACD Systems
[2011/04/16 07:23:14 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\Apowersoft
[2010/04/12 12:46:07 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\AVG9
[2010/06/27 11:05:09 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\FxFotoDB
[2011/06/07 07:14:31 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\LimeWire
[2010/12/25 11:14:46 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\Nuance
[2011/04/16 12:52:19 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\PhotoScape
[2011/04/24 09:28:11 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\PMS
[2010/06/23 04:45:15 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\SanDisk
[2010/04/12 11:58:15 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\Snapfish
[2010/04/13 06:39:47 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\SuperAdBlocker.com
[2010/05/01 07:29:32 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\Template
[2011/06/04 10:52:36 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\uTorrent
[2011/05/28 15:05:17 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\Vso
[2010/05/11 07:32:06 | 000,000,000 | ---D | M] -- C:\Users\Dianne\AppData\Roaming\WinBatch
[2011/06/07 05:39:32 | 000,032,544 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 805 bytes -> C:\Users\Dianne\Documents\Fw_ 13 pictures for you.eml:OECustomProperty
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F35A93AD

< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP