Hi kahdah, thanks for getting back to me.

I realise you've got a lot of people asking for help!
I've run all the scans you asked me to and the results follow. As an aside, whilst I was waiting for a reply I had a look at my startup processes with msconfig and found one called "dumprep 0 -k", which looked suspicious to me. I'm no expert on these things but it looked like a command prompt that disabled the standard Microsoft error reporting dialogue box to me, so I disabled it. It didn't help much though!!
Scan results follow. Thanks for the help!
-----------------------------
OTL logfile created on: 11/11/2009 09:37:57 - Run 1
OTL by OldTimer - Version 3.1.5.0 Folder = C:\Documents and Settings\HP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1023.45 Mb Total Physical Memory | 634.93 Mb Available Physical Memory | 62.04% Memory free
1.64 Gb Paging File | 1.36 Gb Available in Paging File | 82.64% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.96 Gb Total Space | 2.05 Gb Free Space | 10.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DANNY
Current User Name: HP
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\HP\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\HP\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wbem\framedyn.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\Syncor11.dll (SoundMAX)
========== Win32 Services (SafeList) ==========
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8wd) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (FontCache3.0.0.0) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (idsvc) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (aspnet_state) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (helpsvc) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (SoundMAX Agent Service (default) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
========== Driver Services (SafeList) ==========
DRV - (AvgMfx86) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (ialm) -- C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (smwdm) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (aeaudio) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (usbcm) -- C:\WINDOWS\system32\drivers\usbcm.sys (Microsystems Corp)
DRV - (AEILAB) -- C:\WINDOWS\system32\drivers\AEILAB.SYS (USB2LAN Provider)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/01 23:42:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/22 08:10:13 | 00,000,000 | ---D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe (adi)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\plop\mbamgui.exe File not found
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident\4.0; File not found
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/31 11:07:36 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (MACHINE) - File not found
O34 - HKLM BootExecute: (BootExecut) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/07/31 11:06:53 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ==========
[2009/11/11 09:34:53 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HP\Desktop\OTL.exe
[2009/11/10 07:49:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/11/07 19:47:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Local Settings\Application Data\Threat Expert
[2009/11/07 19:39:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/11/07 17:15:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\IObit
[2009/11/06 10:15:26 | 00,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2009/11/06 10:15:26 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2009/11/06 10:15:26 | 00,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2009/11/05 15:39:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Local Settings\Application Data\Help
[2009/11/05 15:39:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\Help
[2009/11/05 15:37:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\My Documents\RegRun2
[2009/11/05 09:24:47 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\HP\Desktop\RootRepeal.exe
[2009/11/04 23:02:50 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/11/04 23:02:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/11/04 21:07:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\Malwarebytes
[2009/11/04 21:07:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/11/04 16:40:52 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/11/01 10:47:58 | 00,093,360 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2009/10/31 15:22:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\WinRAR
[2009/10/31 15:21:17 | 00,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2009/10/25 10:45:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/10/21 18:20:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\Download Manager
[2009/10/21 18:16:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\HP\Application Data\GARMIN
[2009/10/21 18:16:20 | 00,000,000 | ---D | C] -- C:\Program Files\Garmin GPS Plugin
[2009/10/21 18:16:16 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2009/10/21 18:16:16 | 00,000,000 | ---D | C] -- C:\Program Files\DIFX
[2009/10/21 18:16:15 | 00,000,000 | ---D | C] -- C:\Program Files\Garmin
[2004/11/24 19:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009/11/11 09:34:53 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HP\Desktop\OTL.exe
[2009/11/11 09:22:37 | 00,206,492 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/11/11 09:22:37 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/11/11 09:21:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/11 09:21:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/11 09:21:45 | 00,122,928 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/11/11 09:15:26 | 04,718,592 | -H-- | M] () -- C:\Documents and Settings\HP\NTUSER.DAT
[2009/11/11 09:15:26 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\HP\ntuser.ini
[2009/11/11 09:15:18 | 05,873,462 | -H-- | M] () -- C:\Documents and Settings\HP\Local Settings\Application Data\IconCache.db
[2009/11/10 16:19:28 | 00,000,416 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3C2A9A05-3E89-4C90-AE87-3454265031E6}.job
[2009/11/10 09:25:46 | 00,002,246 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/11/10 09:25:46 | 00,000,243 | ---- | M] () -- C:\WINDOWS\SYSTEM.INI
[2009/11/10 09:25:46 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/11/09 08:17:33 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/11/08 19:42:46 | 00,002,459 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\Puppy Luv.lnk
[2009/11/08 10:47:00 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/11/07 17:15:44 | 00,000,927 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/11/07 11:44:42 | 00,002,469 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\PowerPoint.lnk
[2009/11/05 17:36:21 | 26,768,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/11/05 15:37:32 | 00,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/11/05 15:37:32 | 00,001,688 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2009/11/05 15:37:32 | 00,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat
[2009/11/05 09:25:59 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\settings.dat
[2009/11/05 09:24:51 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\HP\Desktop\RootRepeal.exe
[2009/11/05 07:58:19 | 00,523,776 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\dds.scr
[2009/11/04 23:03:09 | 00,000,959 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\Spybot - Search & Destroy.lnk
[2009/11/04 16:42:27 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/11/04 09:16:01 | 44,680,544 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/11/04 09:16:01 | 00,072,810 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/11/03 12:37:08 | 00,002,481 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\Excel.lnk
[2009/11/03 07:31:19 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/11/03 07:31:19 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/10/28 10:47:53 | 00,093,360 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2009/10/27 10:23:55 | 00,002,483 | ---- | M] () -- C:\Documents and Settings\HP\Desktop\Word.lnk
[2009/10/25 05:57:38 | 00,508,956 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/25 05:57:38 | 00,433,130 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/10/25 05:57:38 | 00,067,768 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/22 09:19:04 | 05,939,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2009/10/22 09:19:04 | 05,939,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2009/10/14 22:43:17 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009/11/07 17:15:44 | 00,000,927 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Advanced SystemCare.lnk
[2009/11/05 15:37:32 | 00,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat
[2009/11/05 09:25:59 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\HP\Desktop\settings.dat
[2009/11/05 07:58:13 | 00,523,776 | ---- | C] () -- C:\Documents and Settings\HP\Desktop\dds.scr
[2009/11/04 23:03:09 | 00,000,959 | ---- | C] () -- C:\Documents and Settings\HP\Desktop\Spybot - Search & Destroy.lnk
[2009/11/04 16:42:24 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/11/01 07:42:52 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/11/01 07:42:52 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2009/10/25 10:48:54 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/09 16:52:41 | 00,000,020 | ---- | C] () -- C:\WINDOWS\WinInit.Ini
[2009/09/23 06:46:19 | 00,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2009/09/23 06:44:36 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2009/04/30 23:31:06 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/04/30 23:31:06 | 01,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/04/30 23:31:06 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/04/30 23:31:06 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009/03/26 22:09:51 | 00,000,289 | ---- | C] () -- C:\WINDOWS\Resize.INI
[2009/02/19 18:23:08 | 00,000,057 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini
[2008/12/19 15:15:58 | 04,338,246 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2008/12/17 17:41:18 | 00,884,237 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2008/12/17 17:22:58 | 00,093,184 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2008/12/17 17:22:48 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/12/17 17:17:34 | 00,239,247 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2008/12/17 16:59:54 | 00,560,802 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2008/12/11 11:27:02 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/11/29 17:47:16 | 00,000,072 | ---- | C] () -- C:\WINDOWS\mb2loc.ini
[2008/11/28 19:32:18 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/11/10 17:47:02 | 00,019,832 | ---- | C] () -- C:\Documents and Settings\HP\Application Data\GDIPFONTCACHEV1.DAT
[2008/11/01 09:06:07 | 00,000,036 | ---- | C] () -- C:\WINDOWS\Tiny_Run.ini
[2008/10/12 14:56:40 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/10/10 15:35:00 | 00,000,000 | ---- | C] () -- C:\WINDOWS\bbcauto.INI
[2008/10/01 08:57:57 | 00,039,424 | ---- | C] () -- C:\Documents and Settings\HP\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/17 20:11:29 | 00,000,032 | ---- | C] () -- C:\Documents and Settings\HP\Application Data\ntl.ini
[2008/09/16 06:40:19 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2008/09/06 11:22:18 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/06 11:01:06 | 00,019,832 | ---- | C] () -- C:\Documents and Settings\HP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/07/31 16:14:12 | 05,873,462 | -H-- | C] () -- C:\Documents and Settings\HP\Local Settings\Application Data\IconCache.db
[2008/07/31 15:15:00 | 00,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2008/07/31 12:51:54 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\HP\Application Data\desktop.ini
[2008/07/31 11:56:24 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/10/03 17:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/08/04 12:00:00 | 00,002,246 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 12:00:00 | 00,000,243 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
========== LOP Check ==========
[2009/06/29 12:57:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/08/16 12:16:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/11/07 19:52:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/09/17 19:53:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/11/08 10:47:00 | 00,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2004/08/04 12:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/11/11 09:21:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/11/10 16:19:28 | 00,000,416 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{3C2A9A05-3E89-4C90-AE87-3454265031E6}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004/08/04 12:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008/04/14 00:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/14 00:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004/08/04 12:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/14 00:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/14 00:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004/08/04 12:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008/04/14 00:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/14 00:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >
< %SYSTEMDRIVE%\sceclt.dll /s /md5 >
< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >
< %SYSTEMDRIVE%\logevent.dll /s /md5 >
< %SYSTEMDRIVE%\iaStor.sys /s /md5 >
< %SYSTEMDRIVE%\nvstor.sys /s /md5 >
< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004/08/04 12:00:00 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 18:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 18:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 18:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >
< %SYSTEMDRIVE%\viasraid.sys /s /md5 >
< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008/04/13 18:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 18:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 18:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >
========== Alternate Data Streams ==========
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
-----------------------------
OTL Extras logfile created on: 11/11/2009 09:37:57 - Run 1
OTL by OldTimer - Version 3.1.5.0 Folder = C:\Documents and Settings\HP\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1023.45 Mb Total Physical Memory | 634.93 Mb Available Physical Memory | 62.04% Memory free
1.64 Gb Paging File | 1.36 Gb Available in Paging File | 82.64% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.96 Gb Total Space | 2.05 Gb Free Space | 10.81% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DANNY
Current User Name: HP
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger -- (America Online, Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager -- (Electronic Arts)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03737893-5BEE-4C78-9C58-3AE7F172BBBE}" = Garmin Communicator Plugin
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1A5488D7-314D-4CBC-89BF-C5B59510BDBA}" = Finding Nemo
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 17
"{296B2D8E-CE82-92AF-B2E8-A646E7CB78A2}_is1" = RegAlyzer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C59AF9D-4139-4D07-BCA2-3CDEFE8B28E3}" = Puppy Luv A New Breed
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6E612C00-92CD-11D4-9A6D-0000B455B172}" = Slam Tilt
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{abe7844e-4d49-4c7e-9d03-7329a6b9feac}.sdb" = Dorling Kindersley Application Database v1.4
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B406605B-45FE-4D8F-8250-1E77479583AE}" = Zoo Tycoon 2 - Marine Mania
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BCB8D603-985E-4765-B4AB-B4B991A535B7}" = Finding Nemo UWF
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom NetXtreme Ethernet Controller
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D169152F-9CDD-4160-BF1D-2C8BFE550C54}_is1" = Genie Backup Manager Lite 6.0
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E9459BCF-0982-498B-ABA7-26C34323493F}" = Citrix Presentation Server Client - Web Only
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"193bb64c00732e4d5ff2a48ccd900ee4" = Crystal Rain Forest V2
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"99 Bottles" = 99 Bottles
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Adventure Rock_is1" = Adventure Rock 1.0.1.96
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.4
"AOL Instant Messenger" = AOL Instant Messenger
"Arcade Master" = Arcade Master
"AVG8Uninstall" = AVG Free 8.5
"Balloon Kaboom" = Balloon Kaboom
"Balloon Kaboom Challenge" = Balloon Kaboom Challenge
"Blast Thru Special Edition" = Blast Thru Special Edition
"Cars - Radiator Springs Adventures" = Cars - Radiator Springs Adventures
"Colors of War Special Edition" = Colors of War Special Edition
"Dart Mania" = Dart Mania
"Drone" = Drone
"Drop" = Drop
"EADM" = EA Download Manager
"FileZilla Client" = FileZilla Client 3.2.4.1
"Foto Breakout" = Foto Breakout
"Funny Diet" = Funny Diet
"Gonzo Heads" = Gonzo Heads
"HijackThis" = HijackThis 2.0.2
"Human Body Explorer" = Human Body Explorer
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1A5488D7-314D-4CBC-89BF-C5B59510BDBA}" = Finding Nemo
"InstallShield_{B406605B-45FE-4D8F-8250-1E77479583AE}" = Zoo Tycoon 2 - Marine Mania
"InstallShield_{BCB8D603-985E-4765-B4AB-B4B991A535B7}" = Finding Nemo: Nemo's Underwater World of Fun
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom NetXtreme Ethernet Controller
"Jewel Jam Special Edition" = Jewel Jam Special Edition
"Leap And Croak" = Leap And Croak
"LEGO Stunt Rally" = LEGO Stunt Rally
"MarbleBlastGold" = MarbleBlast (remove only)
"Maze Cube" = Maze Cube
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mini Golf Special Edition" = Mini Golf Special Edition
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"MusicBox 2" = MusicBox 2
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Node Jumper Special Edition" = Node Jumper Special Edition
"NoteTab Light_is1" = NoteTab Light (Remove only)
"NVIDIA Drivers" = NVIDIA Drivers
"Pingu and Friends" = Pingu and Friends
"QuickTime" = QuickTime
"Science Genius Virtual Laboratory_is1" = Science Genius Virtual Laboratory
"Snake Arena Special Edition" = Snake Arena Special Edition
"Space Battle 2001 Special Edition" = Space Battle 2001 Special Edition
"Sunken Treasure" = Sunken Treasure
"SystemRequirementsLab" = System Requirements Lab
"TescoDownloader" = Tesco Download Manager
"Tile Blazer Special Edition" = Tile Blazer Special Edition
"ViewpointMediaPlayer" = Viewpoint Media Player
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"World Explorer" = World Explorer
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XP Codec Pack" = XP Codec Pack
"Zoombinis Island Odyssey" = Zoombinis Island Odyssey
"Zoombinis Mountain Rescue" = Zoombinis Mountain Rescue
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 09/10/2009 12:44:51 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application wx32.exe, version 2.0.20.0, faulting module wx32.exe,
version 2.0.20.0, fault address 0x00121d98.
Error - 09/10/2009 12:51:28 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application wx32.exe, version 2.0.20.0, faulting module wx32.exe,
version 2.0.20.0, fault address 0x000be951.
Error - 09/10/2009 12:51:50 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application wx32.exe, version 2.0.20.0, faulting module wx32.exe,
version 2.0.20.0, fault address 0x000be951.
Error - 09/10/2009 12:57:31 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application wx32.exe, version 2.0.20.0, faulting module wx32.exe,
version 2.0.20.0, fault address 0x000be951.
Error - 09/10/2009 12:57:52 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application wx32.exe, version 2.0.20.0, faulting module wx32.exe,
version 2.0.20.0, fault address 0x000be951.
Error - 09/10/2009 15:56:36 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x003a006c.
Error - 11/10/2009 14:45:22 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application setup32.exe, version 3.0.0.0, faulting module
setup32.exe, version 3.0.0.0, fault address 0x000063c2.
Error - 24/10/2009 05:28:20 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application gng.exe, version 0.0.0.0, faulting module gng.exe,
version 0.0.0.0, fault address 0x00008ead.
Error - 24/10/2009 05:29:35 | Computer Name = DANNY | Source = Application Error | ID = 1000
Description = Faulting application gng.exe, version 0.0.0.0, faulting module gng.exe,
version 0.0.0.0, fault address 0x00008ead.
Error - 25/10/2009 06:46:35 | Computer Name = DANNY | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
[ System Events ]
Error - 09/11/2009 09:56:00 | Computer Name = DANNY | Source = ipnathlp | ID = 30009
Description = The DHCP allocator encountered a network error while attempting to
reply on IP address 252.47.70.102 to a request from a client. The data is the error
code.
Error - 09/11/2009 19:27:10 | Computer Name = DANNY | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
Error - 10/11/2009 03:36:42 | Computer Name = DANNY | Source = Service Control Manager | ID = 7023
Description = The Windows Firewall/Internet Connection Sharing (ICS) service terminated
with the following error: %%5
Error - 10/11/2009 05:35:28 | Computer Name = DANNY | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
Error - 10/11/2009 12:17:02 | Computer Name = DANNY | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer HP DeskJet 710C share name
Printer.
Error - 10/11/2009 12:22:00 | Computer Name = DANNY | Source = ipnathlp | ID = 30005
Description = The DHCP allocator has detected a DHCP server with IP address 192.168.0.22
on
the same network as the interface with IP address 192.168.0.1. The allocator has
disabled itself on the interface in order to avoid confusing DHCP clients.
Error - 10/11/2009 20:12:18 | Computer Name = DANNY | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
Error - 11/11/2009 02:56:45 | Computer Name = DANNY | Source = ipnathlp | ID = 30005
Description = The DHCP allocator has detected a DHCP server with IP address 192.168.0.22
on
the same network as the interface with IP address 192.168.0.1. The allocator has
disabled itself on the interface in order to avoid confusing DHCP clients.
Error - 11/11/2009 02:56:45 | Computer Name = DANNY | Source = ipnathlp | ID = 30009
Description = The DHCP allocator encountered a network error while attempting to
reply on IP address 252.47.70.102 to a request from a client. The data is the error
code.
Error - 11/11/2009 05:15:03 | Computer Name = DANNY | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
< End of report >
-----------------------------
GMER 1.0.15.15220 -
http://www.gmer.net
Rootkit scan 2009-11-11 10:02:25
Windows 5.1.2600 Service Pack 3
Running: izbfktbb.exe; Driver: C:\DOCUME~1\HP\LOCALS~1\Temp\fgtdapow.sys
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\spoolsv.exe[184] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\spoolsv.exe[184] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\spoolsv.exe[184] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\spoolsv.exe[184] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\spoolsv.exe[184] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\spoolsv.exe[184] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\spoolsv.exe[184] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\spoolsv.exe[184] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[364] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[756] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[756] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[756] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[756] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[756] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[756] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[756] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[756] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[792] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\winlogon.exe[828] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\winlogon.exe[828] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\winlogon.exe[828] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\winlogon.exe[828] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\winlogon.exe[828] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\winlogon.exe[828] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\winlogon.exe[828] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\winlogon.exe[828] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\services.exe[880] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\services.exe[880] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\services.exe[880] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\services.exe[880] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\services.exe[880] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\services.exe[880] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\services.exe[880] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\lsass.exe[892] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\lsass.exe[892] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\lsass.exe[892] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\lsass.exe[892] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\lsass.exe[892] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\lsass.exe[892] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\lsass.exe[892] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[936] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\Java\jre6\bin\jqs.exe[980] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\nvsvc32.exe[1072] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\nvsvc32.exe[1072] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\nvsvc32.exe[1072] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[1112] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1112] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1112] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1112] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1112] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1112] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1112] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\System32\svchost.exe[1420] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\svchost.exe[1420] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\svchost.exe[1420] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\svchost.exe[1420] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\svchost.exe[1420] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\svchost.exe[1420] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\svchost.exe[1420] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\svchost.exe[1420] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\svchost.exe[1680] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\svchost.exe[1680] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\svchost.exe[1680] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\svchost.exe[1680] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\svchost.exe[1680] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\svchost.exe[1680] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\svchost.exe[1680] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\svchost.exe[1680] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\System32\alg.exe[1868] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\System32\alg.exe[1868] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\System32\alg.exe[1868] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\System32\alg.exe[1868] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\System32\alg.exe[1868] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\System32\alg.exe[1868] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\System32\alg.exe[1868] WS2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\System32\alg.exe[1868] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe[2304] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\Program Files\WinZip\WZQKPICK.EXE[2496] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
.text C:\WINDOWS\system32\wscntfy.exe[3612] ntdll.dll!NtOpenKey 7C90D5CE 5 Bytes JMP 10003D7C
.text C:\WINDOWS\system32\wscntfy.exe[3612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10003BEC
.text C:\WINDOWS\system32\wscntfy.exe[3612] kernel32.dll!ExitProcess 7C81CB12 5 Bytes JMP 10003DEC
.text C:\WINDOWS\system32\wscntfy.exe[3612] ws2_32.dll!connect 71AB4A07 5 Bytes JMP 10003AA0
.text C:\WINDOWS\system32\wscntfy.exe[3612] ws2_32.dll!send 71AB4C27 5 Bytes JMP 10003214
.text C:\WINDOWS\system32\wscntfy.exe[3612] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 100027E4
.text C:\WINDOWS\system32\wscntfy.exe[3612] ws2_32.dll!recv 71AB676F 5 Bytes JMP 10002778
.text C:\WINDOWS\system32\wscntfy.exe[3612] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10003A4C
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
-----------------------------