I was actually expecting to have to wait longer, hence the delayed reply (I just checked the forum today; will definitely be turning on email notifications ^^).
So, problems that I've been having. Well, about a week ago AVG started popping up telling me I have Trojan.fakealert and Trojan.agent as well as an annoying fake antivirus called Internet Security 2010. I got rid of Internet Security using a guide online (I actually had to go online on my phone, as it was blocking me from going to most any webpages). But AVG continued to pop up telling me I had Trojans- unfortunately I cleaned my Virus Vault and reinstalled AVG, so I have no record of what it was telling me I had. With that failing, I came here and followed Boopme's instructions on this thread:
http://www.bleepingcomputer.com/forums/ind...p;#entry1576856 Currently I have these Trojans in the Virus Vault: Crypt.LZO, Downloader.Small.GSQ, Pakes.ELN, Generic16.ZZT.
As for other problems...Safe mode runs ridiculously slow for me, don't know if that's normal or not. My computer just recently started doing the startup/shutdown music again (it hasn't done that in almost a year, I was very surprised). Firefox usually takes a few minutes to open, but other programs work fine. Sometimes I'll close Firefox and try to open it again, but a notification tells me it's already running and to close it. So I have to go into Task Manager and end the process. My DVD drive has disappeared a few times, and updating drivers never helps; I have to uninstall it and restart my computer for it to recognize that it's there.
I dunno if that helps or not. Also, I'm on a Toshiba Satellite laptop that's a little over 2yrs old. This is the first time AVG has notified me of any major problems.
Here's the logs:
OTL logfile created on: 1/21/2010 3:17:23 PM - Run 1
OTL by OldTimer - Version 3.1.25.3 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.1 | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 25.23 Gb Free Space | 17.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAIBOX
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/01/21 14:42:29 | 00,547,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
PRC - [2010/01/15 22:10:34 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/01/11 19:19:21 | 02,033,432 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/01/11 15:37:30 | 01,055,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/01/11 15:37:29 | 00,600,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/01/11 15:37:29 | 00,503,576 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/01/11 15:37:28 | 00,702,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/01/11 15:37:16 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/01/11 15:37:14 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/01/11 15:37:10 | 00,745,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgscanx.exe
PRC - [2009/11/12 16:33:10 | 00,141,600 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2009/11/12 16:33:00 | 00,545,568 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/11/10 10:28:08 | 00,112,592 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
PRC - [2009/10/11 04:17:36 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/10/11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/09/29 18:08:50 | 00,602,112 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS.1\system32\ati2evxx.exe
PRC - [2009/06/05 10:48:14 | 00,144,712 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/04/10 12:38:16 | 17,879,552 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS.1\RTHDCPL.EXE
PRC - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/11/09 13:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/07/03 02:38:24 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.1\explorer.exe
PRC - [2008/05/01 23:15:46 | 00,015,872 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2007/10/12 08:34:56 | 00,071,096 | ---- | M] () -- C:\Program Files\Super_DVD_Creator_9.8\NMSAccessU.exe
PRC - [2007/02/14 12:55:52 | 00,794,624 | R--- | M] (Realtek Semiconductor Corp.) -- C:\Program Files\REALTEK USB Wireless LAN Driver and Utility\RtWLan.exe
PRC - [2004/04/06 09:00:00 | 00,015,360 | ---- | M] () -- C:\Program Files\WinRoll\winroll.exe
========== Modules (SafeList) ========== MOD - [2010/01/21 14:42:29 | 00,547,840 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\My Documents\Downloads\OTL.exe
MOD - [2008/05/01 23:15:36 | 00,004,608 | ---- | M] () -- C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2004/04/06 09:00:00 | 00,008,704 | ---- | M] () -- C:\Program Files\WinRoll\winroll.dll
========== Win32 Services (SafeList) ========== SRV - [2010/01/11 15:37:16 | 00,906,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/01/11 15:37:14 | 00,285,392 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2009/11/12 16:33:00 | 00,545,568 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV - [2009/11/10 10:28:08 | 00,112,592 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2009/11/06 14:29:22 | 01,141,712 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/30 11:18:16 | 00,359,624 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/10/11 04:17:35 | 00,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009/09/29 18:08:50 | 00,602,112 | ---- | M] (ATI Technologies Inc.) [Auto | Running] -- C:\WINDOWS.1\system32\ati2evxx.exe -- (Ati HotKey Poller)
SRV - [2009/06/05 10:48:14 | 00,144,712 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2008/12/12 10:17:38 | 00,238,888 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2008/11/09 13:48:14 | 00,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/10/12 08:34:56 | 00,071,096 | ---- | M] () [Auto | Running] -- C:\Program Files\Super_DVD_Creator_9.8\NMSAccessU.exe -- (NMSAccessU)
SRV - [2004/10/22 03:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT)
========== Driver Services (SafeList) ========== DRV - [2010/01/11 15:38:23 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/01/11 15:38:16 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/01/11 15:38:15 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/01/05 07:56:06 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/01/05 07:56:04 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/01/05 07:56:02 | 00,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009/12/12 20:25:13 | 00,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS.1\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/11/09 11:20:12 | 00,207,792 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS.1\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/09/29 20:18:22 | 03,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009/06/10 05:53:48 | 00,341,376 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/05/02 21:49:16 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2009/04/14 15:09:56 | 05,069,312 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/08/20 10:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS.1\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2008/08/05 19:10:12 | 01,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/14 03:00:00 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/14 03:00:00 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008/04/14 03:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2008/04/14 03:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\rootmdm.sys -- (ROOTMODEM)
DRV - [2008/02/08 08:46:36 | 00,057,408 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\wsimd.sys -- (WSIMD)
DRV - [2007/04/16 18:19:10 | 00,011,776 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/01/18 09:24:58 | 00,026,496 | R--- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\RimSerial.sys -- (RimVSerPort)
DRV - [2006/11/15 15:23:06 | 00,038,144 | R--- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\EAPPkt.sys -- (EAPPkt)
DRV - [2006/02/25 07:13:06 | 00,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\aspi32.sys -- (Aspi32)
DRV - [2006/01/04 14:41:48 | 01,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\Monfilt.sys -- (Monfilt)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\S-1-5-21-1715567821-1580436667-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\S-1-5-21-1715567821-1580436667-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://imagni.deviantart.com/|http://www.tinierme.com/tinierme/html/index2.html|http://twitter.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.1.0014
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.4
FF - prefs.js..extensions.enabledItems: browserhighlighter@ebay.com:1.0.13966
FF - prefs.js..extensions.enabledItems: searchrecs@veoh.com:1.5.1
FF - prefs.js..extensions.enabledItems: web@veoh.com:1.4
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.10.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/01/11 15:37:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/21 15:07:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/21 15:07:53 | 00,000,000 | ---D | M]
[2009/05/02 23:21:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/01/20 21:20:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions
[2009/05/27 22:49:54 | 00,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009/05/28 14:27:40 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/12/12 20:26:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\DTToolbar@toolbarnet.com
[2009/07/26 22:34:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\searchrecs@veoh.com
[2009/12/12 20:25:48 | 00,002,055 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\searchplugins\daemon-search.xml
[2009/05/27 22:50:16 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\searchplugins\winamp-search.xml
[2010/01/20 21:20:47 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/12/24 13:50:46 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/21 14:36:59 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\browserhighlighter@ebay.com
[2008/12/24 13:50:46 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\yahoo_dex@partners.mozilla.com
[2008/09/03 17:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2008/06/17 23:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2007/04/16 10:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/01/10 22:13:53 | 00,000,727 | ---- | M]) - C:\WINDOWS.1\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS.1\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DriverMax] C:\Program Files\Innovative Solutions\DriverMax\devices.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DriverMax_RESTART] C:\Program Files\Innovative Solutions\DriverMax\devices.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exe ()
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] File not found
O4 - HKU\.DEFAULT..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\JMstart.exe File not found
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\REALTEK USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK USB Wireless LAN Driver and Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O4 - Startup: C:\Documents and Settings\Tai\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Tai\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.1\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS.1\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS.1\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\My Documents\My Pictures\Wallpaper Worthy\34e2169bd59e0b6824ad65bf2e78485a.png
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell - "" = AutoRun
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell - "" = AutoRun
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{978b7c70-99a8-11de-ae64-0016448d0bc4}\Shell\AutoRun\command - "" = E:\Customizer.exe -- File not found
O33 - MountPoints2\{978b7c71-99a8-11de-ae64-0016448d0bc4}\Shell\AutoRun\command - "" = E:\mri.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/01/21 02:36:20 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2010/01/19 20:19:56 | 00,000,000 | ---D | C] -- C:\Program Files\Xenorate Codec Pack
[2010/01/18 21:14:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Downloads
[2010/01/14 20:53:52 | 00,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticalrt.dll
[2010/01/14 20:53:51 | 03,227,648 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticaldd.dll
[2010/01/14 20:53:51 | 00,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticalcl.dll
[2010/01/14 20:27:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\My Drivers
[2010/01/14 15:03:40 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2010/01/14 04:19:50 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010/01/14 04:19:46 | 00,000,000 | ---D | C] -- C:\rsit
[2010/01/13 16:43:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Disc Stuff
[2010/01/11 15:38:46 | 00,000,000 | -H-D | C] -- C:\$AVG
[2010/01/11 15:38:25 | 00,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\avgrsstx.dll
[2010/01/11 15:38:23 | 00,360,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgtdix.sys
[2010/01/11 15:38:16 | 00,333,192 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgldx86.sys
[2010/01/11 15:38:15 | 00,028,424 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgmfx86.sys
[2010/01/11 15:37:40 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\drivers\Avg
[2010/01/11 15:37:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\avg9
[2010/01/11 15:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/01/11 15:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/11 15:32:16 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/01/11 15:32:16 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\My Drivers
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\Innovative Solutions
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Innovative Solutions
[2010/01/11 15:30:10 | 00,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2010/01/10 23:47:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\SUPERAntiSpyware.com
[2010/01/10 23:47:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2010/01/10 23:47:16 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/01/10 22:38:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\DoctorWeb
[2010/01/10 22:24:51 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Desktop\First Aid
[2010/01/10 22:13:30 | 00,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2010/01/10 21:42:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/01/10 21:42:31 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbamswissarmy.sys
[2010/01/10 21:42:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\Malwarebytes
[2010/01/10 21:42:24 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbam.sys
[2010/01/10 21:36:30 | 00,000,000 | ---D | C] -- C:\Program Files\xerox
[2010/01/10 21:36:29 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\xircom
[2010/01/10 21:36:29 | 00,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010/01/10 21:31:31 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\NtmsData
[2010/01/10 20:28:01 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\Videos
[2010/01/10 16:35:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\ImgBurn
[2010/01/10 16:06:40 | 00,000,000 | ---D | C] -- C:\Program Files\AC3Filter
[2010/01/10 15:30:18 | 00,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS.1\SGDetectionTool.dll
[2010/01/10 15:30:16 | 01,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS.1\PCTBDCore.dll
[2010/01/10 15:30:16 | 00,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS.1\PCTBDRes.dll
[2010/01/10 15:21:44 | 00,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\pctgntdi.sys
[2010/01/10 15:21:11 | 00,207,792 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\PCTCore.sys
[2010/01/10 15:21:11 | 00,087,784 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\PCTAppEvent.sys
[2010/01/10 15:20:50 | 00,070,408 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\pctplsg.sys
[2010/01/10 15:20:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\PC Tools
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PC Tools
[2010/01/10 15:20:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP
[2010/01/10 13:59:15 | 00,000,000 | ---D | C] -- C:\DVDTemp
[2010/01/10 13:59:00 | 00,000,000 | ---D | C] -- C:\Program Files\Super_DVD_Creator_9.8
[2010/01/10 04:04:39 | 00,000,000 | ---D | C] -- C:\divx2dvd
[2010/01/10 02:33:02 | 00,000,000 | ---D | C] -- C:\Program Files\Easy DVD Creator
[2009/12/25 17:11:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Documents\DAEMON Tools Images
[2009/05/28 07:09:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
========== Files - Modified Within 30 Days ========== [2010/01/21 14:09:33 | 54,461,828 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\incavi.avm
[2010/01/21 02:18:08 | 00,061,652 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\soldier boys.rtf
[2010/01/20 23:13:49 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\prvlcl.dat
[2010/01/19 20:46:03 | 05,242,880 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/01/19 18:56:50 | 00,142,495 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\microavi.avg
[2010/01/19 14:40:36 | 00,001,565 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\Orbit.lnk
[2010/01/19 14:39:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS.1\tasks\SA.DAT
[2010/01/19 14:39:01 | 00,002,048 | --S- | M] () -- C:\WINDOWS.1\bootstat.dat
[2010/01/19 14:37:10 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/01/18 00:48:31 | 00,003,809 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\draft.rtf
[2010/01/17 12:33:13 | 00,002,206 | ---- | M] () -- C:\WINDOWS.1\System32\wpa.dbl
[2010/01/17 02:16:00 | 00,000,354 | ---- | M] () -- C:\WINDOWS.1\tasks\Driver Robot.job
[2010/01/14 23:13:41 | 07,670,930 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Hello Cloud.flv
[2010/01/14 22:28:22 | 50,161,454 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Zack & Cloud - Time of Dying.mp4
[2010/01/14 20:24:05 | 04,235,754 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/01/14 17:21:48 | 06,061,540 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\avi7.avg
[2010/01/14 17:21:48 | 00,492,629 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\miniavi.avg
[2010/01/14 15:03:41 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2010/01/14 15:02:09 | 41,411,89120 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Backup Jan 2010.bkf
[2010/01/14 08:09:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS.1\tasks\AppleSoftwareUpdate.job
[2010/01/14 04:16:03 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\RSIT(2).exe
[2010/01/14 03:51:30 | 00,046,822 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\13542_208080167060_648607060_3698511_10380_n.jpg
[2010/01/14 02:49:42 | 00,128,512 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/13 14:22:27 | 00,007,728 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\copy.rtf
[2010/01/11 15:38:25 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\avgrsstx.dll
[2010/01/11 15:38:23 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgtdix.sys
[2010/01/11 15:38:16 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgldx86.sys
[2010/01/11 15:38:15 | 00,113,461 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\iavichjw.avm
[2010/01/11 15:38:15 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgmfx86.sys
[2010/01/11 01:11:39 | 00,000,664 | ---- | M] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2010/01/10 13:59:19 | 00,000,822 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk
[2010/01/10 02:33:09 | 00,000,067 | ---- | M] () -- C:\WINDOWS.1\Easy DVD Creator.INI
[2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbam.sys
[2009/12/29 00:03:39 | 00,000,694 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Quick Screen Capture.lnk
========== Files Created - No Company Name ========== [2010/01/18 21:00:38 | 00,061,652 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\soldier boys.rtf
[2010/01/18 00:20:07 | 00,003,809 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\draft.rtf
[2010/01/15 01:39:40 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\prvlcl.dat
[2010/01/14 23:10:49 | 07,670,930 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Hello Cloud.flv
[2010/01/14 22:18:18 | 50,161,454 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Zack & Cloud - Time of Dying.mp4
[2010/01/14 14:47:37 | 41,411,89120 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Backup Jan 2010.bkf
[2010/01/14 04:16:02 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\RSIT(2).exe
[2010/01/14 03:51:28 | 00,046,822 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\13542_208080167060_648607060_3698511_10380_n.jpg
[2010/01/13 14:22:27 | 00,007,728 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\copy.rtf
[2010/01/11 15:38:15 | 00,113,461 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\iavichjw.avm
[2010/01/11 15:37:43 | 54,461,828 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\incavi.avm
[2010/01/11 15:37:42 | 00,492,629 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\miniavi.avg
[2010/01/11 15:37:42 | 00,142,495 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\microavi.avg
[2010/01/11 15:37:40 | 06,061,540 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\avi7.avg
[2010/01/11 14:46:36 | 00,000,354 | ---- | C] () -- C:\WINDOWS.1\tasks\Driver Robot.job
[2010/01/11 01:11:39 | 00,000,664 | ---- | C] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2010/01/10 16:07:52 | 00,380,928 | ---- | C] () -- C:\WINDOWS.1\System32\ac3filter.acm
[2010/01/10 15:30:19 | 00,767,952 | ---- | C] () -- C:\WINDOWS.1\BDTSupport.dll
[2010/01/10 15:30:18 | 01,152,444 | ---- | C] () -- C:\WINDOWS.1\UDB.zip
[2010/01/10 15:30:18 | 00,000,882 | ---- | C] () -- C:\WINDOWS.1\RegSDImport.xml
[2010/01/10 15:30:18 | 00,000,880 | ---- | C] () -- C:\WINDOWS.1\RegISSImport.xml
[2010/01/10 15:30:18 | 00,000,131 | ---- | C] () -- C:\WINDOWS.1\IDB.zip
[2010/01/10 15:21:44 | 00,007,387 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctgntdi.cat
[2010/01/10 15:21:11 | 00,007,412 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\PCTAppEvent.cat
[2010/01/10 15:21:11 | 00,007,383 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctcore.cat
[2010/01/10 15:20:50 | 00,007,383 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctplsg.cat
[2010/01/10 13:59:19 | 00,000,822 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk
[2010/01/10 02:33:07 | 00,000,067 | ---- | C] () -- C:\WINDOWS.1\Easy DVD Creator.INI
[2009/12/29 00:03:39 | 00,000,694 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Quick Screen Capture.lnk
[2009/12/16 02:46:44 | 00,000,000 | ---- | C] () -- C:\WINDOWS.1\ToDisc.INI
[2009/12/12 20:25:13 | 00,691,696 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\sptd.sys
[2009/07/26 22:34:30 | 00,323,584 | ---- | C] () -- C:\WINDOWS.1\System32\FoxImager.dll
[2009/07/01 04:23:01 | 00,012,288 | ---- | C] () -- C:\WINDOWS.1\impborl.dll
[2009/06/23 21:16:28 | 00,000,754 | ---- | C] () -- C:\WINDOWS.1\WORDPAD.INI
[2009/05/05 19:46:40 | 00,001,300 | ---- | C] () -- C:\WINDOWS.1\System32\cool.dll
[2009/05/03 17:21:14 | 00,128,512 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/02 21:28:41 | 00,164,352 | ---- | C] () -- C:\WINDOWS.1\System32\unrar.dll
[2009/05/02 21:28:41 | 00,000,038 | ---- | C] () -- C:\WINDOWS.1\avisplitter.ini
[2009/05/02 21:28:38 | 03,596,288 | ---- | C] () -- C:\WINDOWS.1\System32\qt-dx331.dll
[2009/05/02 21:28:37 | 00,057,344 | ---- | C] () -- C:\WINDOWS.1\System32\ff_vfw.dll
[2009/05/02 21:28:37 | 00,000,547 | ---- | C] () -- C:\WINDOWS.1\System32\ff_vfw.dll.manifest
[2008/04/14 03:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS.1\System32\CopyToSendTo.dll
[2003/09/23 05:40:34 | 00,394,240 | ---- | C] () -- C:\WINDOWS.1\System32\HMTCD.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP:A8ADE5D8
< End of report >
DRV - [2010/01/11 15:38:23 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/01/11 15:38:16 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/01/11 15:38:15 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS.1\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010/01/05 07:56:06 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/01/05 07:56:04 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/01/05 07:56:02 | 00,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009/12/12 20:25:13 | 00,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS.1\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/11/09 11:20:12 | 00,207,792 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\WINDOWS.1\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/09/29 20:18:22 | 03,565,056 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009/06/10 05:53:48 | 00,341,376 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2009/05/18 14:17:00 | 00,026,600 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2009/05/02 21:49:16 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2009/04/14 15:09:56 | 05,069,312 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/08/20 10:58:58 | 00,044,944 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS.1\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2008/08/05 19:10:12 | 01,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/14 03:00:00 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/14 03:00:00 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2008/04/14 03:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2008/04/14 03:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\rootmdm.sys -- (ROOTMODEM)
DRV - [2008/02/08 08:46:36 | 00,057,408 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\wsimd.sys -- (WSIMD)
DRV - [2007/04/16 18:19:10 | 00,011,776 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/01/18 09:24:58 | 00,026,496 | R--- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\RimSerial.sys -- (RimVSerPort)
DRV - [2006/11/15 15:23:06 | 00,038,144 | R--- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\EAPPkt.sys -- (EAPPkt)
DRV - [2006/02/25 07:13:06 | 00,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS.1\system32\drivers\aspi32.sys -- (Aspi32)
DRV - [2006/01/04 14:41:48 | 01,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\Monfilt.sys -- (Monfilt)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comIE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\S-1-5-21-1715567821-1580436667-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\S-1-5-21-1715567821-1580436667-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://imagni.deviantart.com/|http://www.tinierme.com/tinierme/html/index2.html|http://twitter.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.1.0014
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.4
FF - prefs.js..extensions.enabledItems: browserhighlighter@ebay.com:1.0.13966
FF - prefs.js..extensions.enabledItems: searchrecs@veoh.com:1.5.1
FF - prefs.js..extensions.enabledItems: web@veoh.com:1.4
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.10.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.2.20080910
FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/01/11 15:37:07 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/21 15:07:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/21 15:07:53 | 00,000,000 | ---D | M]
[2009/05/02 23:21:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/01/20 21:20:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions
[2009/05/27 22:49:54 | 00,000,000 | ---D | M] (Winamp Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2009/05/28 14:27:40 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/12/12 20:26:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\DTToolbar@toolbarnet.com
[2009/07/26 22:34:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\extensions\searchrecs@veoh.com
[2009/12/12 20:25:48 | 00,002,055 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\searchplugins\daemon-search.xml
[2009/05/27 22:50:16 | 00,001,196 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\6r0sgxfg.default\searchplugins\winamp-search.xml
[2010/01/20 21:20:47 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/12/24 13:50:46 | 00,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/21 14:36:59 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\browserhighlighter@ebay.com
[2008/12/24 13:50:46 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\yahoo_dex@partners.mozilla.com
[2008/09/03 17:11:24 | 00,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2008/06/17 23:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2007/04/16 10:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: ([2010/01/10 22:13:53 | 00,000,727 | ---- | M]) - C:\WINDOWS.1\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] C:\WINDOWS.1\RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DriverMax] C:\Program Files\Innovative Solutions\DriverMax\devices.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [DriverMax_RESTART] C:\Program Files\Innovative Solutions\DriverMax\devices.exe (Innovative Solutions)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exe ()
O4 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] File not found
O4 - HKU\.DEFAULT..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [_nltide_3] C:\WINDOWS.1\System32\advpack.dll (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk = C:\Documents and Settings\Administrator\Local Settings\Temp\JMstart.exe File not found
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\REALTEK USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK USB Wireless LAN Driver and Utility\RtWLan.exe (Realtek Semiconductor Corp.)
O4 - Startup: C:\Documents and Settings\Tai\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Tai\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.1\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS.1\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS.1\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\My Documents\My Pictures\Wallpaper Worthy\34e2169bd59e0b6824ad65bf2e78485a.png
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell - "" = AutoRun
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{218c255a-d96e-11de-ae69-0016448d0bc4}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell - "" = AutoRun
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{566c0db0-850b-11de-ae5e-0016448d0bc4}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -- File not found
O33 - MountPoints2\{978b7c70-99a8-11de-ae64-0016448d0bc4}\Shell\AutoRun\command - "" = E:\Customizer.exe -- File not found
O33 - MountPoints2\{978b7c71-99a8-11de-ae64-0016448d0bc4}\Shell\AutoRun\command - "" = E:\mri.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/01/21 02:36:20 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Administrator\Recent
[2010/01/19 20:19:56 | 00,000,000 | ---D | C] -- C:\Program Files\Xenorate Codec Pack
[2010/01/18 21:14:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Downloads
[2010/01/14 20:53:52 | 00,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticalrt.dll
[2010/01/14 20:53:51 | 03,227,648 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticaldd.dll
[2010/01/14 20:53:51 | 00,045,056 | ---- | C] (Advanced Micro Devices Inc.) -- C:\WINDOWS.1\System32\aticalcl.dll
[2010/01/14 20:27:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\My Drivers
[2010/01/14 15:03:40 | 00,472,064 | ---- | C] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2010/01/14 04:19:50 | 00,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010/01/14 04:19:46 | 00,000,000 | ---D | C] -- C:\rsit
[2010/01/13 16:43:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\Disc Stuff
[2010/01/11 15:38:46 | 00,000,000 | -H-D | C] -- C:\$AVG
[2010/01/11 15:38:25 | 00,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\avgrsstx.dll
[2010/01/11 15:38:23 | 00,360,584 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgtdix.sys
[2010/01/11 15:38:16 | 00,333,192 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgldx86.sys
[2010/01/11 15:38:15 | 00,028,424 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgmfx86.sys
[2010/01/11 15:37:40 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\drivers\Avg
[2010/01/11 15:37:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\avg9
[2010/01/11 15:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/01/11 15:32:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/11 15:32:16 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/01/11 15:32:16 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\My Drivers
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\Innovative Solutions
[2010/01/11 15:30:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Innovative Solutions
[2010/01/11 15:30:10 | 00,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2010/01/10 23:47:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\SUPERAntiSpyware.com
[2010/01/10 23:47:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
[2010/01/10 23:47:16 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/01/10 22:38:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\DoctorWeb
[2010/01/10 22:24:51 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Desktop\First Aid
[2010/01/10 22:13:30 | 00,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2010/01/10 21:42:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/01/10 21:42:31 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbamswissarmy.sys
[2010/01/10 21:42:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\Malwarebytes
[2010/01/10 21:42:24 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbam.sys
[2010/01/10 21:36:30 | 00,000,000 | ---D | C] -- C:\Program Files\xerox
[2010/01/10 21:36:29 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\xircom
[2010/01/10 21:36:29 | 00,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2010/01/10 21:31:31 | 00,000,000 | ---D | C] -- C:\WINDOWS.1\System32\NtmsData
[2010/01/10 20:28:01 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\My Documents\Videos
[2010/01/10 16:35:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\ImgBurn
[2010/01/10 16:06:40 | 00,000,000 | ---D | C] -- C:\Program Files\AC3Filter
[2010/01/10 15:30:18 | 00,149,456 | ---- | C] (PC Tools) -- C:\WINDOWS.1\SGDetectionTool.dll
[2010/01/10 15:30:16 | 01,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS.1\PCTBDCore.dll
[2010/01/10 15:30:16 | 00,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\WINDOWS.1\PCTBDRes.dll
[2010/01/10 15:21:44 | 00,233,136 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\pctgntdi.sys
[2010/01/10 15:21:11 | 00,207,792 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\PCTCore.sys
[2010/01/10 15:21:11 | 00,087,784 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\PCTAppEvent.sys
[2010/01/10 15:20:50 | 00,070,408 | ---- | C] (PC Tools) -- C:\WINDOWS.1\System32\drivers\pctplsg.sys
[2010/01/10 15:20:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\PC Tools
[2010/01/10 15:20:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PC Tools
[2010/01/10 15:20:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP
[2010/01/10 13:59:15 | 00,000,000 | ---D | C] -- C:\DVDTemp
[2010/01/10 13:59:00 | 00,000,000 | ---D | C] -- C:\Program Files\Super_DVD_Creator_9.8
[2010/01/10 04:04:39 | 00,000,000 | ---D | C] -- C:\divx2dvd
[2010/01/10 02:33:02 | 00,000,000 | ---D | C] -- C:\Program Files\Easy DVD Creator
[2009/12/25 17:11:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Documents\DAEMON Tools Images
[2009/05/28 07:09:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
========== Files - Modified Within 30 Days ========== [2010/01/21 14:09:33 | 54,461,828 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\incavi.avm
[2010/01/21 02:18:08 | 00,061,652 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\soldier boys.rtf
[2010/01/20 23:13:49 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\prvlcl.dat
[2010/01/19 20:46:03 | 05,242,880 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/01/19 18:56:50 | 00,142,495 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\microavi.avg
[2010/01/19 14:40:36 | 00,001,565 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Startup\Orbit.lnk
[2010/01/19 14:39:05 | 00,000,006 | -H-- | M] () -- C:\WINDOWS.1\tasks\SA.DAT
[2010/01/19 14:39:01 | 00,002,048 | --S- | M] () -- C:\WINDOWS.1\bootstat.dat
[2010/01/19 14:37:10 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/01/18 00:48:31 | 00,003,809 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\draft.rtf
[2010/01/17 12:33:13 | 00,002,206 | ---- | M] () -- C:\WINDOWS.1\System32\wpa.dbl
[2010/01/17 02:16:00 | 00,000,354 | ---- | M] () -- C:\WINDOWS.1\tasks\Driver Robot.job
[2010/01/14 23:13:41 | 07,670,930 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Hello Cloud.flv
[2010/01/14 22:28:22 | 50,161,454 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Zack & Cloud - Time of Dying.mp4
[2010/01/14 20:24:05 | 04,235,754 | -H-- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/01/14 17:21:48 | 06,061,540 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\avi7.avg
[2010/01/14 17:21:48 | 00,492,629 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\miniavi.avg
[2010/01/14 15:03:41 | 00,472,064 | ---- | M] ( ) -- C:\Documents and Settings\Administrator\Desktop\RootRepeal.exe
[2010/01/14 15:02:09 | 41,411,89120 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Backup Jan 2010.bkf
[2010/01/14 08:09:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS.1\tasks\AppleSoftwareUpdate.job
[2010/01/14 04:16:03 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\RSIT(2).exe
[2010/01/14 03:51:30 | 00,046,822 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\13542_208080167060_648607060_3698511_10380_n.jpg
[2010/01/14 02:49:42 | 00,128,512 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/13 14:22:27 | 00,007,728 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\copy.rtf
[2010/01/11 15:38:25 | 00,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\avgrsstx.dll
[2010/01/11 15:38:23 | 00,360,584 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgtdix.sys
[2010/01/11 15:38:16 | 00,333,192 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgldx86.sys
[2010/01/11 15:38:15 | 00,113,461 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\Avg\iavichjw.avm
[2010/01/11 15:38:15 | 00,028,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS.1\System32\drivers\avgmfx86.sys
[2010/01/11 01:11:39 | 00,000,664 | ---- | M] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2010/01/10 13:59:19 | 00,000,822 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk
[2010/01/10 02:33:09 | 00,000,067 | ---- | M] () -- C:\WINDOWS.1\Easy DVD Creator.INI
[2010/01/07 16:07:14 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS.1\System32\drivers\mbam.sys
[2009/12/29 00:03:39 | 00,000,694 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Quick Screen Capture.lnk
========== Files Created - No Company Name ========== [2010/01/18 21:00:38 | 00,061,652 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\soldier boys.rtf
[2010/01/18 00:20:07 | 00,003,809 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\draft.rtf
[2010/01/15 01:39:40 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\prvlcl.dat
[2010/01/14 23:10:49 | 07,670,930 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Hello Cloud.flv
[2010/01/14 22:18:18 | 50,161,454 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\YouTube - Zack & Cloud - Time of Dying.mp4
[2010/01/14 14:47:37 | 41,411,89120 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Backup Jan 2010.bkf
[2010/01/14 04:16:02 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\RSIT(2).exe
[2010/01/14 03:51:28 | 00,046,822 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\13542_208080167060_648607060_3698511_10380_n.jpg
[2010/01/13 14:22:27 | 00,007,728 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\copy.rtf
[2010/01/11 15:38:15 | 00,113,461 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\iavichjw.avm
[2010/01/11 15:37:43 | 54,461,828 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\incavi.avm
[2010/01/11 15:37:42 | 00,492,629 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\miniavi.avg
[2010/01/11 15:37:42 | 00,142,495 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\microavi.avg
[2010/01/11 15:37:40 | 06,061,540 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\Avg\avi7.avg
[2010/01/11 14:46:36 | 00,000,354 | ---- | C] () -- C:\WINDOWS.1\tasks\Driver Robot.job
[2010/01/11 01:11:39 | 00,000,664 | ---- | C] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2010/01/10 16:07:52 | 00,380,928 | ---- | C] () -- C:\WINDOWS.1\System32\ac3filter.acm
[2010/01/10 15:30:19 | 00,767,952 | ---- | C] () -- C:\WINDOWS.1\BDTSupport.dll
[2010/01/10 15:30:18 | 01,152,444 | ---- | C] () -- C:\WINDOWS.1\UDB.zip
[2010/01/10 15:30:18 | 00,000,882 | ---- | C] () -- C:\WINDOWS.1\RegSDImport.xml
[2010/01/10 15:30:18 | 00,000,880 | ---- | C] () -- C:\WINDOWS.1\RegISSImport.xml
[2010/01/10 15:30:18 | 00,000,131 | ---- | C] () -- C:\WINDOWS.1\IDB.zip
[2010/01/10 15:21:44 | 00,007,387 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctgntdi.cat
[2010/01/10 15:21:11 | 00,007,412 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\PCTAppEvent.cat
[2010/01/10 15:21:11 | 00,007,383 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctcore.cat
[2010/01/10 15:20:50 | 00,007,383 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\pctplsg.cat
[2010/01/10 13:59:19 | 00,000,822 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Windows Login.lnk
[2010/01/10 02:33:07 | 00,000,067 | ---- | C] () -- C:\WINDOWS.1\Easy DVD Creator.INI
[2009/12/29 00:03:39 | 00,000,694 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Quick Screen Capture.lnk
[2009/12/16 02:46:44 | 00,000,000 | ---- | C] () -- C:\WINDOWS.1\ToDisc.INI
[2009/12/12 20:25:13 | 00,691,696 | ---- | C] () -- C:\WINDOWS.1\System32\drivers\sptd.sys
[2009/07/26 22:34:30 | 00,323,584 | ---- | C] () -- C:\WINDOWS.1\System32\FoxImager.dll
[2009/07/01 04:23:01 | 00,012,288 | ---- | C] () -- C:\WINDOWS.1\impborl.dll
[2009/06/23 21:16:28 | 00,000,754 | ---- | C] () -- C:\WINDOWS.1\WORDPAD.INI
[2009/05/05 19:46:40 | 00,001,300 | ---- | C] () -- C:\WINDOWS.1\System32\cool.dll
[2009/05/03 17:21:14 | 00,128,512 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/02 21:28:41 | 00,164,352 | ---- | C] () -- C:\WINDOWS.1\System32\unrar.dll
[2009/05/02 21:28:41 | 00,000,038 | ---- | C] () -- C:\WINDOWS.1\avisplitter.ini
[2009/05/02 21:28:38 | 03,596,288 | ---- | C] () -- C:\WINDOWS.1\System32\qt-dx331.dll
[2009/05/02 21:28:37 | 00,057,344 | ---- | C] () -- C:\WINDOWS.1\System32\ff_vfw.dll
[2009/05/02 21:28:37 | 00,000,547 | ---- | C] () -- C:\WINDOWS.1\System32\ff_vfw.dll.manifest
[2008/04/14 03:00:00 | 00,061,440 | ---- | C] () -- C:\WINDOWS.1\System32\CopyToSendTo.dll
[2003/09/23 05:40:34 | 00,394,240 | ---- | C] () -- C:\WINDOWS.1\System32\HMTCD.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 201 bytes -> C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users.WINDOWS.1\Application Data\TEMP:A8ADE5D8
< End of report >
OTL Extras logfile created on: 1/21/2010 3:17:23 PM - Run 1
OTL by OldTimer - Version 3.1.25.3 Folder = C:\Documents and Settings\Administrator\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.1 | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 25.23 Gb Free Space | 17.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: TAIBOX
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Users\Administrator\My Documents\Flele\ssp.exe" = C:\Users\Administrator\My Documents\Flele\ssp.exe:*:Enabled:SSP -- File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager -- (Electronic Arts)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player -- (Veoh Networks)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Internet Explorer\IEXPLORE.EXE" = C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Users\Administrator\My Documents\VLC\vlc.exe" = C:\Users\Administrator\My Documents\VLC\vlc.exe:*:Enabled:VLC media player -- File not found
"C:\Users\Administrator\Local Settings\Temp\dologin.exe" = C:\Users\Administrator\Local Settings\Temp\dologin.exe:*:Enabled:DoLoginStart -- File not found
"C:\Users\Administrator\Local Settings\Temp\JMstart.exe" = C:\Users\Administrator\Local Settings\Temp\JMstart.exe:*:Enabled:JMstart -- File not found
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7095FD27-37F0-4750-9DE8-D37DC0043706}" = REALTEK RTL8187B Wireless LAN Driver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = Realtek WLAN driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BE686891-3C56-4714-AFEF-341A7867BA80}" = REALTEK USB Wireless LAN Driver and Utility
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALShow_is1" = ALShow
"ALUpdate_is1" = ALTools Update
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG Free 9.0
"AviSynth" = AviSynth 2.5
"Browser Defender_is1" = Browser Defender 2.0.6.11
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DMX5_is1" = DriverMax 5
"EADM" = EA Download Manager
"ffdshow" = ffdshow (remove only)
"HijackThis" = HijackThis 2.0.2
"ImgBurn" = ImgBurn
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.4.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Orbit_is1" = Orbit Downloader
"Quick Screen Capture 3.0_is1" = Quick Screen Capture 3.0
"Spyware Doctor" = Spyware Doctor 7.0
"SumatraPDF" = SumatraPDF
"Super DVD Creator_is1" = Super DVD Creator 9.8 Full Version
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/14/2009 5:52:47 PM | Computer Name = TAIBOX | Source = MsiInstaller | ID = 11101
Description =
[ System Events ]
Error - 1/11/2010 2:57:29 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/11/2010 2:57:48 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/11/2010 4:34:29 PM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 2:18:06 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 2:18:29 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 2:32:37 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 2:33:00 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 7:02:24 PM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 7:02:49 PM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/21/2010 5:02:40 PM | Computer Name = TAIBOX | Source = PSched | ID = 14103
Description = QoS [Adapter {2614BE59-EBF7-4AE1-8165-166CF43F8E4E}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
< End of report >
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
"DisableUnicastResponsesToMulticastBroadcast" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"C:\Users\Administrator\My Documents\Flele\ssp.exe" = C:\Users\Administrator\My Documents\Flele\ssp.exe:*:Enabled:SSP -- File not found
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)
"C:\Program Files\Electronic Arts\EADM\Core.exe" = C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager -- (Electronic Arts)
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" = C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player -- (Veoh Networks)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit -- (Orbitdownloader.com)
"C:\Program Files\Internet Explorer\IEXPLORE.EXE" = C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer -- (Microsoft Corporation)
"C:\Users\Administrator\My Documents\VLC\vlc.exe" = C:\Users\Administrator\My Documents\VLC\vlc.exe:*:Enabled:VLC media player -- File not found
"C:\Users\Administrator\Local Settings\Temp\dologin.exe" = C:\Users\Administrator\Local Settings\Temp\dologin.exe:*:Enabled:DoLoginStart -- File not found
"C:\Users\Administrator\Local Settings\Temp\JMstart.exe" = C:\Users\Administrator\Local Settings\Temp\JMstart.exe:*:Enabled:JMstart -- File not found
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03CE1BCB-03F5-4C6A-B37E-69799AA3C544}" = SpyHunter
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java 6 Update 17
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7095FD27-37F0-4750-9DE8-D37DC0043706}" = REALTEK RTL8187B Wireless LAN Driver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{895722FE-25FE-4854-95AC-B0C42F9DBEDA}" = Realtek WLAN driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}" = iTunes
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BE686891-3C56-4714-AFEF-341A7867BA80}" = REALTEK USB Wireless LAN Driver and Utility
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"AC3Filter" = AC3Filter (remove only)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALShow_is1" = ALShow
"ALUpdate_is1" = ALTools Update
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG Free 9.0
"AviSynth" = AviSynth 2.5
"Browser Defender_is1" = Browser Defender 2.0.6.11
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DMX5_is1" = DriverMax 5
"EADM" = EA Download Manager
"ffdshow" = ffdshow (remove only)
"HijackThis" = HijackThis 2.0.2
"ImgBurn" = ImgBurn
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.4.2
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Orbit_is1" = Orbit Downloader
"Quick Screen Capture 3.0_is1" = Quick Screen Capture 3.0
"Spyware Doctor" = Spyware Doctor 7.0
"SumatraPDF" = SumatraPDF
"Super DVD Creator_is1" = Super DVD Creator 9.8 Full Version
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1715567821-1580436667-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 7/14/2009 5:52:47 PM | Computer Name = TAIBOX | Source = MsiInstaller | ID = 11101
Description =
[ System Events ]
Error - 1/11/2010 2:57:29 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/11/2010 2:57:48 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/11/2010 4:34:29 PM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 2:18:06 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 2:18:29 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 2:32:37 AM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 2:33:00 AM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/12/2010 7:02:24 PM | Computer Name = TAIBOX | Source = sptd | ID = 262148
Description = Driver detected an internal error in its data structures for .
Error - 1/12/2010 7:02:49 PM | Computer Name = TAIBOX | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 1/21/2010 5:02:40 PM | Computer Name = TAIBOX | Source = PSched | ID = 14103
Description = QoS [Adapter {2614BE59-EBF7-4AE1-8165-166CF43F8E4E}]: The netcard driver
failed the query for OID_GEN_LINK_SPEED.
< End of report >
Thank you for taking the time to help me!