I have a HP Compaq mini netbook which runs on win xp pro sp3.The OS was pre installed by the manufacturer. It has a RAM of 1 gb and hdd of 250 gb. The problem started some 4 months ago when it started taking around 10 minutes to put it on, but when it is on it didn't have any problem. But as from last week it started being very slow in opening all the programs, including loading the firefox. I have tried scanning using the OTL so that i can post the scan log in vain. It scans up to scanning module... then it doesn't respond at all, i have waited for more than 30 minutes, with no response.When i restart it(OTL) again it reaches the same point. I have used the OTL.exe and OTL.sr and both of them behave the same.
Please assist me.
Regards.
I have managed to run OTL on safe mode and these are my logs
OTL logfile created on: 10/30/2011 11:31:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 798.83 Mb Available Physical Memory | 78.68% Memory free
2.38 Gb Paging File | 2.31 Gb Available in Paging File | 96.79% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.13 Gb Total Space | 23.35 Gb Free Space | 33.29% Space Free | Partition Type: NTFS
Drive D: | 78.91 Gb Total Space | 21.15 Gb Free Space | 26.81% Space Free | Partition Type: NTFS
Drive F: | 6.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: COMPUTER_1 | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/10/27 19:51:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2008/04/14 01:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (HWDeviceService.exe)
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/08/11 10:53:34 | 000,218,624 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Internet Everywhere 3G+\UpdateDog\ouc.exe -- (Internet Everywhere 3G+. RunOuc)
SRV - [2010/09/24 20:12:15 | 000,352,976 | ---- | M] (Kaspersky Lab ZAO) [Auto | Stopped] -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe -- (AVP)
SRV - [2010/07/02 12:16:05 | 000,221,184 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- c:\Program Files\IDT\WDM\stacsv.exe -- (STacSV)
SRV - [2009/12/21 09:53:26 | 000,512,000 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ZTEMT UI\bin\MonServiceUDisk.exe -- (UDisk Monitor)
SRV - [2007/11/06 23:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
========== Driver Services (SafeList) ==========
DRV - [2011/08/11 10:53:37 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2011/08/11 10:53:37 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2011/08/11 10:53:36 | 000,235,392 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2011/08/11 10:53:36 | 000,193,792 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2011/03/28 20:46:40 | 000,098,160 | ---- | M] (Tonec Inc.) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\idmtdi.sys -- (IDMTDI)
DRV - [2010/11/09 14:56:12 | 000,098,392 | ---- | M] (Sunbelt Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SBREDrv.sys -- (SBRE)
DRV - [2010/09/24 20:12:15 | 000,475,736 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2010/09/08 08:56:50 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2010/09/08 08:56:50 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2010/09/08 08:56:48 | 000,107,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2010/09/04 01:24:40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\taphss.sys -- (taphss)
DRV - [2010/07/17 22:22:49 | 001,746,432 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2010/07/15 18:44:20 | 000,013,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\epmntdrv.sys -- (epmntdrv)
DRV - [2010/07/15 18:44:20 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2010/06/09 17:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\kl2.sys -- (kl2)
DRV - [2010/06/09 17:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\kl1.sys -- (KL1)
DRV - [2010/05/07 12:06:26 | 000,032,856 | ---- | M] (Kaspersky Lab ZAO) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\klim5.sys -- (klim5)
DRV - [2009/11/25 14:51:28 | 000,104,704 | ---- | M] (ZTEMT Incorporated) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CT_ZTEMT_U_USBSER.sys -- (ztemtusbser)
DRV - [2009/11/02 20:27:24 | 000,019,472 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/06/29 23:44:38 | 001,642,931 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2009/04/21 20:13:34 | 000,113,664 | ---- | M] (Andrea Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AESTAud.sys -- (AESTAud)
DRV - [2009/03/31 23:11:44 | 000,039,424 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
DRV - [2008/04/13 20:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2007/11/06 23:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2790392
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit0.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "TVfree Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "TVfree Customized Web Search"
FF - prefs.js..extensions.enabledItems: [email protected]:11.0.1.400
FF - prefs.js..extensions.enabledItems: [email protected]:11.0.1.400
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:7.2.8
FF - prefs.js..extensions.enabledItems: {c66f6b8c-7cdb-437c-b9db-9a7a7d9cdd1b}:3.5.0.12
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@palmsource.com/installer,version=1.0: C:\PROGRA~1\Palm\PACKAG~1\NPInstal.dll ()
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.647: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Administrator\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/28 21:06:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/28 21:06:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla Firefox\components [2011/10/01 21:54:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010/09/21 06:37:27 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Documents and Settings\Administrator\Application Data\IDM\idmmzcc3 [2011/07/11 18:44:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Documents and Settings\Administrator\Application Data\IDM\idmmzcc3 [2011/07/11 18:44:56 | 000,000,000 | ---D | M]
[2011/07/11 18:47:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/10/26 23:43:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnismpp1.default\extensions
[2011/10/26 23:43:04 | 000,000,000 | ---D | M] (TVfree Community Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnismpp1.default\extensions\{c66f6b8c-7cdb-437c-b9db-9a7a7d9cdd1b}
[2011/06/19 12:16:08 | 000,000,915 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xnismpp1.default\searchplugins\conduit.xml
[2011/09/28 16:50:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/01/18 19:48:51 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/10/01 00:05:51 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/04 06:26:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/19 10:31:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/09/21 06:38:47 | 000,000,000 | ---D | M] (Anti-Banner) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2010/07/27 11:09:47 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2010/10/01 00:05:15 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2007/08/11 03:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit0.dll (Conduit Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\prxtbFre0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files\BitTorrentBar\prxtbBit0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AESTFltr] C:\WINDOWS\System32\AESTFltr.exe (Andrea Electronics Corporation)
O4 - HKLM..\Run: [autodetect] C:\Program Files\Safaricom Broadband\AutoDect.exe ()
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6B77C15E-2662-49C1-BA87-4398E0F21B5C}: NameServer = 41.220.238.4,196.201.231.167
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8541A0A8-C403-47D8-AC89-C34BB98AEEB7}: NameServer = 41.220.238.4,196.201.231.167
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) -C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) -C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Administrator\Application Data\rmhzb.exe) - File not found
O20 - Winlogon\Notify\klogon: DllName - (C:\WINDOWS\system32\klogon.dll) - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/17 22:06:29 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/07/11 10:08:38 | 000,000,058 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{0012232c-c051-11e0-9198-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0012232c-c051-11e0-9198-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0012232c-c051-11e0-9198-0025560dd663}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{01af4330-fbe5-11df-8fe3-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{01af4330-fbe5-11df-8fe3-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{01af4330-fbe5-11df-8fe3-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0625880c-9808-11df-8edf-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{0625880c-9808-11df-8edf-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0625880c-9808-11df-8edf-0025b3460cb0}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{0a89b12f-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b12f-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b12f-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b131-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b131-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b131-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b134-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b134-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b134-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b136-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b136-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b136-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b138-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b138-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b138-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b13a-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b13a-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b13a-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b13c-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b13c-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b13c-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b13e-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b13e-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b13e-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0a89b140-c3e1-11e0-91a2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{0a89b140-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0a89b140-c3e1-11e0-91a2-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{2c4aef3a-3e64-11e0-9068-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{2c4aef3a-3e64-11e0-9068-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2c4aef3a-3e64-11e0-9068-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{3b71612a-ac08-11df-8f1f-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{3b71612a-ac08-11df-8f1f-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3b71612a-ac08-11df-8f1f-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4dc3c0e4-3e51-11e0-9067-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{4dc3c0e4-3e51-11e0-9067-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4dc3c0e4-3e51-11e0-9067-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4dc3c0e8-3e51-11e0-9067-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{4dc3c0e8-3e51-11e0-9067-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4dc3c0e8-3e51-11e0-9067-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{57f64528-97a3-11df-8eda-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{57f64528-97a3-11df-8eda-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{57f64528-97a3-11df-8eda-0025b3460cb0}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{57f6452b-97a3-11df-8eda-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{57f6452b-97a3-11df-8eda-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{57f6452b-97a3-11df-8eda-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{5a45de9e-c329-11e0-91a1-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{5a45de9e-c329-11e0-91a1-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{5a45de9e-c329-11e0-91a1-0025560dd663}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{672d702c-f40d-11df-8fd0-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{672d702c-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{672d702c-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{672d7030-f40d-11df-8fd0-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{672d7030-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{672d7030-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{672d7031-f40d-11df-8fd0-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{672d7031-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{672d7031-f40d-11df-8fd0-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{76f4164e-6547-11e0-90e2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{76f4164e-6547-11e0-90e2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{76f4164e-6547-11e0-90e2-0025560dd663}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{76f4164f-6547-11e0-90e2-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{76f4164f-6547-11e0-90e2-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{76f4164f-6547-11e0-90e2-0025560dd663}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{85f7eaa6-01b7-11e0-8fef-0025b3460cb0}\Shell\AutoRun\command - "" = G:\PMBP_Win.exe
O33 - MountPoints2\{93440f45-7d21-11e0-911e-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{93440f45-7d21-11e0-911e-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{93440f45-7d21-11e0-911e-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{a7c013a6-c2c5-11e0-919f-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{a7c013a6-c2c5-11e0-919f-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a7c013a6-c2c5-11e0-919f-0025560dd663}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{a7c013a7-c2c5-11e0-919f-0025560dd663}\Shell - "" = AutoRun
O33 - MountPoints2\{a7c013a7-c2c5-11e0-919f-0025560dd663}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a7c013a7-c2c5-11e0-919f-0025560dd663}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{b268e88d-4ffc-11e0-90a3-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{b268e88d-4ffc-11e0-90a3-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b268e88d-4ffc-11e0-90a3-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{b9d639ea-9435-11df-8ece-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{b9d639ea-9435-11df-8ece-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9d639ea-9435-11df-8ece-0025b3460cb0}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{b9d639ec-9435-11df-8ece-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{b9d639ec-9435-11df-8ece-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b9d639ec-9435-11df-8ece-0025b3460cb0}\Shell\AutoRun\command - "" = D:\AutoRun.exe
O33 - MountPoints2\{d91a1714-a8e3-11df-8f14-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{d91a1714-a8e3-11df-8f14-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d91a1714-a8e3-11df-8f14-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{d91a1715-a8e3-11df-8f14-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{d91a1715-a8e3-11df-8f14-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{d91a1715-a8e3-11df-8f14-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{de14c693-b987-11df-8f4a-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{de14c693-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{de14c693-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{de14c694-b987-11df-8f4a-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{de14c694-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{de14c694-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{de14c697-b987-11df-8f4a-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{de14c697-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{de14c697-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{de14c698-b987-11df-8f4a-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{de14c698-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{de14c698-b987-11df-8f4a-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e75664ec-f888-11df-8fdd-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{e75664ec-f888-11df-8fdd-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e75664ec-f888-11df-8fdd-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{e75664ed-f888-11df-8fdd-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{e75664ed-f888-11df-8fdd-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e75664ed-f888-11df-8fdd-0025b3460cb0}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ee205164-8c9a-11e0-914c-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{ee205164-8c9a-11e0-914c-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ee205164-8c9a-11e0-914c-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f6383d38-3d87-11e0-9064-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{f6383d38-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6383d38-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f6383d39-3d87-11e0-9064-0025b3460cb0}\Shell\autoPlay\COmmAND - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d39-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d39-3d87-11e0-9064-0025b3460cb0}\Shell\expLOre\ComMAnd - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d39-3d87-11e0-9064-0025b3460cb0}\Shell\opeN\commaND - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d3b-3d87-11e0-9064-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{f6383d3b-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6383d3b-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{f6383d3c-3d87-11e0-9064-0025b3460cb0}\Shell\autoPlay\COmmAND - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d3c-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d3c-3d87-11e0-9064-0025b3460cb0}\Shell\expLOre\ComMAnd - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d3c-3d87-11e0-9064-0025b3460cb0}\Shell\opeN\commaND - "" = F:\xcqf.pif
O33 - MountPoints2\{f6383d40-3d87-11e0-9064-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{f6383d40-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6383d40-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{f6383d41-3d87-11e0-9064-0025b3460cb0}\Shell\autoPlay\COmmAND - "" = G:\xcqf.pif
O33 - MountPoints2\{f6383d41-3d87-11e0-9064-0025b3460cb0}\Shell\AutoRun\command - "" = G:\xcqf.pif
O33 - MountPoints2\{f6383d41-3d87-11e0-9064-0025b3460cb0}\Shell\expLOre\ComMAnd - "" = G:\xcqf.pif
O33 - MountPoints2\{f6383d41-3d87-11e0-9064-0025b3460cb0}\Shell\opeN\commaND - "" = G:\xcqf.pif
O33 - MountPoints2\{ff06477a-ac0a-11df-8f20-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{ff06477a-ac0a-11df-8f20-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff06477a-ac0a-11df-8f20-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{ff06477d-ac0a-11df-8f20-0025b3460cb0}\Shell - "" = AutoRun
O33 - MountPoints2\{ff06477d-ac0a-11df-8f20-0025b3460cb0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ff06477d-ac0a-11df-8f20-0025b3460cb0}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/30 21:00:15 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.scr
[2011/10/29 18:44:00 | 000,027,984 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\sbbd.exe
[2011/10/29 18:43:59 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2011/10/29 18:40:30 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2011/10/29 10:47:38 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2011/10/28 10:10:49 | 000,000,000 | ---D | C] -- C:\ubuntu
[2011/10/27 19:50:57 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/10/25 22:13:20 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2011/10/23 10:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook
[2011/10/09 21:36:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\ZTEEVDO
[2011/10/09 21:22:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ZTEMT UI
[2011/10/09 21:22:28 | 000,104,704 | ---- | C] (ZTEMT Incorporated) -- C:\WINDOWS\System32\drivers\CT_ZTEMT_U_USBSER.sys
[2011/10/09 21:22:20 | 000,000,000 | ---D | C] -- C:\Program Files\ZTEMT UI
[2011/10/07 05:32:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/10/06 23:17:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Interbank FX
[2011/10/06 21:28:29 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2011/10/02 11:58:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Debut
[2011/10/02 11:58:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Software
[2011/10/02 11:57:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Video Related Programs
[2011/10/02 11:57:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/10/02 11:56:57 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Software
[2011/10/02 11:56:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\NCH Software
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/30 23:35:50 | 000,748,748 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/10/30 23:35:50 | 000,252,006 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/10/30 23:30:56 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/30 23:30:11 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B104C796-8274-4204-92E1-E8EF1497D78A}.job
[2011/10/30 22:49:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500UA.job
[2011/10/30 22:47:41 | 000,001,010 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500UA.job
[2011/10/30 21:01:17 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.scr
[2011/10/30 10:48:47 | 000,001,008 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500Core.job
[2011/10/29 23:48:06 | 000,000,958 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500Core.job
[2011/10/29 18:48:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\SBRC.dat
[2011/10/29 11:59:51 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/10/28 16:14:39 | 000,134,978 | ---- | M] () -- C:\wubildr
[2011/10/28 16:14:14 | 000,000,238 | RHS- | M] () -- C:\boot.ini
[2011/10/28 16:12:48 | 000,008,192 | ---- | M] () -- C:\wubildr.mbr
[2011/10/27 19:51:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/10/24 19:03:27 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/10/22 00:11:04 | 000,001,882 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\fxTrade Practice.lnk
[2011/10/20 14:03:17 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/10/20 08:27:35 | 000,160,768 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/10 20:46:14 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\debutShakeIcon.job
[2011/10/09 21:23:19 | 000,000,659 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Internet Everywhere 3G+.lnk
[2011/10/02 11:57:12 | 000,000,775 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Debut Video Capture Software.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/29 18:48:23 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\SBRC.dat
[2011/10/28 16:12:48 | 000,008,192 | ---- | C] () -- C:\wubildr.mbr
[2011/10/28 16:12:47 | 000,134,978 | ---- | C] () -- C:\wubildr
[2011/10/25 23:22:32 | 000,000,861 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Express Burn Disc Burning Software.lnk
[2011/10/23 10:43:26 | 000,001,030 | ---- | C] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500UA.job
[2011/10/23 10:43:24 | 000,001,008 | ---- | C] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500Core.job
[2011/10/04 20:46:09 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\debutShakeIcon.job
[2011/10/02 11:57:12 | 000,000,775 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Debut Video Capture Software.lnk
[2011/10/02 11:57:08 | 000,000,781 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Debut Video Capture Software.lnk
[2011/09/21 15:19:13 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/09/08 23:10:00 | 000,000,088 | ---- | C] () -- C:\WINDOWS\Launcher.ini
[2011/07/23 09:28:39 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\$_hpcst$.hpc
[2010/12/23 22:48:16 | 000,153,600 | ---- | C] () -- C:\WINDOWS\System32\AI_ContextMenu.dll
[2010/12/23 17:36:09 | 000,000,034 | -H-- | C] () -- C:\WINDOWS\System32\Converter_sysquict.dat
[2010/09/21 06:38:29 | 000,115,369 | ---- | C] () -- C:\WINDOWS\System32\drivers\klin.dat
[2010/09/21 06:38:29 | 000,097,961 | ---- | C] () -- C:\WINDOWS\System32\drivers\klick.dat
[2010/09/07 21:46:16 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010/08/06 08:58:11 | 001,774,720 | ---- | C] () -- C:\WINDOWS\System32\BootMan.exe
[2010/08/06 08:58:11 | 000,086,408 | ---- | C] () -- C:\WINDOWS\System32\setupempdrv03.exe
[2010/08/06 08:58:11 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\EuEpmGdi.dll
[2010/08/06 08:58:11 | 000,013,192 | ---- | C] () -- C:\WINDOWS\System32\epmntdrv.sys
[2010/08/06 08:58:11 | 000,008,456 | ---- | C] () -- C:\WINDOWS\System32\EuGdiDrv.sys
[2010/07/29 21:13:40 | 000,160,768 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/27 08:36:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010/07/17 22:20:30 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2010/07/17 22:10:01 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010/07/17 22:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010/07/17 14:55:30 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/07/17 14:53:49 | 000,263,824 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/09/09 19:01:40 | 000,027,675 | ---- | C] () -- C:\WINDOWS\System32\drivers\klopp.dat
[2008/04/14 01:55:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2007/11/06 23:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2006/12/31 03:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 08:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 08:00:00 | 000,748,748 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 08:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 08:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 08:00:00 | 000,252,006 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 08:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 08:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 08:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 08:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 08:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/10/28 23:11:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\BitTorrent
[2011/10/30 20:19:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\DMCache
[2011/07/20 00:11:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\FXTS2
[2011/08/19 22:51:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\HotSync
[2011/10/22 20:02:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IDM
[2011/08/28 07:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\JetStart
[2011/10/21 11:46:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PriceGong
[2011/10/30 21:08:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\TeraCopy
[2011/10/09 22:27:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\ZTEEVDO
[2011/08/08 15:04:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2011/08/19 22:52:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2011/08/11 11:03:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Internet Everywhere 3G+
[2011/09/23 22:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/01/21 23:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/12/24 07:54:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\xml_param
[2011/10/10 20:46:14 | 000,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\debutShakeIcon.job
[2011/10/30 10:48:47 | 000,001,008 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500Core.job
[2011/10/30 22:49:01 | 000,001,030 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1935655697-2077806209-515967899-500UA.job
[2011/10/30 23:30:11 | 000,000,438 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{B104C796-8274-4204-92E1-E8EF1497D78A}.job
========== Purity Check ==========
< End of report >
OTL Extras logfile created on: 10/30/2011 11:31:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 798.83 Mb Available Physical Memory | 78.68% Memory free
2.38 Gb Paging File | 2.31 Gb Available in Paging File | 96.79% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 70.13 Gb Total Space | 23.35 Gb Free Space | 33.29% Space Free | Partition Type: NTFS
Drive D: | 78.91 Gb Total Space | 21.15 Gb Free Space | 26.81% Space Free | Partition Type: NTFS
Drive F: | 6.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: COMPUTER_1 | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
http [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1"
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Livestation\Livestation.exe" = C:\Program Files\Livestation\Livestation.exe:*:Enabled:Livestation
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application
"C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin -- (Google)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Documents and Settings\Administrator\My Documents\Downloads\BitTorrent-7.2.1(1).exe" = C:\Documents and Settings\Administrator\My Documents\Downloads\BitTorrent-7.2.1(1).exe:*:Enabled:BitTorrent
"D:\My Documents\Downloads\BitTorrent-7.2.1(1).exe" = D:\My Documents\Downloads\BitTorrent-7.2.1(1).exe:*:Enabled:BitTorrent -- (BitTorrent, Inc.)
"C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = C:\Documents and Settings\Administrator\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin -- (Skype Limited)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}" = HP USB Disk Storage Format Tool
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22FC7536-BE5C-4E88-8069-C24689D34EC5}" = Snagit 10.0.1
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java 6 Update 24
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = FXDD Malta - MetaTrader 4 4.00
"{3EAAC5FD-E209-4856-8C49-D4EA40F85032}" = Safaricom Mobile Office
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4C8B2F4D-9910-4381-B85A-789A7868E5A5}" = Money Manager
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{75D5B2BE-E76C-4C3C-93A7-1C1D74085295}" = IBFX Australia Trader 4 1.2
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{82705358-3BD6-3CD5-AA9A-B8F058BE3A29}" = Google Talk Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{93D34EE3-99B3-4DB1-8B0A-0A657466F90D}" = Safaricom Broadband
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.4.4 MUI
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{ED721ABC-423D-4F7D-AEBB-E1E39C388E84}" = Facebook Video Calling 1.0.0.8714
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"conduitEngine" = Conduit Engine
"Debut" = Debut Video Capture Software
"DirectFoldersAppID_is1" = Direct Folders
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 6.1.1 Home Edition
"ExpressFX" = ExpressFX
"FLVCodec" = PlayFLV
"FLVPlayer4Free Free FLV Player_is1" = FLVPlayer4Free Free FLV Player 3.8.0.0
"Foxit Reader" = Foxit Reader
"Free Convert to DIVX AVI WMV MP4 MPEG Converter_is1" = Free Convert to DIVX AVI WMV MP4 MPEG Converter 5.8
"Freecorder Toolbar" = Freecorder Toolbar
"Freecorder4.1" = Freecorder
"FXCM Micro Trading Station II" = FXCM Micro Trading Station II
"HaaliHaaliReaderCE" = Haali Reader CE 2.0 (remove only)
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie8" = Windows Internet Explorer 8
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"Interbank FX Trader 4" = Interbank FX Trader 4 Build 226
"Internet Download Manager" = Internet Download Manager
"Internet Everywhere 3G+" = Internet Everywhere 3G+
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.22)" = Mozilla Firefox (3.6.22)
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"OpenAL" = OpenAL
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"Safaricom Broadband" = Safaricom Broadband
"Streamster" = Marketiva
"TeraCopy_is1" = TeraCopy 2.12
"UninstEGWhite" = White Estate Software
"VLC media player" = VLC media player 1.1.11
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WinPcapInst" = WinPcap 4.0.2
"WinRAR archiver" = WinRAR archiver
"WordWeb" = WordWeb
"Wubi" = Ubuntu
"Zain e-GO" = Zain e-GO
"ZTEWireless-101_is1" = ZTEMT UI
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Autochartist" = IBFX - PRS 3.3.4
"fxTrade Practice" = fxTrade Practice
"GoToMeeting" = GoToMeeting 4.8.0.723
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/15/2011 9:47:18 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is incorrectly
formatted.
The bogus string is 6730, the bogus index value is the first DWORD in Data section
while the last valid index values are the second and third DWORD in Data section.
Error - 6/15/2011 5:55:03 PM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application mpc-hc.exe, version 1.3.1249.0, faulting module
qdvd.dll, version 6.5.2600.5512, fault address 0x000189ad.
Error - 6/15/2011 6:11:14 PM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application mpc-hc.exe, version 1.3.1249.0, faulting module
qdvd.dll, version 6.5.2600.5512, fault address 0x000189ad.
Error - 6/20/2011 3:33:41 PM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/20/2011 3:33:41 PM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
Error - 6/21/2011 1:10:13 AM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application idman.exe, version 5.19.2.1, faulting module
idman.exe, version 5.19.2.1, fault address 0x00177db9.
Error - 6/21/2011 1:14:26 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/21/2011 1:14:26 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
Error - 6/21/2011 5:09:59 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/21/2011 5:09:59 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
[ Application Events ]
Error - 6/15/2011 9:47:18 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is incorrectly
formatted.
The bogus string is 6730, the bogus index value is the first DWORD in Data section
while the last valid index values are the second and third DWORD in Data section.
Error - 6/15/2011 5:55:03 PM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application mpc-hc.exe, version 1.3.1249.0, faulting module
qdvd.dll, version 6.5.2600.5512, fault address 0x000189ad.
Error - 6/15/2011 6:11:14 PM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application mpc-hc.exe, version 1.3.1249.0, faulting module
qdvd.dll, version 6.5.2600.5512, fault address 0x000189ad.
Error - 6/20/2011 3:33:41 PM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/20/2011 3:33:41 PM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
Error - 6/21/2011 1:10:13 AM | Computer Name = COMPUTER_1 | Source = Application Error | ID = 1000
Description = Faulting application idman.exe, version 5.19.2.1, faulting module
idman.exe, version 5.19.2.1, fault address 0x00177db9.
Error - 6/21/2011 1:14:26 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/21/2011 1:14:26 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
Error - 6/21/2011 5:09:59 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3012
Description = The performance strings in the Performance registry value is corrupted
when process Performance extension counter provider. BaseIndex value from Performance
registry
is the first DWORD in Data section, LastCounter value is the second DWORD in Data
section, and LastHelp value is the third DWORD in Data section.
Error - 6/21/2011 5:09:59 AM | Computer Name = COMPUTER_1 | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service WmiApRpl (WmiApRpl)
failed. The Error code is the first DWORD in Data section.
[ OSession Events ]
Error - 8/6/2010 3:10:42 AM | Computer Name = COMPUTER_1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20866
seconds with 60 seconds of active time. This session ended with a crash.
Error - 11/10/2010 4:03:38 PM | Computer Name = COMPUTER_1 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6942
seconds with 60 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 10/30/2011 1:21:50 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7022
Description = The Windows Image Acquisition (WIA) service hung on starting.
Error - 10/30/2011 1:23:15 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Application Layer Gateway
Service service to connect.
Error - 10/30/2011 1:23:15 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053
Error - 10/30/2011 2:01:54 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the UDisk Monitor service.
Error - 10/30/2011 2:58:48 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the HWDeviceService.exe service.
Error - 10/30/2011 3:17:19 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the HWDeviceService.exe service.
Error - 10/30/2011 3:17:53 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the HWDeviceService.exe service.
Error - 10/30/2011 3:18:23 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the HWDeviceService.exe service.
Error - 10/30/2011 4:31:22 PM | Computer Name = COMPUTER_1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 10/30/2011 4:32:45 PM | Computer Name = COMPUTER_1 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Fips intelppm KLIF
< End of report >
I look forward for your assistance.
Edited by polepole, 30 October 2011 - 02:53 PM.