Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Freezing and crashing


  • This topic is locked This topic is locked

#31
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
MEDIONPC
MS-6747
Microsoft® Windows XP Professional Manufacturer
512MB


aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-24 16:05:30
-----------------------------
16:05:30.390 OS Version: Windows 5.1.2600 Service Pack 3
16:05:30.390 Number of processors: 2 586 0x209
16:05:30.390 ComputerName: YOUR-xxxx UserName: xxxxx
16:05:37.500 Initialize success
16:06:21.750 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
16:06:21.765 Disk 0 Vendor: ST3160021A 3.04 Size: 152627MB BusType: 3
16:06:21.937 Disk 0 MBR read successfully
16:06:21.937 Disk 0 MBR scan
16:06:21.984 Disk 0 scanning sectors +312576705
16:06:22.078 Disk 0 scanning C:\WINDOWS\system32\drivers
16:07:11.187 Service scanning
16:07:17.843 Disk 0 trace - called modules:
16:07:17.875 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
16:07:17.875 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x83354ab8]
16:07:17.875 3 CLASSPNP.SYS[f8535fd7] -> nt!IofCallDriver -> \Device\0000006d[0x83357f18]
16:07:17.875 5 ACPI.sys[f84ac620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x83365940]
16:07:17.890 Scan finished successfully

Edited by jones082, 24 March 2011 - 05:13 PM.

  • 0

Advertisements


#32
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Okay we'll try a CLEAN BOOT TROUBLESHOOTING technique XP and delineate the problem.

  • First, restart in Safe Mode (tap the f8 key promptly on startup and choose the Safe Mode option from the boot menu).
  • In Safe Mode –
    • Run msconfig and select the "Services" tab. Check "Hide Microsoft Services" and then disable the rest (except your antivirus software). Also uncheck "load startup group" on the general page (except your antivirus software).
    • See this link for detailed information:http://support.micro....b;EN-US;310353
    • Now restart and test the issue at hand. Boot times and overall performance issues.
  • Note: if you already have items unchecked under msconfig > startups and are in “selective” startup mode – you should note what these are before beginning. They will need to be de-selected again.

  • 0

#33
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
Ran even worse...could barely function.
Now when I re-boot, when it says "Choose Operating System" there are two Windows XP Media Editions!
I think there used to be a choice for Recovery Console.
  • 0

#34
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts

Now when I re-boot, when it says "Choose Operating System" there are two Windows XP Media Editions!
I think there used to be a choice for Recovery Console.


The recovery console was put in there by Combofix and is used to recover failed systems.

The two Windows XP Media Editions are the windows installations. One would be the original windows and the other is created when you first inserted the XP installation disc and done a windows setup.

Try booting into both and see which one is the new installation then test it if its any different in performance.
  • 0

#35
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
The second installation will not even start...it said something like "boot disk problem."
  • 0

#36
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi,

Boot into the working windows installation.

Download Dial-a-fix
Unzip the program and run it.
Put a check under the following:
MSI
WU/WUAU
SSL/HTTPS/CryptSvc
Registration center


Then click on the GO button.

Next, re-run Combofix then post the log on your next reply.
  • 0

#37
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
Ran Dial a fix.
Ran combofix.
Still no help.

ComboFix 11-03-26.02 - Bill 03/27/2011 13:11:25.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.300 [GMT -7:00]
Running from: C:\Documents and Settings\Bill\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}


((((((((((((((((((((((((( Files Created from 2011-02-27 to 2011-03-27 )))))))))))))))))))))))))))))))


2011-03-27 19:21:47 . 2011-03-27 20:02:41 -------- d-----w- C:\WINDOWS\system32\CatRoot2
2011-03-21 13:42:16 . 2011-02-16 01:39:12 233472 ----a-w- C:\WINDOWS\system32\PuranDefragS.exe
2011-03-21 13:42:16 . 2011-02-16 01:39:12 229376 ----a-w- C:\WINDOWS\system32\PuranDC.exe
2011-03-21 13:42:16 . 2011-02-16 01:39:12 1114112 ----a-w- C:\WINDOWS\system32\PuranFD.exe
2011-03-21 13:42:16 . 2011-02-16 01:39:12 108544 ----a-w- C:\WINDOWS\system32\PuranDefragBT.exe
2011-03-21 13:42:16 . 2009-12-31 21:02:08 212992 ----a-w- C:\WINDOWS\system32\PuranDefrag.dll
2011-03-21 13:42:15 . 2011-03-23 14:48:42 -------- d-----w- C:\Program Files\Puran Defrag
2011-03-21 03:19:04 . 2011-03-21 03:19:04 -------- d-----w- C:\Program Files\ESET
2011-03-17 15:26:52 . 2010-12-21 01:09:00 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-03-17 15:26:19 . 2010-12-21 01:08:40 20952 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2011-03-17 15:26:16 . 2011-03-17 15:26:57 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2011-03-15 00:37:18 . 2011-03-15 00:37:11 2418084 ----a-w- C:\MGtools.exe
2011-03-13 21:03:37 . 2011-03-13 21:03:37 -------- d-----w- C:\Documents and Settings\Bill\Local Settings\Application Data\Help
2011-03-13 01:26:04 . 2011-03-13 01:26:04 -------- d-----w- C:\Documents and Settings\Bill\Application Data\Auslogics
2011-03-13 01:25:50 . 2011-03-13 01:25:50 -------- d-----w- C:\Program Files\Auslogics
2011-03-13 00:16:23 . 2011-03-15 00:17:54 -------- d-----w- C:\Documents and Settings\All Users\Application Data\PCPitstop
2011-03-12 15:31:57 . 2011-02-23 14:54:55 19544 ----a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-03-12 15:31:56 . 2011-02-23 14:56:45 301528 ----a-w- C:\WINDOWS\system32\drivers\aswSP.sys
2011-03-12 15:31:32 . 2011-02-23 14:55:10 25432 ----a-w- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-03-12 15:31:30 . 2011-02-23 14:55:49 49240 ----a-w- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-03-12 15:31:28 . 2011-02-23 14:56:55 371544 ----a-w- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-03-12 15:31:26 . 2011-02-23 14:55:47 102232 ----a-w- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-03-12 15:31:26 . 2011-02-23 14:55:44 96344 ----a-w- C:\WINDOWS\system32\drivers\aswmon.sys
2011-03-12 15:31:24 . 2011-02-23 14:54:57 30680 ----a-w- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-03-12 15:27:30 . 2011-02-23 15:04:21 40648 ----a-w- C:\WINDOWS\avastSS.scr
2011-03-12 15:27:22 . 2011-02-23 15:04:17 190016 ----a-w- C:\WINDOWS\system32\aswBoot.exe
2011-03-12 15:25:55 . 2011-03-12 15:25:55 -------- d-----w- C:\Program Files\AVAST Software
2011-03-12 15:25:55 . 2011-03-12 15:25:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\AVAST Software
2011-03-12 14:50:40 . 2011-03-12 14:50:41 -------- d--h--w- C:\WINDOWS\system32\GroupPolicy
2011-03-11 18:04:42 . 2011-03-11 18:07:04 -------- d-----w- C:\Program Files\WhoCrashed
2011-03-08 22:53:42 . 2011-03-08 22:53:42 -------- d-----w- C:\Documents and Settings\Bill\Application Data\ImgBurn
2011-03-08 22:40:33 . 2011-03-08 22:40:54 -------- d-----w- C:\Program Files\ImgBurn
2011-03-08 15:20:38 . 2010-10-19 20:51:33 222080 ------w- C:\WINDOWS\system32\MpSigStub.exe
2011-03-08 15:07:53 . 2011-03-08 15:07:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Ahead
2011-03-04 03:20:23 . 2011-03-06 22:04:45 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2011-03-03 02:35:50 . 2011-03-03 02:35:50 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2011-03-03 00:00:40 . 2011-03-17 23:35:54 -------- d-----w- C:\Documents and Settings\Bill\Local Settings\Application Data\Temp
2011-03-02 14:32:17 . 2010-12-09 15:15:09 718336 -c--a-w- C:\WINDOWS\system32\dllcache\ntdll.dll
2011-03-02 14:32:17 . 2010-12-09 15:15:09 718336 ----a-w- C:\WINDOWS\system32\ntdll.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-02-19 23:15:11 . 2011-02-19 23:15:11 22 --sha-w- C:\Documents and Settings\Bill\Application Data\Sys2662.Config.Repository.bin
2011-02-09 13:53:52 . 2003-11-12 08:54:00 270848 ----a-w- C:\WINDOWS\system32\sbe.dll
2011-02-09 13:53:52 . 2003-11-12 08:54:00 186880 ----a-w- C:\WINDOWS\system32\encdec.dll
2011-02-02 07:58:35 . 2003-10-25 23:22:59 2067456 ----a-w- C:\WINDOWS\system32\mstscax.dll
2011-01-27 11:57:06 . 2003-10-25 23:22:59 677888 ----a-w- C:\WINDOWS\system32\mstsc.exe
2011-01-21 14:44:37 . 2003-10-25 23:15:53 439296 ----a-w- C:\WINDOWS\system32\shimgvw.dll
2011-01-07 14:09:02 . 2003-10-25 23:15:25 290048 ----a-w- C:\WINDOWS\system32\atmfd.dll
2010-12-31 13:10:33 . 2011-02-18 15:35:21 1854976 ----a-w- C:\WINDOWS\system32\win32k.sys
2006-07-15 09:27:32 . 2006-07-15 09:27:38 774144 ----a-w- C:\Program Files\RngInterstitial.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04:11 122512 ----a-w- C:\Program Files\AVAST Software\Avast\ashShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TClockEx"="C:\Program Files\TClockEx\TCLOCKEX.EXE" [2000-03-09 08:15:18 89088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="C:\Program Files\AVAST Software\Avast\avastUI.exe" [2011-02-23 15:04:20 3451496]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-04-01 23:16:00 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-01 23:16:00 5562368]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2008-04-14 00:12:19 50176]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 02:04:47 35760]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoFavoritesMenu"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 16:13:36 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 21:21:42 548352 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Rio\\Rio Music Manager\\riomm.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\ABBYY FineReader 5.0 Sprint\\Sprint.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\StubInstaller.exe"=
"C:\Documents and Settings\Bill\Local Settings\Apps\2.0\06TZVVQ6.JXN\JY03NKBX.R20\thef...app_0d221d3645bc6701_0002.0005_8decbbb466c17454\The Filter.exe"= C:\Documents and Settings\Bill\Local Settings\Apps\2.0\06TZVVQ6.JXN\JY03NKBX.R20\thef...app_0d221d3645bc6701_0002.0005_8decbbb466c17454\The Filter.exe:127.0.0.1/255.255.255.255:Enabled:The Filter: Windows Media Player plugin
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\doom 3\\Doom3.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"123:TCP"= 123:TCP:time.windows.com

R1 aswSP;aswSP;C:\WINDOWS\system32\drivers\aswSP.sys [3/12/2011 8:31:56 AM 301528]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [11/11/2009 10:44:48 AM 12872]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44:46 AM 67656]
R2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\drivers\EAPPkt.sys [10/9/2007 1:13:00 PM 38144]
R2 WbUsbBus;Winbond USB Smart Card Controller;C:\WINDOWS\system32\drivers\wbusbbus.sys [11/6/2003 12:34:19 PM 18025]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\drivers\wg111v3.sys [12/28/2007 3:02:12 PM 287232]
R3 wbusbscr;Winbond Smartcard Reader;C:\WINDOWS\system32\drivers\wbusbscr.sys [11/6/2003 12:34:19 PM 22340]
S1 aswSnx;aswSnx;C:\WINDOWS\system32\drivers\aswSnx.sys [3/12/2011 8:31:28 AM 371544]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [3/12/2011 8:31:57 AM 19544]
S2 WbUsb;Winbond Generic USB Controller;C:\WINDOWS\system32\drivers\wbusb.sys [11/3/2003 5:41:42 PM 11510]
S3 SASENUM;SASENUM;C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44:50 AM 12872]
S3 utm4odk1;AVZ Kernel Driver;\??\C:\WINDOWS\system32\Drivers\utm4odk1.sys --> C:\WINDOWS\system32\Drivers\utm4odk1.sys [?]
S4 PuranDefrag;PuranDefrag;C:\WINDOWS\system32\PuranDefragS.exe [3/21/2011 6:42:16 AM 233472]

--- Other Services/Drivers In Memory ---

*Deregistered* - uphcleanhlp

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

Contents of the 'Scheduled Tasks' folder

2011-03-24 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006Core.job
- C:\Documents and Settings\Bill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-28 03:20:33 . 2010-04-28 03:20:29]

2011-03-27 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006UA.job
- C:\Documents and Settings\Bill\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-28 03:20:33 . 2010-04-28 03:20:29]

2011-03-27 C:\WINDOWS\Tasks\User_Feed_Synchronization-{91AD3615-D7B6-4577-84DE-F0F77B97CE47}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 19:58:32 . 2009-03-08 11:31:54]


------- Supplementary Scan -------

uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: jango.com\www
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate

Edited by jones082, 27 March 2011 - 02:43 PM.

  • 0

#38
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi jones082,

:D

Ran Dial a fix.
Ran combofix.
Still no help.


It did help, as it corrected the windows cryptographic service which now enabled CF to read if there are patched system files - and yet it has given no significant improvement in actual performance. :D

I apologized for not being able yet to pinpoint what exactly ails this machine.

Something else may be at play here. Can you check the device manager if there no question/exclamation marks shown in the listed devices.
  • 0

#39
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
The only place I know to find exclamation marks is the event viewer. Is that where you mean?
  • 0

#40
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi,

Press Start > Run then type in the following:

devmgmt.msc

The device manager console will pop-up showing a list of devices. Tell me if you see any question/exclamation marks.
  • 0

Advertisements


#41
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
No, just the tree of all the drives, ports, adapters, processors, etc.
  • 0

#42
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi,

  • Re-run AVPTool
  • Select the Manual Disinfection tab
  • Where it states Step 3 paste in the following disinfection script and press execute

    begin
    SetAVZPMStatus(True);
    SetAVZGuardStatus(True);
    SearchRootkit(true, true);
     BC_DeleteFile('C:\DOCUME~1\Bill\LOCALS~1\Temp\{0E94F14D-40F0-43F4-B684-A036DACEA2B1}\Downloadexe.exe');
     DeleteFile('C:\DOCUME~1\Bill\LOCALS~1\Temp\{0E94F14D-40F0-43F4-B684-A036DACEA2B1}\Downloadexe.exe');
     RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\Eventlog\Application\ACW_DE','EventMessageFile');
     RegKeyParamDel('HKEY_USERS','S-1-5-21-531059437-3393555123-1363351605-1006\Software\Microsoft\Windows\CurrentVersion\Run-','NBJ');
    BC_ImportDeletedList;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
    
  • Your system will reboot on completion, if it does not please do so yourself
  • On completion please run another analysis scan and attach the zip file

Posted Image

Next

Run OTL
  • Choose Standard Output
  • Under the extras registry section, ensure that safelist is selected
  • Click Run Scan, post the OTL.txt and Extras.txt on your next reply.

  • 0

#43
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
Hi,
I couldn't find an Extras.txt anywhere. I don't think it generated one.
Attached is the zip file as well.[attachment=48772:avptool_sysinfo.zip]

OTL logfile created on: 3/29/2011 5:13:23 PM - Run 5
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Bill\Desktop\security
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation


Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 209.00 Mb Available Physical Memory | 41.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.36 Gb Total Space | 91.99 Gb Free Space | 63.72% Space Free | Partition Type: NTFS
Drive D: | 4.68 Gb Total Space | 1.14 Gb Free Space | 24.43% Space Free | Partition Type: FAT32

Computer Name: YOUR-xxxxxx | User Name: xxxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/23 10:49:21 | 001,004,088 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Bill\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/03/13 14:11:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Bill\Desktop\security\OTL.exe
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/07/01 10:34:48 | 002,326,528 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe
PRC - [2004/08/26 19:40:20 | 000,282,624 | ---- | M] (Digital Networks North America, Inc.) -- C:\WINDOWS\system32\RioMSC.exe
PRC - [2003/06/11 08:34:58 | 000,155,770 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe


========== Modules (SafeList) ==========

MOD - [2011/03/13 14:11:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Bill\Desktop\security\OTL.exe
MOD - [2011/02/23 08:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
SRV - [2004/08/26 19:40:20 | 000,282,624 | ---- | M] (Digital Networks North America, Inc.) [Auto | Running] -- C:\WINDOWS\system32\RioMSC.exe -- (RioMSC)
SRV - [2003/06/11 08:34:58 | 000,155,770 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe -- (APC UPS Service)


========== Driver Services (SafeList) ==========

DRV - [2011/03/29 16:27:13 | 000,011,264 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\uzm4odk1.sys -- (uzm4odk1)
DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/05/26 18:25:45 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/02 18:08:01 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/03/02 18:08:01 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\06043172.sys -- (06043172)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\01592982.sys -- (01592982)
DRV - [2009/10/09 23:31:10 | 000,315,408 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\0604317.sys -- (setup_9.0.0.722_30.03.2011_02-21drv)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\06043171.sys -- (06043171)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\01592981.sys -- (01592981)
DRV - [2008/04/13 11:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/13 11:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 11:45:34 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irbus.sys -- (IrBus)
DRV - [2008/04/13 11:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/12/28 15:02:12 | 000,287,232 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wg111v3.sys -- (RTL8187B)
DRV - [2007/05/23 14:26:34 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2005/06/02 20:38:36 | 000,018,025 | ---- | M] (Winbond Electronics Corp.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wbusbbus.sys -- (WbUsbBus)
DRV - [2005/06/02 20:33:52 | 000,022,340 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wbusbscr.sys -- (wbusbscr)
DRV - [2004/01/29 10:07:00 | 000,796,064 | R--- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcwPVRP2.sys -- (hcwPVRP2) Hauppauge WinTV-PVR PCI II (Encoder-16)
DRV - [2003/08/27 19:48:00 | 000,011,510 | ---- | M] (Winbond Electronics Corp.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\wbusb.sys -- (WbUsb)
DRV - [2003/07/30 05:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2003/07/30 05:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2003/05/22 08:44:44 | 000,670,203 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctxs51.sys -- (Intels51)
DRV - [2003/03/20 15:01:46 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2001/08/17 07:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.no_proxies_on: "64.136.29.30,64.136.21.30,64.136.29.34,searchap.untd.com,127.0.0.1,localhost,*microsoft.com,*windowsupdate.com,*wustat.windows.com,*.pogo.com,*.worldwinner.com,*test-speed.com,liveupdate.symantecliveupdate.com,*symantec.com,*.nai.com,*.networkassociates.com,*photosite.com,*.dir.untd.com,localhost,127.0.0.1"


File not found (No name found) -- C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\{3EC9C995-8072-4FC0-953E-4F30620D17F3}

O1 HOSTS File: ([2011/03/27 13:26:22 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE (Dale Nurden)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
O4 - Startup: C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk = C:\Documents and Settings\Bill\Desktop\Virus Removal Tool1\setup_9.0.0.722_30.03.2011_02-21\startup.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: jango.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcp...ols/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...ector/swdir.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.micr...b?1093135076296 (MSSecurityAdvisor Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} https://support.micr...ActiveX/odc.cab (Microsoft PID Sniffer)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ontent/opuc.cab (Office Update Installation Engine)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://www.maricopa....in/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1118468142156 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1118468013203 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {91D4B4D5-E368-40AB-8F53-A37FA634B471} http://h36.e-tmm.com/bin/tol9inst.cab (Installer9Ctrl Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupd...7919.2453587963 (Reg Error: Key error.)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft...ols/DoomCln.CAB (DoomCln Object)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} http://mail.lycos.co.../AttachMail.cab (LycosMail Upload Control)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.micr...04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.c...driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Bill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/25 16:26:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/29 16:35:31 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\0604317.sys
[2011/03/29 16:35:31 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\06043171.sys
[2011/03/29 16:35:31 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\06043172.sys
[2011/03/29 16:35:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Desktop\Virus Removal Tool1
[2011/03/29 16:22:20 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\0159298.sys
[2011/03/29 16:22:20 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\01592981.sys
[2011/03/29 16:22:20 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\01592982.sys
[2011/03/29 08:22:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Bill\Recent
[2011/03/27 18:35:49 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/03/27 13:20:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/03/27 13:06:18 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/03/27 13:02:21 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/03/27 12:21:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/03/21 06:42:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Puran Defrag
[2011/03/21 06:42:15 | 000,000,000 | ---D | C] -- C:\Program Files\Puran Defrag
[2011/03/20 20:19:04 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/03/17 08:26:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/17 08:26:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/17 08:26:19 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/17 08:26:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/14 18:04:23 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/03/14 18:04:23 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/03/14 18:04:23 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/03/14 18:04:23 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/03/14 17:53:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/03/13 14:03:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Local Settings\Application Data\Help
[2011/03/13 12:23:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavalys
[2011/03/12 18:26:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Application Data\Auslogics
[2011/03/12 18:25:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2011/03/12 18:25:50 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2011/03/12 17:16:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2011/03/12 08:31:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/03/12 08:31:57 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/12 08:31:56 | 000,301,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/03/12 08:31:32 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/03/12 08:31:30 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/03/12 08:31:28 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/03/12 08:31:26 | 000,102,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/03/12 08:31:26 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/03/12 08:31:24 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/03/12 08:27:30 | 000,040,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/03/12 08:27:22 | 000,190,016 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/03/12 08:25:55 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/03/12 08:25:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/12 07:50:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011/03/11 11:04:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/03/11 11:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
[2011/03/08 15:53:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Application Data\ImgBurn
[2011/03/08 15:40:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/03/08 15:40:33 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/03/08 08:07:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2011/03/03 20:20:23 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/03/02 19:35:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/03/02 17:27:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Templates
[2011/03/02 17:00:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Local Settings\Application Data\Temp
[2006/07/15 02:27:38 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll

========== Files - Modified Within 30 Days ==========

[2011/03/29 17:17:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{91AD3615-D7B6-4577-84DE-F0F77B97CE47}.job
[2011/03/29 17:09:32 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/29 17:06:51 | 000,021,961 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/03/29 17:06:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/29 17:06:26 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/29 17:03:45 | 000,014,528 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\avptool_sysinfo.zip
[2011/03/29 16:37:58 | 000,002,230 | ---- | M] () -- C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk
[2011/03/29 16:27:13 | 000,011,264 | ---- | M] () -- C:\WINDOWS\System32\drivers\uzm4odk1.sys
[2011/03/29 08:35:16 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006UA.job
[2011/03/28 09:00:15 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/28 09:00:14 | 000,002,287 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\Google Chrome.lnk
[2011/03/27 13:26:22 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/27 13:06:30 | 000,000,396 | RHS- | M] () -- C:\Boot.ini
[2011/03/27 13:01:34 | 004,303,726 | R--- | M] () -- C:\Documents and Settings\Bill\Desktop\ComboFix.exe
[2011/03/27 12:26:34 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/03/27 12:26:34 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/03/25 19:10:34 | 000,000,279 | ---- | M] () -- C:\Boot.bak
[2011/03/24 15:35:05 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006Core.job
[2011/03/21 12:14:16 | 000,000,017 | ---- | M] () -- C:\WINDOWS\System32\npd6.d
[2011/03/14 17:37:11 | 002,418,084 | ---- | M] () -- C:\MGtools.exe
[2011/03/14 17:33:40 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Bill\defogger_reenable
[2011/03/12 08:31:28 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/03/12 08:22:50 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/03/08 15:41:00 | 000,001,556 | ---- | M] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/06 12:19:12 | 004,816,641 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\Vince Guaraldi Trio - Charlie Brown Slow.mp3
[2011/03/03 20:38:05 | 000,429,905 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110303-222229.backup

========== Files Created - No Company Name ==========

[2011/03/29 17:06:26 | 536,399,872 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/29 17:04:22 | 000,014,528 | ---- | C] () -- C:\Documents and Settings\Bill\Desktop\avptool_sysinfo.zip
[2011/03/29 16:27:13 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\uzm4odk1.sys
[2011/03/29 16:26:07 | 000,002,230 | ---- | C] () -- C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk
[2011/03/27 13:06:30 | 000,000,279 | ---- | C] () -- C:\Boot.bak
[2011/03/25 19:10:28 | 000,001,802 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
[2011/03/21 06:42:30 | 000,000,017 | ---- | C] () -- C:\WINDOWS\System32\npd6.d
[2011/03/14 18:04:23 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/03/14 18:04:23 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/03/14 18:04:23 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/03/14 18:04:23 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/03/14 18:04:23 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/03/14 17:37:18 | 002,418,084 | ---- | C] () -- C:\MGtools.exe
[2011/03/14 17:33:40 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Bill\defogger_reenable
[2011/03/14 17:30:10 | 004,303,726 | R--- | C] () -- C:\Documents and Settings\Bill\Desktop\ComboFix.exe
[2011/03/08 15:40:59 | 000,001,556 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/08 08:17:52 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/03/06 12:18:12 | 004,816,641 | ---- | C] () -- C:\Documents and Settings\Bill\Desktop\Vince Guaraldi Trio - Charlie Brown Slow.mp3
[2011/02/19 16:15:11 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\Bill\Application Data\Sys2662.Config.Repository.bin
[2010/08/23 20:55:32 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\housecall.guid.cache
[2010/08/04 07:18:54 | 000,018,432 | ---- | C] () -- C:\WINDOWS\ss3unstl.exe
[2010/07/30 18:19:09 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\Bill\Application Data\Sys6925.Config Collection.sys
[2010/07/30 18:19:09 | 000,000,022 | -HS- | C] () -- C:\WINDOWS\Sys3390 SettingsCollection.bin
[2010/07/21 19:47:23 | 000,023,084 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
[2009/07/18 07:42:38 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/11 10:02:41 | 000,059,296 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/03/12 20:37:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\pdwindows20.bin
[2009/03/12 19:19:58 | 000,074,752 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2008/06/07 17:51:11 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\strings.exe
[2008/06/07 17:51:11 | 000,039,184 | ---- | C] () -- C:\WINDOWS\System32\Ntrights.exe
[2008/06/07 17:51:11 | 000,011,254 | ---- | C] () -- C:\WINDOWS\System32\locate.com
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/10/17 03:05:51 | 000,000,031 | ---- | C] () -- C:\WINDOWS\bluevoda.ini
[2007/03/12 01:00:33 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2006/11/12 16:56:36 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/24 02:36:39 | 002,768,896 | ---- | C] () -- C:\WINDOWS\System32\GSDLL32.dll
[2006/10/24 02:36:39 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\gswin32c.exe
[2006/10/24 02:36:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\PSConvert.exe
[2006/10/24 02:36:39 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\psparam.ini
[2006/09/12 15:24:09 | 000,046,345 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/04/12 23:28:45 | 000,105,168 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2006/04/12 23:28:18 | 000,105,168 | ---- | C] () -- C:\WINDOWS\GREUninstall.exe
[2006/04/10 02:17:53 | 000,329,216 | ---- | C] () -- C:\WINDOWS\System32\HTMLExpertLib.dll
[2006/04/10 02:17:53 | 000,104,960 | ---- | C] () -- C:\WINDOWS\System32\UAFDLL.DLL
[2006/04/10 02:17:53 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\HTMLProcessors.dll
[2006/04/10 02:17:53 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\ScriptSyntaxMgr.dll
[2006/04/10 02:17:53 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\HTMLValidator.dll
[2006/04/10 02:17:52 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\HDPREV.DLL
[2006/04/10 02:17:52 | 000,049,664 | ---- | C] () -- C:\WINDOWS\System32\ElementSyntaxMgr.dll
[2006/04/10 02:17:51 | 000,430,080 | ---- | C] () -- C:\WINDOWS\System32\Crde96v3.dll
[2006/03/26 21:11:56 | 000,000,035 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006/03/26 21:11:06 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2006/03/26 21:11:05 | 000,009,136 | ---- | C] () -- C:\WINDOWS\System32\Inetwh16.dll
[2006/03/26 21:11:04 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\Sh33w32.dll
[2006/03/26 21:11:04 | 000,004,528 | ---- | C] () -- C:\WINDOWS\System32\Setbrows.exe
[2006/03/26 21:10:12 | 000,000,157 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\ntl.ini
[2006/03/26 21:10:08 | 000,002,223 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\ntl.nws
[2006/03/24 05:41:33 | 000,107,134 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2006/03/24 05:41:03 | 000,014,191 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/11/30 13:34:40 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2005/11/29 02:33:09 | 000,071,749 | ---- | C] () -- C:\WINDOWS\hcextoutput.dll
[2005/11/29 01:19:31 | 000,000,032 | ---- | C] () -- C:\WINDOWS\thxcfg.ini
[2005/09/20 03:59:52 | 000,069,320 | ---- | C] () -- C:\WINDOWS\hpoins05.dat.temp
[2005/09/20 03:59:52 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat.temp
[2005/08/03 01:25:31 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/08/03 01:17:49 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/07/28 19:34:45 | 000,000,702 | ---- | C] () -- C:\WINDOWS\GraphicsDesk.INI
[2005/07/01 02:00:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CALENDARPLUS.INI
[2005/05/23 00:05:49 | 000,000,059 | ---- | C] () -- C:\WINDOWS\LTDLG13N.INI
[2005/05/21 00:08:50 | 000,005,603 | ---- | C] () -- C:\WINDOWS\1st-ftp.ini
[2005/05/03 11:44:44 | 000,025,157 | ---- | C] () -- C:\WINDOWS\RMAgentOutput.dll
[2005/05/03 11:43:44 | 000,126,976 | ---- | C] () -- C:\WINDOWS\dllTSCLIBMT.dll
[2005/04/27 21:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/27 21:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/01 16:16:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005/03/04 12:20:49 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2005/03/03 16:16:42 | 000,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini
[2005/01/20 01:03:08 | 000,000,019 | ---- | C] () -- C:\WINDOWS\squotes.ini
[2004/12/01 19:14:42 | 000,000,034 | ---- | C] () -- C:\WINDOWS\AuthMgr.INI
[2004/10/22 12:51:04 | 000,000,004 | ---- | C] () -- C:\WINDOWS\uccspecb.sys
[2004/10/13 17:24:03 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2004/10/01 17:33:46 | 000,000,823 | ---- | C] () -- C:\WINDOWS\TSC.ini
[2004/09/08 14:52:43 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/21 22:58:47 | 000,000,603 | ---- | C] () -- C:\WINDOWS\etel5.ini
[2004/08/12 06:02:34 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2004/07/22 17:28:02 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2004/07/14 20:05:36 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2004/07/14 18:55:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MSDraw.ini
[2004/07/12 22:12:49 | 000,001,859 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2004/07/12 20:19:07 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI_setup.ini
[2004/07/12 20:11:32 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT
[2004/07/12 20:10:44 | 000,000,111 | ---- | C] () -- C:\WINDOWS\EPSON Stylus CX5400.ini
[2004/07/12 17:56:09 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/07/11 16:54:37 | 000,106,496 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/07/11 16:54:37 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\fusioncache.dat
[2004/01/25 11:43:22 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/11/12 01:54:00 | 001,287,168 | ---- | C] () -- C:\WINDOWS\System32\quartz(2).dll
[2003/11/12 01:54:00 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/11/07 12:59:11 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/11/03 17:43:03 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\MSIFPCTL.exe
[2003/11/03 07:54:17 | 000,233,472 | ---- | C] () -- C:\WINDOWS\CMIRMDRV.EXE
[2003/11/03 07:54:17 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRMDRV.DLL
[2003/11/03 07:54:17 | 000,003,424 | ---- | C] () -- C:\WINDOWS\cmiainfo.sys
[2003/11/03 07:54:17 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2003/11/03 07:54:17 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2003/11/03 07:54:16 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.exe
[2003/11/03 07:54:16 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2003/11/03 07:54:15 | 000,074,085 | ---- | C] () -- C:\WINDOWS\Cmuda.ini
[2003/11/03 07:54:13 | 000,266,240 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2003/11/03 07:54:13 | 000,225,280 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2003/11/03 07:54:13 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2003/11/03 07:46:30 | 000,000,958 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2003/11/01 11:46:06 | 000,000,015 | ---- | C] () -- C:\WINDOWS\NASBA.ini
[2003/10/27 05:42:20 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2003/10/26 10:01:01 | 000,073,728 | ---- | C] () -- C:\WINDOWS\Dit.exe
[2003/10/26 10:01:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\DitExp.exe
[2003/10/26 10:01:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\Dit.DLL
[2003/10/26 10:01:01 | 000,000,208 | ---- | C] () -- C:\WINDOWS\Dit.INI
[2003/10/26 09:38:11 | 000,294,912 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2003/10/26 09:38:11 | 000,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2003/10/25 16:41:54 | 000,000,874 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/10/25 16:31:55 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/25 16:28:46 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2003/10/25 16:23:48 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/10/25 16:16:30 | 000,000,916 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/10/25 16:15:58 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\NSREG.DLL
[2003/10/25 16:15:51 | 000,458,946 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/10/25 16:15:51 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/10/25 16:15:51 | 000,079,514 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/10/25 16:15:51 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/10/25 16:15:50 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/10/25 16:15:49 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/10/25 16:15:48 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/10/25 16:15:42 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/10/25 16:15:42 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/10/25 16:15:36 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/10/25 16:15:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/10/25 16:15:27 | 000,147,901 | ---- | C] () -- C:\WINDOWS\System32\mtxptlib.dll
[2003/10/25 09:20:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/10/25 09:20:17 | 000,281,336 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/01/07 13:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/05 17:51:00 | 000,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll
[2002/07/04 15:05:34 | 000,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini
[2002/03/14 12:00:26 | 000,038,567 | ---- | C] () -- C:\WINDOWS\System32\pcpbios.exe
[2002/03/13 16:46:46 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\zlib.dll
[2001/12/14 13:34:46 | 000,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2001/10/28 17:42:30 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\prnmnt.dll
[1999/07/23 13:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/12 11:40:22 | 000,029,184 | ---- | C] () -- C:\WINDOWS\rmud.exe
[1998/08/16 05:00:00 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2010/10/18 08:36:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2006/04/15 02:52:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Authentium
[2011/03/12 08:25:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010/07/29 17:45:57 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/05/22 17:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/03/12 20:49:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Iceni
[2011/03/14 17:17:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2008/03/21 20:22:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\The Filter
[2009/12/20 09:30:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/03/12 18:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Auslogics
[2007/08/30 23:26:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\BluesBegone001
[2007/12/03 17:01:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\eFax Messenger
[2010/07/20 17:54:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\ElevatedDiagnostics
[2011/03/06 11:39:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\FrostWire
[2009/01/22 19:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\ICAClient
[2011/03/08 15:53:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\ImgBurn
[2011/02/19 17:20:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\LimeWire
[2007/12/18 15:02:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Netscape
[2009/07/02 23:02:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Opera
[2009/10/29 11:14:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\OverDrive
[2009/06/09 21:11:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\PC Registry Cleaner
[2010/08/27 16:54:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Philipp Winterberg
[2007/01/21 13:40:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Sereniti
[2010/07/25 15:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Stardock
[2009/08/01 16:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\SystemRequirementsLab
[2004/07/11 21:50:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\Template
[2011/02/19 17:19:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Bill\Application Data\WinPatrol
[2011/03/29 17:17:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{91AD3615-D7B6-4577-84DE-F0F77B97CE47}.job

========== Purity Check ==========



< End of report >

Edited by jones082, 29 March 2011 - 06:31 PM.

  • 0

#44
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Hi jones082,

I couldn't find an Extras.txt anywhere. I don't think it generated one.


Run OTL

* Choose Standard Output
* Under the extras registry section, ensure that safelist is selected
* Click Run Scan, post the OTL.txt and Extras.txt on your next reply.


The line in bold.

Can you run it again whilst I review the other logs.
  • 0

#45
jones082

jones082

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 253 posts
Got it:



OTL logfile created on: 3/29/2011 8:34:49 PM - Run 7
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Bill\Desktop\security
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 223.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.36 Gb Total Space | 89.37 Gb Free Space | 61.91% Space Free | Partition Type: NTFS
Drive D: | 4.68 Gb Total Space | 1.14 Gb Free Space | 24.43% Space Free | Partition Type: FAT32

Computer Name: YOUR-Xxxxx | User Name: xxxxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/23 10:49:21 | 001,004,088 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Bill\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/03/13 14:11:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Bill\Desktop\security\OTL.exe
PRC - [2011/02/23 08:04:20 | 003,451,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2008/07/01 10:34:48 | 002,326,528 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe
PRC - [2004/08/26 19:40:20 | 000,282,624 | ---- | M] (Digital Networks North America, Inc.) -- C:\WINDOWS\system32\RioMSC.exe
PRC - [2003/06/11 08:34:58 | 000,155,770 | ---- | M] (American Power Conversion Corporation) -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe


========== Modules (SafeList) ==========

MOD - [2011/03/13 14:11:39 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Bill\Desktop\security\OTL.exe
MOD - [2011/02/23 08:04:17 | 000,197,208 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\snxhk.dll
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/03/29 17:56:26 | 003,229,784 | ---- | M] () [Auto | Running] -- C:/Program Files/Common Files/Akamai/netsession_win_a35e6b9.dll -- (Akamai)
SRV - [2011/02/23 08:04:19 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2005/04/27 14:59:24 | 000,241,725 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean)
SRV - [2004/08/26 19:40:20 | 000,282,624 | ---- | M] (Digital Networks North America, Inc.) [Auto | Running] -- C:\WINDOWS\system32\RioMSC.exe -- (RioMSC)
SRV - [2003/06/11 08:34:58 | 000,155,770 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe -- (APC UPS Service)


========== Driver Services (SafeList) ==========

DRV - [2011/03/29 16:27:13 | 000,011,264 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\uzm4odk1.sys -- (uzm4odk1)
DRV - [2011/02/23 07:56:55 | 000,371,544 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/02/23 07:56:45 | 000,301,528 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/02/23 07:55:49 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/02/23 07:55:47 | 000,102,232 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/02/23 07:55:10 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/02/23 07:54:57 | 000,030,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/02/23 07:54:55 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/05/26 18:25:45 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/03/02 18:08:01 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/03/02 18:08:01 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\06043172.sys -- (06043172)
DRV - [2009/10/22 13:54:18 | 000,037,392 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\01592982.sys -- (01592982)
DRV - [2009/10/09 23:31:10 | 000,315,408 | ---- | M] (Kaspersky Lab) [File_System | System | Stopped] -- C:\WINDOWS\system32\drivers\0604317.sys -- (setup_9.0.0.722_30.03.2011_02-21drv)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\06043171.sys -- (06043171)
DRV - [2009/09/25 17:59:42 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\01592981.sys -- (01592981)
DRV - [2008/04/13 11:56:06 | 000,088,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2008/04/13 11:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 11:45:34 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\irbus.sys -- (IrBus)
DRV - [2008/04/13 11:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2007/12/28 15:02:12 | 000,287,232 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wg111v3.sys -- (RTL8187B)
DRV - [2007/05/23 14:26:34 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2005/06/02 20:38:36 | 000,018,025 | ---- | M] (Winbond Electronics Corp.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\wbusbbus.sys -- (WbUsbBus)
DRV - [2005/06/02 20:33:52 | 000,022,340 | ---- | M] (Winbond Electronics Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wbusbscr.sys -- (wbusbscr)
DRV - [2004/01/29 10:07:00 | 000,796,064 | R--- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcwPVRP2.sys -- (hcwPVRP2) Hauppauge WinTV-PVR PCI II (Encoder-16)
DRV - [2003/08/27 19:48:00 | 000,011,510 | ---- | M] (Winbond Electronics Corp.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\wbusb.sys -- (WbUsb)
DRV - [2003/07/30 05:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2003/07/30 05:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2003/05/22 08:44:44 | 000,670,203 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctxs51.sys -- (Intels51)
DRV - [2003/03/20 15:01:46 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2001/08/17 07:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..network.proxy.no_proxies_on: "64.136.29.30,64.136.21.30,64.136.29.34,searchap.untd.com,127.0.0.1,localhost,*microsoft.com,*windowsupdate.com,*wustat.windows.com,*.pogo.com,*.worldwinner.com,*test-speed.com,liveupdate.symantecliveupdate.com,*symantec.com,*.nai.com,*.networkassociates.com,*photosite.com,*.dir.untd.com,localhost,127.0.0.1"


File not found (No name found) -- C:\PROGRAM FILES\NETSCAPE\NAVIGATOR 9\EXTENSIONS\{3EC9C995-8072-4FC0-953E-4F30620D17F3}

O1 HOSTS File: ([2011/03/27 13:26:22 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE (Dale Nurden)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
O4 - Startup: C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk = C:\Documents and Settings\Bill\Desktop\Virus Removal Tool1\setup_9.0.0.722_30.03.2011_02-21\startup.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: jango.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.micr.../OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcp...ols/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...ector/swdir.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.micr...b?1093135076296 (MSSecurityAdvisor Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.co.../sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} https://support.micr...ActiveX/odc.cab (Microsoft PID Sniffer)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.micros...ontent/opuc.cab (Office Update Installation Engine)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://www.maricopa....in/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1118468142156 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1118468013203 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {91D4B4D5-E368-40AB-8F53-A37FA634B471} http://h36.e-tmm.com/bin/tol9inst.cab (Installer9Ctrl Class)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupd...7919.2453587963 (Reg Error: Key error.)
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} http://www.microsoft...ols/DoomCln.CAB (DoomCln Object)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} http://mail.lycos.co.../AttachMail.cab (LycosMail Upload Control)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.micr...04/clearadj.cab (CTAdjust Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.c...driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Bill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/25 16:26:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/29 17:56:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Akamai
[2011/03/29 16:35:31 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\0604317.sys
[2011/03/29 16:35:31 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\06043171.sys
[2011/03/29 16:35:31 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\06043172.sys
[2011/03/29 16:35:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Desktop\Virus Removal Tool1
[2011/03/29 16:22:20 | 000,315,408 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\0159298.sys
[2011/03/29 16:22:20 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\01592981.sys
[2011/03/29 16:22:20 | 000,037,392 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\01592982.sys
[2011/03/29 08:22:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Bill\Recent
[2011/03/27 18:35:49 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/03/27 13:20:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011/03/27 13:06:18 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011/03/27 13:02:21 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/03/27 12:21:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/03/21 06:42:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Puran Defrag
[2011/03/21 06:42:15 | 000,000,000 | ---D | C] -- C:\Program Files\Puran Defrag
[2011/03/20 20:19:04 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/03/17 08:26:52 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/03/17 08:26:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/03/17 08:26:19 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/03/17 08:26:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/03/14 18:04:23 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011/03/14 18:04:23 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011/03/14 18:04:23 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011/03/14 18:04:23 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011/03/14 17:53:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/03/13 14:03:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Local Settings\Application Data\Help
[2011/03/13 12:23:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavalys
[2011/03/12 18:26:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Application Data\Auslogics
[2011/03/12 18:25:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2011/03/12 18:25:50 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2011/03/12 17:16:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2011/03/12 08:31:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011/03/12 08:31:57 | 000,019,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/03/12 08:31:56 | 000,301,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2011/03/12 08:31:32 | 000,025,432 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/03/12 08:31:30 | 000,049,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/03/12 08:31:28 | 000,371,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/03/12 08:31:26 | 000,102,232 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/03/12 08:31:26 | 000,096,344 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2011/03/12 08:31:24 | 000,030,680 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/03/12 08:27:30 | 000,040,648 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2011/03/12 08:27:22 | 000,190,016 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2011/03/12 08:25:55 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/03/12 08:25:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/03/12 07:50:40 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011/03/11 11:04:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/03/11 11:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
[2011/03/08 15:53:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Application Data\ImgBurn
[2011/03/08 15:40:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn
[2011/03/08 15:40:33 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2011/03/08 08:20:38 | 000,222,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MpSigStub.exe
[2011/03/08 08:07:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2011/03/03 20:20:23 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/03/02 19:35:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/03/02 17:27:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Templates
[2011/03/02 17:00:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Bill\Local Settings\Application Data\Temp
[2006/07/15 02:27:38 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll

========== Files - Modified Within 30 Days ==========

[2011/03/29 20:37:00 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{91AD3615-D7B6-4577-84DE-F0F77B97CE47}.job
[2011/03/29 20:35:03 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006UA.job
[2011/03/29 20:29:47 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/03/29 20:28:05 | 000,021,961 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/03/29 20:27:30 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/03/29 20:27:29 | 536,399,872 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/29 17:55:55 | 000,363,080 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\installer.exe
[2011/03/29 17:03:45 | 000,014,528 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\avptool_sysinfo.zip
[2011/03/29 16:37:58 | 000,002,230 | ---- | M] () -- C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk
[2011/03/29 16:27:13 | 000,011,264 | ---- | M] () -- C:\WINDOWS\System32\drivers\uzm4odk1.sys
[2011/03/28 09:00:15 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/28 09:00:14 | 000,002,287 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\Google Chrome.lnk
[2011/03/27 13:26:22 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011/03/27 13:06:30 | 000,000,396 | RHS- | M] () -- C:\Boot.ini
[2011/03/27 13:01:34 | 004,303,726 | R--- | M] () -- C:\Documents and Settings\Bill\Desktop\ComboFix.exe
[2011/03/27 12:26:34 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/03/27 12:26:34 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/03/25 19:10:34 | 000,000,279 | ---- | M] () -- C:\Boot.bak
[2011/03/24 15:35:05 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-531059437-3393555123-1363351605-1006Core.job
[2011/03/21 12:14:16 | 000,000,017 | ---- | M] () -- C:\WINDOWS\System32\npd6.d
[2011/03/14 17:37:11 | 002,418,084 | ---- | M] () -- C:\MGtools.exe
[2011/03/14 17:33:40 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Bill\defogger_reenable
[2011/03/12 08:31:28 | 000,002,638 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/03/12 08:22:50 | 000,001,945 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2011/03/08 15:41:00 | 000,001,556 | ---- | M] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/06 12:19:12 | 004,816,641 | ---- | M] () -- C:\Documents and Settings\Bill\Desktop\Vince Guaraldi Trio - Charlie Brown Slow.mp3
[2011/03/03 20:38:05 | 000,429,905 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20110303-222229.backup

========== Files Created - No Company Name ==========

[2011/03/29 17:56:07 | 000,363,080 | ---- | C] () -- C:\Documents and Settings\Bill\Desktop\installer.exe
[2011/03/29 17:06:26 | 536,399,872 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/29 17:04:22 | 000,014,528 | ---- | C] () -- C:\Documents and Settings\Bill\Desktop\avptool_sysinfo.zip
[2011/03/29 16:27:13 | 000,011,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\uzm4odk1.sys
[2011/03/29 16:26:07 | 000,002,230 | ---- | C] () -- C:\Documents and Settings\Bill\Start Menu\Programs\Startup\setup_9.0.0.722_30.03.2011_02-21.lnk
[2011/03/27 13:06:30 | 000,000,279 | ---- | C] () -- C:\Boot.bak
[2011/03/25 19:10:28 | 000,001,802 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk
[2011/03/21 06:42:30 | 000,000,017 | ---- | C] () -- C:\WINDOWS\System32\npd6.d
[2011/03/14 18:04:23 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011/03/14 18:04:23 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011/03/14 18:04:23 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011/03/14 18:04:23 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011/03/14 18:04:23 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011/03/14 17:37:18 | 002,418,084 | ---- | C] () -- C:\MGtools.exe
[2011/03/14 17:33:40 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Bill\defogger_reenable
[2011/03/14 17:30:10 | 004,303,726 | R--- | C] () -- C:\Documents and Settings\Bill\Desktop\ComboFix.exe
[2011/03/08 15:40:59 | 000,001,556 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk
[2011/03/08 08:17:52 | 000,001,945 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2011/03/06 12:18:12 | 004,816,641 | ---- | C] () -- C:\Documents and Settings\Bill\Desktop\Vince Guaraldi Trio - Charlie Brown Slow.mp3
[2011/02/19 16:15:11 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\Bill\Application Data\Sys2662.Config.Repository.bin
[2010/08/23 20:55:32 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\housecall.guid.cache
[2010/08/04 07:18:54 | 000,018,432 | ---- | C] () -- C:\WINDOWS\ss3unstl.exe
[2010/07/30 18:19:09 | 000,000,022 | -HS- | C] () -- C:\Documents and Settings\Bill\Application Data\Sys6925.Config Collection.sys
[2010/07/30 18:19:09 | 000,000,022 | -HS- | C] () -- C:\WINDOWS\Sys3390 SettingsCollection.bin
[2010/07/21 19:47:23 | 000,023,084 | ---- | C] () -- C:\WINDOWS\hpqins15.dat
[2009/07/18 07:42:38 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/11 10:02:41 | 000,059,296 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/03/12 20:37:56 | 000,000,031 | ---- | C] () -- C:\WINDOWS\System32\pdwindows20.bin
[2009/03/12 19:19:58 | 000,074,752 | ---- | C] () -- C:\WINDOWS\cadkasdeinst01e.exe
[2008/06/07 17:51:11 | 000,175,616 | ---- | C] () -- C:\WINDOWS\System32\strings.exe
[2008/06/07 17:51:11 | 000,039,184 | ---- | C] () -- C:\WINDOWS\System32\Ntrights.exe
[2008/06/07 17:51:11 | 000,011,254 | ---- | C] () -- C:\WINDOWS\System32\locate.com
[2008/02/04 18:23:10 | 000,693,792 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL
[2007/10/17 03:05:51 | 000,000,031 | ---- | C] () -- C:\WINDOWS\bluevoda.ini
[2007/03/12 01:00:33 | 000,262,144 | ---- | C] () -- C:\WINDOWS\System32\default_user_class.dat
[2006/11/12 16:56:36 | 000,001,751 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/24 02:36:39 | 002,768,896 | ---- | C] () -- C:\WINDOWS\System32\GSDLL32.dll
[2006/10/24 02:36:39 | 000,126,976 | ---- | C] () -- C:\WINDOWS\System32\gswin32c.exe
[2006/10/24 02:36:39 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\PSConvert.exe
[2006/10/24 02:36:39 | 000,000,137 | ---- | C] () -- C:\WINDOWS\System32\psparam.ini
[2006/09/12 15:24:09 | 000,046,345 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.EXE
[2006/04/12 23:28:45 | 000,105,168 | ---- | C] () -- C:\WINDOWS\NSUninst.exe
[2006/04/12 23:28:18 | 000,105,168 | ---- | C] () -- C:\WINDOWS\GREUninstall.exe
[2006/04/10 02:17:53 | 000,329,216 | ---- | C] () -- C:\WINDOWS\System32\HTMLExpertLib.dll
[2006/04/10 02:17:53 | 000,104,960 | ---- | C] () -- C:\WINDOWS\System32\UAFDLL.DLL
[2006/04/10 02:17:53 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\HTMLProcessors.dll
[2006/04/10 02:17:53 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\ScriptSyntaxMgr.dll
[2006/04/10 02:17:53 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\HTMLValidator.dll
[2006/04/10 02:17:52 | 000,129,024 | ---- | C] () -- C:\WINDOWS\System32\HDPREV.DLL
[2006/04/10 02:17:52 | 000,049,664 | ---- | C] () -- C:\WINDOWS\System32\ElementSyntaxMgr.dll
[2006/04/10 02:17:51 | 000,430,080 | ---- | C] () -- C:\WINDOWS\System32\Crde96v3.dll
[2006/03/26 21:11:56 | 000,000,035 | ---- | C] () -- C:\WINDOWS\iltwain.ini
[2006/03/26 21:11:06 | 000,148,480 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.EXE
[2006/03/26 21:11:05 | 000,009,136 | ---- | C] () -- C:\WINDOWS\System32\Inetwh16.dll
[2006/03/26 21:11:04 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\Sh33w32.dll
[2006/03/26 21:11:04 | 000,004,528 | ---- | C] () -- C:\WINDOWS\System32\Setbrows.exe
[2006/03/26 21:10:12 | 000,000,157 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\ntl.ini
[2006/03/26 21:10:08 | 000,002,223 | ---- | C] () -- C:\Documents and Settings\Bill\Application Data\ntl.nws
[2006/03/24 05:41:33 | 000,107,134 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2006/03/24 05:41:03 | 000,014,191 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/11/30 13:34:40 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2005/11/29 02:33:09 | 000,071,749 | ---- | C] () -- C:\WINDOWS\hcextoutput.dll
[2005/11/29 01:19:31 | 000,000,032 | ---- | C] () -- C:\WINDOWS\thxcfg.ini
[2005/09/20 03:59:52 | 000,069,320 | ---- | C] () -- C:\WINDOWS\hpoins05.dat.temp
[2005/09/20 03:59:52 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat.temp
[2005/08/03 01:25:31 | 000,000,004 | ---- | C] () -- C:\WINDOWS\RM_RESULT.DAT
[2005/08/03 01:17:49 | 000,000,170 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/07/28 19:34:45 | 000,000,702 | ---- | C] () -- C:\WINDOWS\GraphicsDesk.INI
[2005/07/01 02:00:02 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CALENDARPLUS.INI
[2005/05/23 00:05:49 | 000,000,059 | ---- | C] () -- C:\WINDOWS\LTDLG13N.INI
[2005/05/21 00:08:50 | 000,005,603 | ---- | C] () -- C:\WINDOWS\1st-ftp.ini
[2005/05/03 11:44:44 | 000,025,157 | ---- | C] () -- C:\WINDOWS\RMAgentOutput.dll
[2005/05/03 11:43:44 | 000,126,976 | ---- | C] () -- C:\WINDOWS\dllTSCLIBMT.dll
[2005/04/27 21:22:38 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005/04/27 21:22:34 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005/04/01 16:16:00 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2005/03/04 12:20:49 | 000,002,560 | ---- | C] () -- C:\WINDOWS\_MSRSTRT.EXE
[2005/03/03 16:16:42 | 000,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini
[2005/01/20 01:03:08 | 000,000,019 | ---- | C] () -- C:\WINDOWS\squotes.ini
[2004/12/01 19:14:42 | 000,000,034 | ---- | C] () -- C:\WINDOWS\AuthMgr.INI
[2004/10/22 12:51:04 | 000,000,004 | ---- | C] () -- C:\WINDOWS\uccspecb.sys
[2004/10/13 17:24:03 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2004/10/01 17:33:46 | 000,000,823 | ---- | C] () -- C:\WINDOWS\TSC.ini
[2004/09/08 14:52:43 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/21 22:58:47 | 000,000,603 | ---- | C] () -- C:\WINDOWS\etel5.ini
[2004/08/12 06:02:34 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2004/07/22 17:28:02 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2004/07/14 20:05:36 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2004/07/14 18:55:15 | 000,000,000 | ---- | C] () -- C:\WINDOWS\MSDraw.ini
[2004/07/12 22:12:49 | 000,001,859 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2004/07/12 20:19:07 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI_setup.ini
[2004/07/12 20:11:32 | 000,000,182 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT4.DAT
[2004/07/12 20:10:44 | 000,000,111 | ---- | C] () -- C:\WINDOWS\EPSON Stylus CX5400.ini
[2004/07/12 17:56:09 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2004/07/11 16:54:37 | 000,106,496 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/07/11 16:54:37 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Bill\Local Settings\Application Data\fusioncache.dat
[2004/01/25 11:43:22 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/11/12 01:54:00 | 001,287,168 | ---- | C] () -- C:\WINDOWS\System32\quartz(2).dll
[2003/11/12 01:54:00 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/11/07 12:59:11 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2003/11/03 17:43:03 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\MSIFPCTL.exe
[2003/11/03 07:54:17 | 000,233,472 | ---- | C] () -- C:\WINDOWS\CMIRMDRV.EXE
[2003/11/03 07:54:17 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRMDRV.DLL
[2003/11/03 07:54:17 | 000,003,424 | ---- | C] () -- C:\WINDOWS\cmiainfo.sys
[2003/11/03 07:54:17 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2003/11/03 07:54:17 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2003/11/03 07:54:16 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.exe
[2003/11/03 07:54:16 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2003/11/03 07:54:15 | 000,074,085 | ---- | C] () -- C:\WINDOWS\Cmuda.ini
[2003/11/03 07:54:13 | 000,266,240 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2003/11/03 07:54:13 | 000,225,280 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2003/11/03 07:54:13 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2003/11/03 07:46:30 | 000,000,958 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2003/11/01 11:46:06 | 000,000,015 | ---- | C] () -- C:\WINDOWS\NASBA.ini
[2003/10/27 05:42:20 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2003/10/26 10:01:01 | 000,073,728 | ---- | C] () -- C:\WINDOWS\Dit.exe
[2003/10/26 10:01:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\DitExp.exe
[2003/10/26 10:01:01 | 000,065,536 | ---- | C] () -- C:\WINDOWS\Dit.DLL
[2003/10/26 10:01:01 | 000,000,208 | ---- | C] () -- C:\WINDOWS\Dit.INI
[2003/10/26 09:38:11 | 000,294,912 | ---- | C] () -- C:\WINDOWS\PIC.dll
[2003/10/26 09:38:11 | 000,024,576 | ---- | C] () -- C:\WINDOWS\HKNTDLL.dll
[2003/10/25 16:41:54 | 000,000,874 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/10/25 16:31:55 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/25 16:28:46 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2003/10/25 16:23:48 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/10/25 16:16:30 | 000,000,916 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/10/25 16:15:58 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\NSREG.DLL
[2003/10/25 16:15:51 | 000,458,946 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/10/25 16:15:51 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/10/25 16:15:51 | 000,079,514 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/10/25 16:15:51 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/10/25 16:15:50 | 000,004,518 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/10/25 16:15:49 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/10/25 16:15:48 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/10/25 16:15:42 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/10/25 16:15:42 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/10/25 16:15:36 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/10/25 16:15:28 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/10/25 16:15:27 | 000,147,901 | ---- | C] () -- C:\WINDOWS\System32\mtxptlib.dll
[2003/10/25 09:20:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/10/25 09:20:17 | 000,281,336 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2003/01/07 13:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/12/05 17:51:00 | 000,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll
[2002/07/04 15:05:34 | 000,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini
[2002/03/14 12:00:26 | 000,038,567 | ---- | C] () -- C:\WINDOWS\System32\pcpbios.exe
[2002/03/13 16:46:46 | 000,053,248 | R--- | C] () -- C:\WINDOWS\System32\zlib.dll
[2001/12/14 13:34:46 | 000,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2001/10/28 17:42:30 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\prnmnt.dll
[1999/07/23 13:46:48 | 000,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 10:53:20 | 000,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll
[1999/01/12 11:40:22 | 000,029,184 | ---- | C] () -- C:\WINDOWS\rmud.exe
[1998/08/16 05:00:00 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll

< End of report >


OTL Extras logfile created on: 3/29/2011 8:34:49 PM - Run 7
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Bill\Desktop\security
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 223.00 Mb Available Physical Memory | 44.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.36 Gb Total Space | 89.37 Gb Free Space | 61.91% Space Free | Partition Type: NTFS
Drive D: | 4.68 Gb Total Space | 1.14 Gb Free Space | 24.43% Space Free | Partition Type: FAT32

Computer Name: YOUR-xxxx | User Name: xxxx | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"123:TCP" = 123:TCP:*:Enabled:time.windows.com
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1035:TCP" = 1035:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe:*:Enabled:hpqcopy2.exe
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe
"C:\Program Files\HP\HP Software Update\hpwucli.exe" = C:\Program Files\HP\HP Software Update\hpwucli.exe:*:Enabled:hpwucli.exe
"C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" = C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Rio\Rio Music Manager\riomm.exe" = C:\Program Files\Rio\Rio Music Manager\riomm.exe:*:Enabled:Rio Music Manager -- (Digital Networks North America, Inc.)
"C:\Program Files\ABBYY FineReader 5.0 Sprint\Sprint.exe" = C:\Program Files\ABBYY FineReader 5.0 Sprint\Sprint.exe:*:Disabled:ABBYY FineReader 5.0 Sprint Plus -- (ABBYY (BIT Software))
"C:\WINDOWS\system32\fxsclnt.exe" = C:\WINDOWS\system32\fxsclnt.exe:*:Enabled:Microsoft Fax Console -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer -- (LimeWire)
"C:\Documents and Settings\Bill\Local Settings\Apps\2.0\06TZVVQ6.JXN\JY03NKBX.R20\thef...app_0d221d3645bc6701_0002.0005_8decbbb466c17454\The Filter.exe" = C:\Documents and Settings\Bill\Local Settings\Apps\2.0\06TZVVQ6.JXN\JY03NKBX.R20\thef...app_0d221d3645bc6701_0002.0005_8decbbb466c17454\The Filter.exe:127.0.0.1/255.255.255.255:Enabled:The Filter: Windows Media Player plugin -- (Exabre Ltd)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire -- (FrostWire Group)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe" = C:\Program Files\Steam\steamapps\common\doom 3\Doom3.exe:*:Enabled:DOOM 3 -- (id Software)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0609D0AF-1382-42BE-81DB-CF30F8B0F6E2}" = Serif PhotoPlus 6.0
"{0AB149EB-2AE0-466C-9BA4-3A718CF06432}" = Informations about your PC
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP1700" = Canon iP1700
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2624B680-02BC-4CBC-839C-DA20DF6EF6EC}" = Citrix Presentation Server Client
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 21
"{282EF7E3-AE54-48AE-A11D-27F512F23AB3}" = Rio Music Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{493F2531-C2E5-4B73-8B11-66E9CFDA9AFA}" = Rio Internet Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A0C892E-FD1C-4203-941E-0956AED20A6A}" = APC PowerChute Personal Edition
"{5C741A01-05D6-4306-BA6A-DC8401285AE8}" = Debugging Tools for Windows
"{6260DD25-D010-4FBC-9A87-D3D70BF8BADB}" = PS2 Multimedia Keyboard Driver
"{66C8BE35-8BBB-472B-96C7-C7C9A499F988}" = ArcSoft Software Suite
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{83073C45-3003-4671-9A86-243AAADD915A}" = Microsoft Calculator Plus
"{8F194222-199F-11D6-B163-AA8310157D2E}" = Microsoft SAPI 5.1 Voices for Windows XP
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint Plus
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{EA1CB7AC-E221-4822-A789-0ADB051DC498}" = Medion Flash XL
"{F1A1FA1C-5973-4355-A7DC-FED4AEA7D1BC}" = APC Back-UPS HS
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Akamai" = Akamai NetSession Interface
"Audacity_is1" = Audacity 1.2.6
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"CleanUp!" = CleanUp!
"C-Media Audio" = C-Media 3D Audio
"Connection Manager" =
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Defraggler" = Defraggler
"DOC to Image Converter_is1" = DOC to Image Converter 2.0
"Easy Picture2Icon" = Easy Picture2Icon 1.0
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Free PS Convert driver_is1" = Free PS Convert driver
"Free RAR Extract Frog" = Free RAR Extract Frog
"FrostWire" = FrostWire 4.20.7
"HijackThis" = HijackThis 2.0.2
"Icon Edit_is1" = Icon Edit 2.1.9
"IconArt" = IconArt
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"IE7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"ImgBurn" = ImgBurn
"Infix" = Infix
"InstallShield Uninstall Information" =
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Malwarebytes' RogueRemover FREE_is1" = Malwarebytes' RogueRemover
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Interactive Training" =
"mmahsc1v64ahdv11f37w2heuzdp7d4pr" =
"MSCSR" = Microsoft Speech Recognition Engine 4.0 (English)
"MSI30a-KB884016" =
"MSI30-Beta1" =
"MSI30-Beta2" =
"MSI30-KB884016" =
"MSI30-RC1" =
"MSI30-RC2" =
"MSI31-Beta" =
"MSI31-RC1" =
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"Neuro-Programmer 2 Professional_is1" = Neuro-Programmer Professional 2.3.6
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"nxrr79drv29d8pp9zy3ee7hgezq5wnqv" =
"PCHealth" =
"PDF Editor 2" = PDF Editor 2
"PIXresizer_is1" = PIXresizer 1.0.8
"Puran Defrag_is1" = Puran Defrag 7.2
"Shockwave" = Shockwave
"Steam App 9050" = DOOM 3
"Switch" = Switch
"SystemRequirementsLab" = System Requirements Lab
"TClockEx_is1" = TClockEx
"The Journey to Wild Divine" = The Journey to Wild Divine
"Unlocker" = Unlocker 1.8.7
"UP286_is1" = Ultimate Paint 2.86 Freeware Edition
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast-Ethernet Adapter
"WhoCrashed_is1" = WhoCrashed 3.01
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Media Center Edition Screen Saver Screen Saver" = Windows XP Media Center Edition Screen Saver Screen Saver
"Windows XP Service Pack" = Windows XP Service Pack 3
"XP TCP/IP Repair_is1" = XP TCP/IP Repair 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/11/2011 2:03:19 PM | Computer Name = YOUR-XKTPAS8D47 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 3/11/2011 2:18:30 PM | Computer Name = YOUR-xxxxxx | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Office
2003 Service Pack 3 (SP3): MAINSP3' could not be installed. Error code 1603. Windows
Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft....k/?LinkId=23127

Error - 3/11/2011 2:18:49 PM | Computer Name = YOUR-xxxxxxx | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Update
for Outlook 2003: Junk E-mail Filter (KB2508974): OUTLFLTR' could not be installed.
Error code 1603. Windows Installer can create logs to help troubleshoot issues
with installing software packages. Use the following link for instructions on turning
on logging support: http://go.microsoft....k/?LinkId=23127

Error - 3/11/2011 2:28:07 PM | Computer Name = YOUR-xxxxxx | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Update
for Office 2003 (KB907417): OTKLOADR' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft....k/?LinkId=23127

Error - 3/11/2011 11:16:32 PM | Computer Name = YOUR-xxxxxx | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Office
2003 Service Pack 3 (SP3): MAINSP3' could not be installed. Error code 1603. Windows
Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft....k/?LinkId=23127

Error - 3/11/2011 11:16:47 PM | Computer Name = YOUR-XKTPAS8D47 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Update
for Outlook 2003: Junk E-mail Filter (KB2508974): OUTLFLTR' could not be installed.
Error code 1603. Windows Installer can create logs to help troubleshoot issues
with installing software packages. Use the following link for instructions on turning
on logging support: http://go.microsoft....k/?LinkId=23127

Error - 3/11/2011 11:16:59 PM | Computer Name = YOUR-XKTPAS8D47 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Professional Edition 2003 - Update 'Update
for Office 2003 (KB907417): OTKLOADR' could not be installed. Error code 1603.
Windows Installer can create logs to help troubleshoot issues with installing software
packages. Use the following link for instructions on turning on logging support:
http://go.microsoft....k/?LinkId=23127

Error - 3/12/2011 10:54:36 AM | Computer Name = YOUR-Xxxxx | Source = MPSampleSubmission | ID = 5000
Description =

Error - 3/20/2011 11:17:56 PM | Computer Name = YOUR-Xxxxxxx | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 3/20/2011 11:17:57 PM | Computer Name = YOUR-XKTPAS8D47 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The specified server cannot perform the requested operation.

[ Media Center Events ]
Error - 4/15/2006 5:38:47 AM | Computer Name = YOUR-Xxxxxxx | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 4/15/2006 2:38:47 AM. You may need to reschedule your recordings.

Error - 3/19/2008 5:26:16 PM | Computer Name = YOUR-XKTPAS8D47 | Source = Recording | ID = 19
Description = The recording schedule has been corrupted and was automatically deleted
on 3/19/2008 2:26:15 PM. You may need to reschedule your recordings.

[ System Events ]
Error - 3/29/2011 8:00:27 PM | Computer Name = YOUR-XKTPAS8D47 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD Networking Support
Environment service which failed to start because of the following error: %%31

Error - 3/29/2011 8:00:27 PM | Computer Name = YOUR-Xxxxxxxxx | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 3/29/2011 8:00:27 PM | Computer Name = YOUR-XKTPAS8D47 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
01592981 06043171 Aavmker4 AFD aswRdr aswSnx aswSP aswTdi Fips FltMgr intelppm IPSec MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
SASDIFSV
SASKUTIL
setup_9.0.0.722_30.03.2011_02-21drv
Tcpip

Error - 3/29/2011 8:04:33 PM | Computer Name = YOUR-Xxxxxxx | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 3/29/2011 8:07:49 PM | Computer Name = YOUR-Xxxxxxx | Source = Service Control Manager | ID = 7001
Description = The aswFsBlk service depends on the FltMgr service which failed to
start because of the following error: %%31

Error - 3/29/2011 8:07:49 PM | Computer Name = YOUR-Xxxxxxxx | Source = Service Control Manager | ID = 7000
Description = The Winbond Generic USB Controller service failed to start due to
the following error: %%1058

Error - 3/29/2011 8:07:59 PM | Computer Name = YOUR-XKTPAS8D47 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
aswSnx FltMgr setup_9.0.0.722_30.03.2011_02-21drv

Error - 3/29/2011 11:28:36 PM | Computer Name = YOUR-XKTPAS8D47 | Source = Service Control Manager | ID = 7001
Description = The aswFsBlk service depends on the FltMgr service which failed to
start because of the following error: %%31

Error - 3/29/2011 11:28:36 PM | Computer Name = YOUR-Xxxxxx | Source = Service Control Manager | ID = 7000
Description = The Winbond Generic USB Controller service failed to start due to
the following error: %%1058

Error - 3/29/2011 11:28:42 PM | Computer Name = YOUR-Xxxxxxx | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
aswSnx FltMgr setup_9.0.0.722_30.03.2011_02-21drv


< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP