Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Suddenly running slow/loss of disk space.


  • Please log in to reply

#1
macko01

macko01

    Member

  • Member
  • PipPip
  • 39 posts
Recently my computer has been running quite slow and when I've been turning it on I've been having to go through a diskchk every time. Last night when I switched off the computer I had around 186GB, this morning when I booted it up it told me I had 8GB left, even though the computer hadn't been on. I restarted the computer for it to then tell me that all the programs were corrupted (although the disk space was back) and that it had to restart again to do another disk check, after the reboot all the disk space is gone again.

I've done a virus scan with ESET and I have done a scan with Malwarebytes' Anti-Malware.

This is a OTL log:

OTL logfile created on: 20/06/2011 13:09:28 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\scott\Downloads\Programs
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.87 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 41.78% Memory free
185.07 Gb Paging File | 183.56 Gb Available in Paging File | 99.18% Paging File free
Paging file location(s): c:\pagefile.sys 191300 191300 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 285.55 Gb Total Space | 8.98 Gb Free Space | 3.15% Space Free | Partition Type: NTFS
Drive D: | 12.54 Gb Total Space | 12.44 Gb Free Space | 99.22% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 171.41 Gb Free Space | 57.50% Space Free | Partition Type: NTFS

Computer Name: SCOTT-PC | User Name: scott | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/06/20 12:58:57 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\scott\Downloads\Programs\OTL.exe
PRC - [2011/05/30 23:30:35 | 000,140,952 | ---- | M] (Google Inc.) -- C:\Users\scott\AppData\Local\Google\Update\1.3.21.57\GoogleCrashHandler.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/05/25 17:29:48 | 001,336,712 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011/05/10 11:12:10 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/04/25 16:30:48 | 003,298,712 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2011/04/15 00:18:12 | 000,328,952 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2011/04/15 00:18:10 | 000,352,304 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/20 10:20:12 | 001,305,408 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2011/01/14 15:55:57 | 002,250,616 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
PRC - [2011/01/12 16:41:24 | 002,219,184 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
PRC - [2010/11/20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/05/25 15:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2009/08/04 20:10:14 | 001,369,600 | ---- | M] (BrandonZ.net) -- C:\Program Files\ZScreen\ZScreen.exe
PRC - [2009/07/14 02:14:24 | 001,401,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mmc.exe
PRC - [2002/08/14 04:33:46 | 001,130,496 | ---- | M] () -- C:\mysql\bin\mysqld-nt.exe


========== Modules (SafeList) ==========

MOD - [2011/06/20 12:58:57 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Users\scott\Downloads\Programs\OTL.exe
MOD - [2010/11/20 12:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Disabled | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/05/25 17:29:48 | 001,336,712 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011/04/15 00:18:12 | 000,328,952 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2011/04/15 00:18:10 | 000,352,304 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2011/01/14 15:55:57 | 002,250,616 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/01/12 16:44:02 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2011/01/12 16:41:42 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2011/01/12 04:01:35 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2002/08/14 04:33:46 | 001,130,496 | ---- | M] () [Auto | Running] -- C:\mysql\bin\mysqld-nt.exe -- (MySql)


========== Driver Services (SafeList) ==========

DRV - [2011/06/05 17:05:47 | 000,218,688 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/15 00:18:10 | 000,037,376 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HssDrv.sys -- (HssDrv)
DRV - [2011/04/12 13:01:38 | 000,045,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV - [2011/04/01 22:32:30 | 000,027,632 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\seehcri.sys -- (seehcri)
DRV - [2011/04/01 22:30:52 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
DRV - [2011/04/01 22:30:52 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
DRV - [2011/03/28 18:46:40 | 000,086,792 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2010/12/21 15:04:06 | 000,137,144 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2010/12/21 15:04:06 | 000,115,008 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/12/21 13:47:38 | 000,134,000 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2010/12/21 13:47:38 | 000,041,336 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2010/12/21 13:47:38 | 000,033,120 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2010/09/22 20:19:02 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/04/12 09:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010/04/01 02:08:26 | 011,621,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/30 17:12:54 | 000,287,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 23:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/05/20 09:47:40 | 000,552,960 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2007/05/15 13:15:22 | 000,042,496 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 40 7F 0A DE 24 B1 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.3.0244
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [email protected]:7.2.6
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.10
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/10 11:12:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/02 20:22:37 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/04/17 11:06:10 | 000,000,000 | ---D | M]

[2011/01/11 01:26:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\scott\AppData\Roaming\Mozilla\Extensions
[2011/05/24 11:50:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\scott\AppData\Roaming\Mozilla\Firefox\Profiles\512oujoc.default\extensions
[2011/04/24 17:40:40 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\scott\AppData\Roaming\Mozilla\Firefox\Profiles\512oujoc.default\extensions\[email protected]
[2011/03/23 21:29:22 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\scott\AppData\Roaming\Mozilla\Firefox\Profiles\512oujoc.default\extensions\[email protected]
[2011/03/29 12:05:26 | 000,000,000 | ---D | M] (Trillian Toolbar) -- C:\Users\scott\AppData\Roaming\Mozilla\Firefox\Profiles\512oujoc.default\extensions\[email protected]
[2011/06/05 16:42:27 | 000,002,055 | ---- | M] () -- C:\Users\scott\AppData\Roaming\Mozilla\Firefox\Profiles\512oujoc.default\searchplugins\daemon-search.xml
[2011/04/27 16:15:52 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/01/11 01:32:05 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/13 02:05:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/24 12:15:07 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/04/27 16:15:52 | 000,000,000 | ---D | M] (afurladvisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
File not found (No name found) --
[2011/06/13 19:04:14 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\SCOTT\APPDATA\ROAMING\IDM\IDMMZCC3
() (No name found) -- C:\USERS\SCOTT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\512OUJOC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/05/10 11:12:10 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2011/03/22 19:38:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/05/10 11:12:12 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2011/05/10 11:12:12 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/05/10 11:12:12 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2011/05/10 11:12:12 | 000,001,180 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2011/05/10 11:12:12 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/06/01 17:14:37 | 000,001,132 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 195.189.238.82 servserv.westwood.com
O1 - Hosts: 195.189.238.82 irc.westwood.com
O1 - Hosts: 195.189.238.82 gameres.westwood.com
O1 - Hosts: 195.189.238.82 apiregister.westwood.com
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: () - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: () - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: () - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [ZScreen] C:\Program Files\ZScreen\ZScreen.exe (BrandonZ.net)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/09/12 15:03:17 | 000,000,000 | RH-D | M] - F:\autorun -- [ NTFS ]
O32 - AutoRun File - [2002/10/17 03:56:50 | 000,000,036 | RH-- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\autorun.exe
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\autorun2.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/06/20 12:53:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/20 12:50:11 | 000,000,000 | -HSD | C] -- C:\found.001
[2011/06/20 12:31:40 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Malwarebytes
[2011/06/20 12:31:33 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/06/20 12:31:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/20 12:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/20 12:31:29 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/06/20 12:31:29 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/18 16:32:49 | 000,000,000 | ---D | C] -- C:\Users\scott\Desktop\folder
[2011/06/18 16:02:03 | 000,000,000 | ---D | C] -- C:\Users\scott\Desktop\Nero-Guilt_EP-WEB-2011
[2011/06/15 22:20:22 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/06/15 22:20:21 | 001,797,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2011/06/15 22:20:21 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/06/15 22:20:21 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/06/15 16:20:46 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/06/14 22:25:14 | 000,000,000 | -HSD | C] -- C:\found.000
[2011/06/13 14:04:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2011/06/13 14:00:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
[2011/06/13 13:59:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2011/06/13 13:51:27 | 000,000,000 | ---D | C] -- C:\Users\scott\Desktop\Microsoft Office 2007
[2011/06/07 17:23:34 | 000,000,000 | ---D | C] -- C:\Program Files\URLGameStarter
[2011/06/07 17:23:34 | 000,000,000 | ---D | C] -- C:\Games
[2011/06/07 11:49:22 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\ooVoo Details
[2011/06/07 11:49:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2011/06/07 11:49:04 | 000,000,000 | ---D | C] -- C:\Program Files\ooVoo
[2011/06/05 17:05:46 | 000,218,688 | ---- | C] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2011/06/05 16:42:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
[2011/06/05 16:42:15 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2011/06/02 20:22:37 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Detector Plug-in
[2011/06/02 20:22:37 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp Detect
[2011/06/02 20:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
[2011/06/02 20:22:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2011/06/02 20:22:08 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Winamp
[2011/06/02 20:22:08 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp
[2011/06/01 16:37:05 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Local\LogMeIn Hamachi
[2011/06/01 16:35:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/06/01 16:35:38 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2011/06/01 15:40:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Westwood
[2011/06/01 15:34:46 | 000,000,000 | ---D | C] -- C:\Westwood
[2011/05/31 14:17:16 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed
[2011/05/31 14:14:39 | 000,000,000 | ---D | C] -- C:\LFS
[2011/05/28 16:56:05 | 000,404,640 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/05/27 15:35:25 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Adobe Mini Bridge CS5
[2011/05/27 15:35:24 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/05/25 06:45:13 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2011/05/21 21:41:14 | 000,000,000 | ---D | C] -- C:\Users\scott\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portforward.com
[2011/05/21 21:41:14 | 000,000,000 | ---D | C] -- C:\Program Files\PFPortChecker

========== Files - Modified Within 30 Days ==========

[2011/06/20 13:10:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/20 12:59:12 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 12:59:12 | 000,013,440 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 12:52:07 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/20 12:51:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/20 12:51:40 | 1507,729,408 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/20 12:50:49 | 000,003,496 | ---- | M] () -- C:\bootsqm.dat
[2011/06/20 12:46:06 | 000,630,640 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/20 12:46:06 | 000,111,422 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/20 12:39:52 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\thqsdr.sys
[2011/06/20 12:35:30 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1717622452-4231292712-1016612457-1001UA.job
[2011/06/20 12:31:33 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/20 12:08:29 | 000,013,396 | ---- | M] () -- C:\Users\scott\Desktop\s_throne - Shortcut.lnk
[2011/06/19 23:48:49 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1717622452-4231292712-1016612457-1001Core.job
[2011/06/19 13:41:07 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/19 12:06:57 | 000,225,903 | ---- | M] () -- C:\Users\scott\Desktop\Screen shot 2011-06-19 at 12.05.22.png
[2011/06/18 15:25:51 | 005,920,343 | ---- | M] () -- C:\Users\scott\Desktop\01-I'm Into You (Single Edit).mp3
[2011/06/17 21:36:56 | 003,856,092 | ---- | M] () -- C:\Users\scott\Desktop\01 Pop Drop & Roll (feat. Lisette Bu.mp3
[2011/06/17 13:59:48 | 000,278,250 | ---- | M] () -- C:\Users\scott\Desktop\prices.png
[2011/06/16 22:02:18 | 001,232,199 | ---- | M] () -- C:\Users\scott\Desktop\ammendments.png
[2011/06/16 21:49:38 | 000,516,810 | ---- | M] () -- C:\Users\scott\Desktop\FINISHEDithink.png
[2011/06/16 16:23:03 | 000,414,140 | ---- | M] () -- C:\Users\scott\Desktop\carsite.png
[2011/06/16 15:21:25 | 000,324,094 | ---- | M] () -- C:\Users\scott\Desktop\website.png
[2011/06/15 16:39:50 | 224,341,823 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/06/15 16:20:54 | 000,000,000 | ---- | M] () -- C:\Windows\System32\cd.dat
[2011/06/13 19:10:29 | 000,001,107 | ---- | M] () -- C:\Users\scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/06/13 19:00:32 | 003,774,896 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/06/06 23:05:27 | 000,000,132 | ---- | M] () -- C:\Users\scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/06/05 17:05:47 | 000,218,688 | ---- | M] (DT Soft Ltd) -- C:\Windows\System32\drivers\dtsoftbus01.sys
[2011/06/04 15:02:54 | 000,000,129 | ---- | M] () -- C:\Users\scott\jagex_runescape_preferences2.dat
[2011/06/04 14:33:25 | 000,000,034 | ---- | M] () -- C:\Users\scott\jagex_runescape_preferences.dat
[2011/06/02 20:22:37 | 000,000,965 | ---- | M] () -- C:\Users\scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/05/27 02:53:51 | 534,520,790 | ---- | M] () -- C:\Users\scott\Desktop\Microsoft Office 2007 FULL PACKAGE NO SERIAL.zip
[2011/05/24 19:14:10 | 000,222,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe

========== Files Created - No Company Name ==========

[2011/06/20 12:50:49 | 000,003,496 | ---- | C] () -- C:\bootsqm.dat
[2011/06/20 12:39:52 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\thqsdr.sys
[2011/06/20 12:31:33 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/20 12:08:29 | 000,013,396 | ---- | C] () -- C:\Users\scott\Desktop\s_throne - Shortcut.lnk
[2011/06/19 12:06:52 | 000,225,903 | ---- | C] () -- C:\Users\scott\Desktop\Screen shot 2011-06-19 at 12.05.22.png
[2011/06/18 15:24:39 | 005,920,343 | ---- | C] () -- C:\Users\scott\Desktop\01-I'm Into You (Single Edit).mp3
[2011/06/17 21:35:02 | 003,856,092 | ---- | C] () -- C:\Users\scott\Desktop\01 Pop Drop & Roll (feat. Lisette Bu.mp3
[2011/06/17 13:59:26 | 000,278,250 | ---- | C] () -- C:\Users\scott\Desktop\prices.png
[2011/06/16 22:01:56 | 001,232,199 | ---- | C] () -- C:\Users\scott\Desktop\ammendments.png
[2011/06/16 21:49:20 | 000,516,810 | ---- | C] () -- C:\Users\scott\Desktop\FINISHEDithink.png
[2011/06/16 16:22:42 | 000,414,140 | ---- | C] () -- C:\Users\scott\Desktop\carsite.png
[2011/06/16 15:21:04 | 000,324,094 | ---- | C] () -- C:\Users\scott\Desktop\website.png
[2011/06/15 16:39:50 | 224,341,823 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/06/15 16:20:54 | 000,000,000 | ---- | C] () -- C:\Windows\System32\cd.dat
[2011/06/13 14:13:09 | 000,001,107 | ---- | C] () -- C:\Users\scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/06/13 13:40:25 | 534,520,790 | ---- | C] () -- C:\Users\scott\Desktop\Microsoft Office 2007 FULL PACKAGE NO SERIAL.zip
[2011/06/02 20:22:37 | 000,000,965 | ---- | C] () -- C:\Users\scott\Application Data\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk
[2011/05/18 17:39:29 | 000,423,936 | ---- | C] () -- C:\Users\scott\AppData\Roaming\chrtmp
[2011/03/25 20:02:14 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2011/02/24 13:31:33 | 000,001,456 | ---- | C] () -- C:\Users\scott\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/02/06 18:03:52 | 000,000,132 | ---- | C] () -- C:\Users\scott\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/01/25 23:52:47 | 000,006,136 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2011/01/16 15:31:35 | 000,000,132 | ---- | C] () -- C:\Users\scott\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/01/11 03:58:51 | 000,000,020 | ---- | C] () -- C:\Users\scott\AppData\Roaming\ArbiAuth.ini
[2011/01/11 03:42:07 | 000,000,026 | ---- | C] () -- C:\Users\scott\AppData\Roaming\RSBot_Accounts.ini
[2011/01/11 01:20:01 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 003,774,896 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,630,640 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,111,422 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:588B60C7

< End of report >

Edited by macko01, 20 June 2011 - 06:19 AM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP