Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Randomly slow internet, buzzing speakers


  • Please log in to reply

#1
Justinn123

Justinn123

    Member

  • Member
  • PipPip
  • 30 posts
Hi. As you most likely know, I'm posting because I'm having a problem. I think my computer has a very bad virus. My computer boots up slower than usual (I think), my internet is really random, it sometimes goes nice and smoothly and runs fast, at other times, the internet is downright slow and Google takes forever to load and the Google links take a while to open up and also, Windows 7 action centre says my internet security isn't running and when I try opening up the Internet Security GUI, it says it has to be updated (PC Tools internet security)and I click update and it says its already updating in the background :) . When I run Gmer to create the log you told me to create and post, it crashes and gives error code, and then when I run it again, computer hangs for a moment or so, then blue screens and reboots. So I did system restore, didn't help, internet is still randomly slow, get random buzzing and slow-ish boot up. I didn't try Gmer in case it blue screened me again. :) I desperately need some help, so if the Geekstogo team could help me, I would appreciate it so much. :)
Well, here are my logs:

Malwarebytes' Anti-Malware 1.44
Database version: 3830
Windows 6.1.7600
Internet Explorer 8.0.7600.16385

7/03/2010 2:23:04 PM
mbam-log-2010-03-07 (14-23-04).txt

Scan type: Quick Scan
Objects scanned: 105596
Time elapsed: 5 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



OTL logfile created on: 8/03/2010 6:11:19 PM - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Users\Justin\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 454.46 Gb Total Space | 317.17 Gb Free Space | 69.79% Space Free | Partition Type: NTFS
Drive D: | 11.30 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JN
Current User Name: Justin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/08 11:12:09 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Justin\Desktop\OTL.exe
PRC - [2010/01/22 10:16:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\PC Tools Internet Security\BDT\BDTUpdateService.exe
PRC - [2010/01/16 14:09:37 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/11 21:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/11/18 12:47:38 | 001,243,112 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\pctsTray.exe
PRC - [2009/11/12 10:03:32 | 000,070,928 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\TFEngine\TFService.exe
PRC - [2009/11/06 15:50:58 | 001,141,736 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\pctsSvc.exe
PRC - [2009/10/31 16:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\pctsAuxs.exe
PRC - [2009/07/14 12:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/14 12:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sppsvc.exe
PRC - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/03/30 16:28:36 | 000,183,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2008/06/10 18:04:58 | 000,689,456 | ---- | M] (Hewlett-Packard) -- C:\Program Files\HP\HP Software Update\HPWUCli.exe


========== Modules (SafeList) ==========

MOD - [2010/03/08 11:12:09 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Justin\Desktop\OTL.exe
MOD - [2009/12/08 13:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2009/11/12 10:03:32 | 000,451,856 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\TFEngine\TFWAH.dll
MOD - [2009/07/14 12:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/14 12:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/14 12:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/14 12:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/14 12:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/14 12:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/14 12:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/14 12:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/14 12:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/14 12:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/14 12:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/02/27 17:46:02 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/01/22 10:16:02 | 000,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\PC Tools Internet Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2010/01/11 21:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/11/12 10:03:32 | 000,070,928 | ---- | M] (PC Tools) [On_Demand | Running] -- C:\Program Files\PC Tools Internet Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2009/11/06 15:50:58 | 001,141,736 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Internet Security\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\PC Tools Internet Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/07/14 12:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/14 12:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/14 12:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/14 12:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/14 12:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/14 12:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/14 12:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 12:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/14 12:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/14 12:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/14 12:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/14 12:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 12:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/14 12:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/14 12:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/14 12:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/14 12:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/14 12:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2009/07/14 12:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/14 12:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2009/03/30 16:28:36 | 001,533,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C8 4D DB DE 86 B7 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:1.5.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: [email protected]:7.6.1
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.6
FF - prefs.js..extensions.enabledItems: [email protected]:4.51
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:2.3.1
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028

FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/02/27 20:59:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/03/01 16:56:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/27 19:29:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/28 11:08:15 | 000,000,000 | ---D | M]

[2010/02/27 19:29:38 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Mozilla\Extensions
[2010/03/01 18:28:51 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions
[2010/02/27 22:04:36 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2010/02/27 22:07:57 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/02/27 19:35:21 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/02/27 20:08:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/02/27 19:35:21 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\[email protected]
[2010/02/27 19:32:44 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Mozilla\Firefox\Profiles\5tmonydp.default\extensions\[email protected]
[2010/02/27 19:56:28 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/11 08:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Internet Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Internet Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Internet Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Internet Security\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [KBD] C:\Program Files\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - Startup: C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\update.exe (TWX Corp.)
O4 - Startup: C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 211.29.152.116 192.168.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 08:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{254f053b-2366-11df-a959-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{254f053b-2366-11df-a959-806e6f6e6963}\Shell\AutoRun\command - "" = E:\SETUP.EXE -- File not found
O33 - MountPoints2\{254f053b-2366-11df-a959-806e6f6e6963}\Shell\configure\command - "" = E:\SETUP.EXE -- File not found
O33 - MountPoints2\{254f053b-2366-11df-a959-806e6f6e6963}\Shell\install\command - "" = E:\SETUP.EXE -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/07/14 13:37:08 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

========== Files/Folders - Created Within 14 Days ==========

[2010/03/08 18:09:39 | 000,554,496 | ---- | C] (OldTimer Tools) -- C:\Users\Justin\Desktop\OTL.exe
[2010/03/08 17:53:20 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/03/07 14:04:46 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Malwarebytes
[2010/03/07 14:04:40 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/07 14:04:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/03/06 16:58:24 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/03/06 16:08:50 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2010/03/02 19:51:44 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\vlc
[2010/03/02 17:58:32 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\HP
[2010/03/02 17:30:03 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Adobe
[2010/03/02 17:29:15 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Adobe
[2010/03/01 20:10:46 | 000,000,000 | ---D | C] -- C:\Users\Justin\Desktop\_system_
[2010/03/01 20:09:55 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\WinRAR
[2010/03/01 19:04:58 | 000,000,000 | R--D | C] -- C:\Users\Justin\AppData\Roaming\Brother
[2010/02/28 14:03:25 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\DataCast
[2010/02/28 14:03:19 | 000,000,000 | ---D | C] -- C:\Program Files\MarkAny
[2010/02/28 14:03:06 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2010/02/28 13:36:47 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\NCH Software
[2010/02/28 12:48:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Office Genuine Advantage
[2010/02/28 12:39:24 | 000,000,000 | ---D | C] -- C:\Users\Justin\Documents\Backup
[2010/02/28 12:05:05 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010/02/28 11:28:17 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/02/28 11:08:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010/02/28 11:07:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/02/28 11:07:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/02/28 11:05:58 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Microsoft Help
[2010/02/28 11:05:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010/02/28 11:05:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2010/02/28 10:52:07 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\CyberLink
[2010/02/28 10:51:01 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Swift Sound
[2010/02/28 10:50:58 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\NCH Swift Sound
[2010/02/28 10:50:58 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Swift Sound
[2010/02/27 22:04:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/02/27 22:03:59 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010/02/27 22:03:59 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2010/02/27 22:02:47 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\GlarySoft
[2010/02/27 22:02:47 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Registry Repair
[2010/02/27 21:57:07 | 000,000,000 | ---D | C] -- C:\Users\Justin\Documents\Xilisoft Corporation
[2010/02/27 21:57:05 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Xilisoft Corporation
[2010/02/27 21:41:47 | 000,000,000 | R-SD | C] -- C:\Users\Justin\Documents\My Stationery
[2010/02/27 21:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\Xilisoft
[2010/02/27 21:22:24 | 000,000,000 | ---D | C] -- C:\Users\Justin\Tracing
[2010/02/27 21:22:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2010/02/27 21:21:16 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2010/02/27 21:21:06 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010/02/27 21:20:58 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010/02/27 21:20:41 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2010/02/27 21:20:21 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/02/27 21:19:07 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2010/02/27 21:17:29 | 000,000,000 | ---D | C] -- C:\Program Files\FreeMind
[2010/02/27 21:13:29 | 000,111,928 | ---- | C] (Brother Industries Ltd) -- C:\Windows\System32\BRRBTOOL.EXE
[2010/02/27 21:13:29 | 000,077,824 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\System32\brlmw03a.dll
[2010/02/27 21:13:29 | 000,024,223 | ---- | C] (Brother Industries, Ltd) -- C:\Windows\System32\brlm03a.dll
[2010/02/27 21:13:27 | 000,176,128 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\System32\BROSNMP.DLL
[2010/02/27 21:13:27 | 000,000,000 | ---D | C] -- C:\Program Files\Brownie
[2010/02/27 21:12:00 | 000,196,608 | ---- | C] (brother) -- C:\Windows\System32\Pdrvinst.dll
[2010/02/27 21:12:00 | 000,000,000 | ---D | C] -- C:\Program Files\Brother
[2010/02/27 21:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/02/27 21:10:50 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2010/02/27 21:09:47 | 000,000,000 | ---D | C] -- C:\Users\Justin\Documents\Printer Driver
[2010/02/27 21:08:36 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/02/27 21:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\WEBREG
[2010/02/27 21:01:25 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\HP
[2010/02/27 20:58:17 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2010/02/27 20:56:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2010/02/27 20:25:36 | 000,000,000 | ---D | C] -- C:\Users\Justin\Documents\ImTOO Software Studio
[2010/02/27 20:25:33 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\ImTOO Software Studio
[2010/02/27 20:17:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2010/02/27 20:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2010/02/27 20:13:16 | 000,000,000 | ---D | C] -- C:\Program Files\ImTOO
[2010/02/27 20:12:27 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2010/02/27 20:02:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010/02/27 20:02:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/02/27 20:02:36 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/02/27 19:58:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/02/27 19:58:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/02/27 19:55:47 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010/02/27 19:51:41 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Hewlett-Packard
[2010/02/27 19:46:07 | 000,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
[2010/02/27 19:41:33 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2010/02/27 19:39:25 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\WinBatch
[2010/02/27 19:37:11 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\IObit
[2010/02/27 19:37:11 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/02/27 19:36:42 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2010/02/27 19:36:03 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Macromedia
[2010/02/27 19:35:57 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010/02/27 19:29:31 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Mozilla
[2010/02/27 19:29:31 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Mozilla
[2010/02/27 19:29:23 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/02/27 18:25:35 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\PCToolsFirewallPlus
[2010/02/27 18:25:32 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Spam Monitor
[2010/02/27 18:23:02 | 001,652,688 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2010/02/27 18:23:02 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2010/02/27 18:23:01 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2010/02/27 18:22:39 | 000,207,792 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2010/02/27 18:22:39 | 000,087,784 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/02/27 18:22:37 | 000,233,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2010/02/27 18:22:37 | 000,098,600 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/02/27 18:21:50 | 000,059,664 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys
[2010/02/27 18:21:50 | 000,051,984 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys
[2010/02/27 18:21:50 | 000,033,552 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys
[2010/02/27 18:21:48 | 000,115,216 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplfw.sys
[2010/02/27 18:21:48 | 000,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2010/02/27 18:21:48 | 000,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2010/02/27 18:21:48 | 000,055,208 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis.sys
[2010/02/27 18:21:48 | 000,032,552 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-DNS.sys
[2010/02/27 18:21:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/02/27 18:21:45 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Internet Security
[2010/02/27 18:21:45 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\PC Tools
[2010/02/27 18:21:45 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/02/27 18:21:23 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/02/27 18:20:31 | 000,019,968 | ---- | C] (TWX Corp.) -- C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\update.exe
[2010/02/27 18:00:33 | 000,000,000 | ---D | C] -- C:\Users\Justin\Games
[2010/02/27 17:58:10 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2010/02/27 17:47:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2010/02/27 17:47:40 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2010/02/27 17:46:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2010/02/27 17:43:10 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010/02/27 17:37:08 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010/02/27 17:26:45 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\ElevatedDiagnostics
[2010/02/27 17:25:16 | 000,000,000 | R--D | C] -- C:\Users\Justin\Searches
[2010/02/27 17:25:05 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Identities
[2010/02/27 17:25:04 | 000,000,000 | R--D | C] -- C:\Users\Justin\Contacts
[2010/02/27 17:24:58 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\VirtualStore
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\AppData\Local\Temporary Internet Files
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Templates
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Start Menu
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\SendTo
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Recent
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\PrintHood
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\NetHood
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Documents\My Videos
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Documents\My Pictures
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Documents\My Music
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\My Documents
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Local Settings
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\AppData\Local\History
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Cookies
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\Application Data
[2010/02/27 17:24:55 | 000,000,000 | -HSD | C] -- C:\Users\Justin\AppData\Local\Application Data
[2010/02/27 17:24:54 | 000,000,000 | --SD | C] -- C:\Users\Justin\AppData\Roaming\Microsoft
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Videos
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Saved Games
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Pictures
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Music
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Links
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Favorites
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Downloads
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Documents
[2010/02/27 17:24:54 | 000,000,000 | R--D | C] -- C:\Users\Justin\Desktop
[2010/02/27 17:24:54 | 000,000,000 | -H-D | C] -- C:\Users\Justin\AppData
[2010/02/27 17:24:54 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Temp
[2010/02/27 17:24:54 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Local\Microsoft
[2010/02/27 17:24:54 | 000,000,000 | ---D | C] -- C:\Users\Justin\AppData\Roaming\Media Center Programs
[2010/02/27 17:09:20 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/02/27 17:06:08 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010/02/24 19:38:52 | 000,421,888 | ---- | C] (Gabest) -- C:\Windows\System32\RealMediaSplitter.ax
[2010/02/24 19:38:52 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll
[2010/02/23 19:08:35 | 000,068,200 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2010/02/23 19:08:32 | 000,000,000 | ---D | C] -- C:\NVIDIA

========== Files - Modified Within 14 Days ==========

[2010/03/08 18:15:31 | 003,407,872 | -HS- | M] () -- C:\Users\Justin\ntuser.dat
[2010/03/08 18:12:39 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/08 18:12:38 | 000,014,608 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/08 18:08:19 | 000,000,222 | ---- | M] () -- C:\Windows\Brownie.ini
[2010/03/08 18:05:07 | 000,524,288 | -HS- | M] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TMContainer00000000000000000002.regtrans-ms
[2010/03/08 18:05:07 | 000,524,288 | -HS- | M] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TMContainer00000000000000000001.regtrans-ms
[2010/03/08 18:05:07 | 000,065,536 | -HS- | M] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TM.blf
[2010/03/08 18:05:04 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/08 18:04:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/08 18:04:53 | 2615,812,096 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/08 17:59:40 | 000,000,000 | -H-- | M] () -- C:\Users\Justin\AppData\Local\IconCache.db
[2010/03/08 11:12:09 | 000,554,496 | ---- | M] (OldTimer Tools) -- C:\Users\Justin\Desktop\OTL.exe
[2010/03/02 17:23:36 | 000,713,888 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/03/02 17:23:36 | 000,619,206 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/03/02 17:23:36 | 000,107,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/03/01 19:06:28 | 000,000,426 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2010/03/01 18:12:27 | 000,309,216 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/03/01 17:14:15 | 000,068,240 | ---- | M] () -- C:\Users\Justin\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/28 14:10:14 | 000,002,172 | ---- | M] () -- C:\Users\Justin\Desktop\Windows Live Mail.lnk
[2010/02/28 14:04:01 | 000,001,942 | ---- | M] () -- C:\Users\Public\Desktop\EmoDio.lnk
[2010/02/28 13:18:19 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/02/28 12:04:53 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/02/28 11:12:12 | 000,002,080 | ---- | M] () -- C:\Users\Justin\Desktop\Windows Live Messenger .lnk
[2010/02/28 11:11:58 | 000,002,645 | ---- | M] () -- C:\Users\Justin\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/02/28 11:11:48 | 000,002,693 | ---- | M] () -- C:\Users\Justin\Desktop\Microsoft Office Word 2007.lnk
[2010/02/28 11:01:56 | 000,005,847 | ---- | M] () -- C:\Users\Justin\Desktop\Photoshop CS4 - Extended.lnk
[2010/02/28 10:51:00 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/02/27 22:02:48 | 000,000,145 | ---- | M] () -- C:\Users\Justin\Desktop\Glary Utilities Freeware.url
[2010/02/27 21:23:24 | 000,002,126 | ---- | M] () -- C:\Users\Justin\Desktop\Xilisoft Video Converter Ultimate.lnk
[2010/02/27 21:17:30 | 000,001,833 | ---- | M] () -- C:\Users\Justin\Desktop\FreeMind.lnk
[2010/02/27 21:13:30 | 000,000,000 | ---- | M] () -- C:\Windows\brmx2001.ini
[2010/02/27 21:13:29 | 000,009,030 | ---- | M] () -- C:\Windows\HL-2040.INI
[2010/02/27 21:13:29 | 000,000,145 | ---- | M] () -- C:\Windows\BRVIDEO.INI
[2010/02/27 21:13:29 | 000,000,054 | ---- | M] () -- C:\Windows\System32\bd2040.dat
[2010/02/27 21:11:18 | 000,001,026 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/02/27 21:01:19 | 000,221,116 | ---- | M] () -- C:\Windows\hpoins19.dat
[2010/02/27 21:00:48 | 000,000,438 | ---- | M] () -- C:\Windows\win.ini
[2010/02/27 20:58:12 | 000,001,275 | ---- | M] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/02/27 20:57:32 | 000,002,071 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/02/27 20:35:11 | 000,003,981 | ---- | M] () -- C:\Users\Justin\Desktop\NFSU2.lnk
[2010/02/27 20:34:12 | 000,004,051 | ---- | M] () -- C:\Users\Justin\Desktop\Call of Duty Modern Warfare 2 Mobilized.lnk
[2010/02/27 20:33:26 | 000,002,349 | ---- | M] () -- C:\Users\Justin\Desktop\Call of Duty 4 - Modern Warfare.lnk
[2010/02/27 20:13:46 | 000,001,996 | ---- | M] () -- C:\Users\Justin\Desktop\ImTOO DPG Converter.lnk
[2010/02/27 20:02:43 | 000,001,986 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/02/27 19:36:42 | 000,001,224 | ---- | M] () -- C:\Users\Justin\Desktop\Revo Uninstaller.lnk
[2010/02/27 19:29:33 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2010/02/27 19:29:27 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/02/27 18:21:51 | 000,002,054 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2010/02/27 18:20:48 | 002,762,231 | ---- | M] () -- C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.exe
[2010/02/27 18:20:36 | 000,019,968 | ---- | M] (TWX Corp.) -- C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\update.exe
[2010/02/27 17:55:19 | 000,020,476 | ---- | M] () -- C:\Users\Justin\AppData\Roaming\UserTile.png
[2010/02/27 17:40:34 | 000,524,288 | -HS- | M] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/02/27 17:40:34 | 000,524,288 | -HS- | M] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/02/27 17:40:34 | 000,065,536 | -HS- | M] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/02/27 17:24:55 | 000,000,020 | -HS- | M] () -- C:\Users\Justin\ntuser.ini
[2010/02/27 17:11:27 | 000,041,962 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010/02/27 17:09:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/02/24 19:38:52 | 000,421,888 | ---- | M] (Gabest) -- C:\Windows\System32\RealMediaSplitter.ax
[2010/02/24 19:38:52 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\Windows\System32\pncrt.dll

========== Files Created - No Company Name ==========

[2010/03/08 18:05:07 | 000,524,288 | -HS- | C] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TMContainer00000000000000000002.regtrans-ms
[2010/03/08 18:05:07 | 000,524,288 | -HS- | C] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TMContainer00000000000000000001.regtrans-ms
[2010/03/08 18:05:07 | 000,065,536 | -HS- | C] () -- C:\Users\Justin\ntuser.dat{c5eba4f9-2a7f-11df-af49-002421a2209a}.TM.blf
[2010/03/08 17:41:05 | 000,284,915 | ---- | C] () -- C:\Users\Justin\Desktop\gmer.zip
[2010/03/01 20:11:32 | 001,410,048 | ---- | C] () -- C:\Users\Justin\Desktop\_DS_MENU.DAT
[2010/02/28 14:10:14 | 000,002,172 | ---- | C] () -- C:\Users\Justin\Desktop\Windows Live Mail.lnk
[2010/02/28 14:03:58 | 000,001,942 | ---- | C] () -- C:\Users\Public\Desktop\EmoDio.lnk
[2010/02/28 13:18:19 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/02/28 11:12:12 | 000,002,080 | ---- | C] () -- C:\Users\Justin\Desktop\Windows Live Messenger .lnk
[2010/02/28 11:11:58 | 000,002,645 | ---- | C] () -- C:\Users\Justin\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/02/28 11:11:48 | 000,002,693 | ---- | C] () -- C:\Users\Justin\Desktop\Microsoft Office Word 2007.lnk
[2010/02/28 11:01:56 | 000,005,847 | ---- | C] () -- C:\Users\Justin\Desktop\Photoshop CS4 - Extended.lnk
[2010/02/28 10:51:00 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/02/27 22:02:48 | 000,000,145 | ---- | C] () -- C:\Users\Justin\Desktop\Glary Utilities Freeware.url
[2010/02/27 21:23:24 | 000,002,126 | ---- | C] () -- C:\Users\Justin\Desktop\Xilisoft Video Converter Ultimate.lnk
[2010/02/27 21:17:30 | 000,001,833 | ---- | C] () -- C:\Users\Justin\Desktop\FreeMind.lnk
[2010/02/27 21:13:30 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2010/02/27 21:13:29 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2010/02/27 21:13:29 | 000,000,145 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2010/02/27 21:13:29 | 000,000,114 | ---- | C] () -- C:\Windows\System32\brlmw03a.ini
[2010/02/27 21:13:27 | 000,009,030 | ---- | C] () -- C:\Windows\HL-2040.INI
[2010/02/27 21:12:00 | 000,000,054 | ---- | C] () -- C:\Windows\System32\bd2040.dat
[2010/02/27 21:11:49 | 000,000,222 | ---- | C] () -- C:\Windows\Brownie.ini
[2010/02/27 21:11:18 | 000,001,026 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/02/27 20:58:12 | 000,001,275 | ---- | C] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/02/27 20:57:32 | 000,002,071 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/02/27 20:53:07 | 000,221,116 | ---- | C] () -- C:\Windows\hpoins19.dat
[2010/02/27 20:53:07 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2010/02/27 20:35:11 | 000,003,981 | ---- | C] () -- C:\Users\Justin\Desktop\NFSU2.lnk
[2010/02/27 20:34:12 | 000,004,051 | ---- | C] () -- C:\Users\Justin\Desktop\Call of Duty Modern Warfare 2 Mobilized.lnk
[2010/02/27 20:32:59 | 000,002,349 | ---- | C] () -- C:\Users\Justin\Desktop\Call of Duty 4 - Modern Warfare.lnk
[2010/02/27 20:13:46 | 000,001,996 | ---- | C] () -- C:\Users\Justin\Desktop\ImTOO DPG Converter.lnk
[2010/02/27 20:13:16 | 000,004,358 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010/02/27 20:02:43 | 000,001,986 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/02/27 19:36:42 | 000,001,224 | ---- | C] () -- C:\Users\Justin\Desktop\Revo Uninstaller.lnk
[2010/02/27 19:29:33 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/02/27 19:29:27 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/02/27 18:23:02 | 001,152,444 | ---- | C] () -- C:\Windows\UDB.zip
[2010/02/27 18:23:02 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll.old
[2010/02/27 18:23:02 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2010/02/27 18:23:02 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2010/02/27 18:23:02 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2010/02/27 18:23:02 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2010/02/27 18:22:39 | 000,007,412 | ---- | C] () -- C:\Windows\System32\drivers\PCTAppEvent.cat
[2010/02/27 18:22:39 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctcore.cat
[2010/02/27 18:22:37 | 000,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2010/02/27 18:21:51 | 000,002,054 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2010/02/27 18:21:48 | 000,007,435 | ---- | C] () -- C:\Windows\System32\drivers\pctNdis-PacketFilter.cat
[2010/02/27 18:21:48 | 000,007,399 | ---- | C] () -- C:\Windows\System32\drivers\pctNdis-DNS.cat
[2010/02/27 18:21:48 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2010/02/27 18:21:48 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplfw.cat
[2010/02/27 18:20:36 | 002,762,231 | ---- | C] () -- C:\Users\Justin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updater.exe
[2010/02/27 17:55:18 | 000,020,476 | ---- | C] () -- C:\Users\Justin\AppData\Roaming\UserTile.png
[2010/02/27 17:24:55 | 000,000,020 | -HS- | C] () -- C:\Users\Justin\ntuser.ini
[2010/02/27 17:24:54 | 003,407,872 | -HS- | C] () -- C:\Users\Justin\ntuser.dat
[2010/02/27 17:24:54 | 000,524,288 | -HS- | C] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/02/27 17:24:54 | 000,524,288 | -HS- | C] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/02/27 17:24:54 | 000,065,536 | -HS- | C] () -- C:\Users\Justin\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/02/27 17:09:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/02/27 16:07:56 | 2615,812,096 | -HS- | C] () -- C:\hiberfil.sys
[2010/02/23 19:08:35 | 000,007,437 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/14 10:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 10:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2008/09/17 12:36:22 | 000,921,600 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll
[2008/09/17 12:36:20 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2008/09/17 12:36:20 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2008/09/17 12:36:20 | 000,045,056 | ---- | C] () -- C:\Windows\System32\Ogg.dll

========== LOP Check ==========

[2010/02/28 14:03:25 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\DataCast
[2010/02/27 22:02:47 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\GlarySoft
[2010/02/27 20:25:33 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\ImTOO Software Studio
[2010/03/08 18:03:11 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\IObit
[2010/02/28 10:50:58 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\NCH Swift Sound
[2010/02/27 18:25:38 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\PCToolsFirewallPlus
[2010/02/27 18:25:32 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Spam Monitor
[2010/02/27 19:39:25 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\WinBatch
[2010/02/27 21:57:05 | 000,000,000 | ---D | M] -- C:\Users\Justin\AppData\Roaming\Xilisoft Corporation
[2009/07/14 15:53:46 | 000,004,646 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2009/07/14 12:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\drivers\AGP440.sys
[2009/07/14 12:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_x86_neutral_65848c2d7375a720\AGP440.sys
[2009/07/14 12:26:15 | 000,053,312 | ---- | M] (Microsoft Corporation) MD5=507812C3054C21CEF746B6EE3D04DD6E -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_b9e9435f20046eeb\AGP440.sys

< MD5 for: ATAPI.SYS >
[2009/07/14 12:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 12:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/14 12:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2009/07/14 12:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\System32\cngaudit.dll
[2009/07/14 12:15:06 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2009/07/14 12:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\drivers\iaStorV.sys
[2009/07/14 12:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_x86_neutral_18cccb83b34e1453\iaStorV.sys
[2009/07/14 12:20:36 | 000,332,352 | ---- | M] (Intel Corporation) MD5=934AF4D7C5F457B9F0743F4299B77B67 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_aee7a89be91b9000\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2009/07/14 12:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\System32\netlogon.dll
[2009/07/14 12:16:02 | 000,563,712 | ---- | M] (Microsoft Corporation) MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_fd8e0d66994d7dc8\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2009/07/14 12:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\drivers\nvstor.sys
[2009/07/14 12:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_x86_neutral_5bde3fe2945bce9e\nvstor.sys
[2009/07/14 12:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) MD5=C99F251A5DE63C6F129CF71933ACED0F -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_39b1194b205239d8\nvstor.sys

< MD5 for: SCECLI.DLL >
[2009/07/14 12:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\System32\scecli.dll
[2009/07/14 12:16:13 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=26073302DAEA83CC5B944C546D6B47D2 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_37e4387f3a6f0483\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

========== Alternate Data Streams ==========

@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:5160F090

< End of report >


OTL Extras logfile created on: 8/03/2010 6:11:20 PM - Run 1
OTL by OldTimer - Version 3.1.35.0 Folder = C:\Users\Justin\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 454.46 Gb Total Space | 317.17 Gb Free Space | 69.79% Space Free | Partition Type: NTFS
Drive D: | 11.30 Gb Total Space | 1.59 Gb Free Space | 14.08% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JN
Current User Name: Justin
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03BF5CB1-B72E-4CA6-A278-F65680F05420}" = HP Picasso Media Center Add-In
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{104066F4-5897-4067-85D3-4C88B67CCF75}" = AIO_Scan
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{2E87F4AB-99BF-421C-AF7B-365A9C08549A}" = F300
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{59D6633C-B05D-4084-B5E7-1FD33EF11278}" = Brother HL-2040
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9F6B13E2-B93F-4203-9BD4-5DC18C9F9DEB}" = AIO_CDB_Software
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B61ED343-0B14-4241-999C-490CB1A20DA4}" = HP Photosmart Officejet and Deskjet All-In-One Driver Software 13.0 Rel. B
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C19BE821-89B1-4A96-AC7C-873810C0CB5F}" = ContentSAFER for Wizmax
"{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"Browser Defender_is1" = Browser Defender 2.0.6.15
"Glary Registry Repair_is1" = Glary Registry Repair 3.3.0.852
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"ImTOO DPG Converter" = ImTOO DPG Converter
"InstallShield_{C20CE592-B0F8-4D20-BF31-0151CA6331A6}" = EmoDio
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PC Tools Internet Security" = PC Tools Internet Security 2010
"Revo Uninstaller" = Revo Uninstaller 1.85
"Switch" = Switch Sound File Converter
"VLC media player" = VLC media player 1.0.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/03/2010 2:11:32 AM | Computer Name = JN | Source = Windows Search Service | ID = 3007
Description =

Error - 1/03/2010 2:12:11 AM | Computer Name = JN | Source = Windows Search Service | ID = 3007
Description =

Error - 1/03/2010 4:28:41 AM | Computer Name = JN | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\pc tools
internet security\networklayer\PCTCFFix64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 2/03/2010 4:04:51 AM | Computer Name = JN | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\pc tools
internet security\networklayer\PCTCFFix64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 2/03/2010 4:51:08 AM | Computer Name = JN | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7600.16385 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: df4 Start
Time: 01cab9e5795a30b6 Termination Time: 10 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id: bc892a79-25d8-11df-8226-002421a2209a

Error - 3/03/2010 4:21:18 AM | Computer Name = JN | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\pc tools
internet security\networklayer\PCTCFFix64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/03/2010 3:11:56 AM | Computer Name = JN | Source = Application Hang | ID = 1002
Description = The program Update.exe version 7.0.0.67 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: c70 Start Time:
01cabcfc132e5b5d Termination Time: 60000 Application Path: C:\Program Files\PC Tools
Internet Security\Update.exe Report Id: 60f386ed-28ef-11df-81dd-002421a2209a

Error - 6/03/2010 11:06:59 PM | Computer Name = JN | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7600.16385 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 16d4 Start
Time: 01cabda30ddc0891 Termination Time: 10 Application Path: C:\Program Files\Internet
Explorer\iexplore.exe Report Id: 7d315cc1-2996-11df-af22-002421a2209a

Error - 6/03/2010 11:37:39 PM | Computer Name = JN | Source = Application Error | ID = 1000
Description = Faulting application name: pctsTray.exe, version: 7.0.0.43, time stamp:
0x4b035fa2 Faulting module name: ntdll.dll, version: 6.1.7600.16385, time stamp:
0x4a5bdadb Exception code: 0xc0000005 Fault offset: 0x0002d5f7 Faulting process id:
0x6ec Faulting application start time: 0x01cabda1fbf33c30 Faulting application path:
C:\Program Files\PC Tools Internet Security\pctsTray.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: c74665ec-299a-11df-af22-002421a2209a

Error - 7/03/2010 12:48:19 AM | Computer Name = JN | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "c:\program files\pc tools
internet security\networklayer\PCTCFFix64.exe". Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 8/03/2010 2:51:15 AM | Computer Name = JN | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/03/2010 2:51:30 AM | Computer Name = JN | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/03/2010 2:51:45 AM | Computer Name = JN | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/03/2010 2:52:00 AM | Computer Name = JN | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Error Reporting Service service to connect.

Error - 8/03/2010 2:53:20 AM | Computer Name = JN | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:51:31 PM on ?8/?03/?2010 was unexpected.

Error - 8/03/2010 2:53:23 AM | Computer Name = JN | Source = BugCheck | ID = 1001
Description =

Error - 8/03/2010 2:57:08 AM | Computer Name = JN | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:55:09 PM on ?8/?03/?2010 was unexpected.

Error - 8/03/2010 2:57:12 AM | Computer Name = JN | Source = BugCheck | ID = 1001
Description =

Error - 8/03/2010 3:00:04 AM | Computer Name = JN | Source = Service Control Manager | ID = 7023
Description = The Windows Update service terminated with the following error: %%-2147467243

Error - 8/03/2010 3:08:14 AM | Computer Name = JN | Source = bowser | ID = 8003
Description =


< End of report >


No Gmer report 'cuz it blue screened me and I don't want that happening again... :)

Edited by Justinn123, 08 March 2010 - 03:41 AM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP