Am i clean?

  1. #1
    smilliebob is offline Newbie

    Am i clean?

    GMER 1.0.15.15530 - GMER - Rootkit Detector and Remover
    Rootkit scan 2010-11-27 10:05:31
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5 WDC_WD2500JS-55NCB1 rev.10.02E01
    Running: i23g0pe6.exe; Driver: C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\ffwyraow.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xABFAA6C0]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xABFAA770]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xABFAA810]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xABFAA8B0]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF65A3000, 0x1A3F84, 0xE8000020]
    init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF64D4900]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\SearchIndexer.exe[480] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

    Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ins taller\UserData\S-1-5-18\Products\00002109A10090400000000000F01FEC\Usage @OutlookMAPI2Intl_1033 1031405629
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\kIqew@ NxYR\syojbboe?GZKMf{ILv`
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\Rwglgxoap@ Yymv{NymNUYcH}qtTJEGOE{tdC\
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\yaebzhd@ ysZGTQhPaX`|XO\QgeYCSCukVY[hd

    ---- EOF - GMER 1.0.15 ----
    Attached Files

  2. #2
    broni is offline Senior Member
    Welcome aboard

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.


    All logs have to be pasted.

  3. #3
    smilliebob is offline Newbie
    GMER 1.0.15.15530 - GMER - Rootkit Detector and Remover
    Rootkit scan 2010-11-27 10:05:31
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-5 WDC_WD2500JS-55NCB1 rev.10.02E01
    Running: i23g0pe6.exe; Driver: C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\ffwyraow.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xABFAA6C0]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xABFAA770]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xABFAA810]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xABFAA8B0]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF65A3000, 0x1A3F84, 0xE8000020]
    init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF64D4900]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\SearchIndexer.exe[480] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

    Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ins taller\UserData\S-1-5-18\Products\00002109A10090400000000000F01FEC\Usage @OutlookMAPI2Intl_1033 1031405629
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\kIqew@ NxYR\syojbboe?GZKMf{ILv`
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\Rwglgxoap@ Yymv{NymNUYcH}qtTJEGOE{tdC\
    Reg HKLM\SOFTWARE\Classes\CLSID\{CAF9FB67-43D3-E485-2E8D-2D6C0E4B9F7D}\yaebzhd@ ysZGTQhPaX`|XO\QgeYCSCukVY[hd

    ---- EOF - GMER 1.0.15 ----


    Malwarebytes' Anti-Malware 1.46
    Malwarebytes

    Database version: 5193

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    26/11/2010 16:43:51
    mbam-log-2010-11-26 (16-43-51).txt

    Scan type: Quick scan
    Objects scanned: 144741
    Time elapsed: 9 minute(s), 13 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 27
    Files Infected: 19

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\rhcjj6j0eg45 (Rogue.AntiVirusXP) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\StartMenuAllU sers (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Autorun\StartMenuCurr entUser (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\rhcjj6j0eg45\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\StartMenuAllU sers (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Autorun\StartMenuCurr entUser (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\Robert Smillie\Application Data\shcgj6j0eg45\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45 (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.
    C:\Program Files\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge (Spyware.MarketScore) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Program Files\rhcjj6j0eg45\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\rhcjj6j0eg45\rhcjj6j0eg45.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\shcgj6j0eg45\shcgj6j0eg45.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\RelevantKnowledge\rloci.bin (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Program Files\RelevantKnowledge\rlservice.exe (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Program Files\RelevantKnowledge\sporder.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\About RelevantKnowledge.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\Privacy Policy and User License Agreement.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge\Support.lnk (Spyware.MarketScore) -> Quarantined and deleted successfully.

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Home Edition
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000000c

    Kernel Drivers (total 142):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x806FF000 \WINDOWS\system32\hal.dll
    0xF7C23000 \WINDOWS\system32\KDCOM.DLL
    0xF7B33000 \WINDOWS\system32\BOOTVID.dll
    0xF76D4000 ACPI.sys
    0xF7C25000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xF76C3000 pci.sys
    0xF7723000 isapnp.sys
    0xF7733000 ohci1394.sys
    0xF7743000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xF7CEB000 pciide.sys
    0xF79A3000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xF7753000 MountMgr.sys
    0xF76A4000 ftdisk.sys
    0xF79AB000 PartMgr.sys
    0xF7763000 VolSnap.sys
    0xF768C000 atapi.sys
    0xF7773000 disk.sys
    0xF7783000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF766C000 fltmgr.sys
    0xF765A000 sr.sys
    0xF7793000 PxHelp20.sys
    0xF7643000 KSecDD.sys
    0xF7630000 WudfPf.sys
    0xF75A3000 Ntfs.sys
    0xF7576000 NDIS.sys
    0xF755C000 Mup.sys
    0xF79B3000 avgrkx86.sys
    0xF77A3000 AVGIDSEH.Sys
    0xF6B13000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xF65A2000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
    0xF658E000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xF6B03000 \SystemRoot\system32\DRIVERS\serial.sys
    0xF7C0F000 \SystemRoot\system32\DRIVERS\serenum.sys
    0xF7ACB000 \SystemRoot\system32\DRIVERS\fdc.sys
    0xF657A000 \SystemRoot\system32\DRIVERS\parport.sys
    0xF6AF3000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF7803000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xF7813000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xF6557000 \SystemRoot\system32\DRIVERS\ks.sys
    0xF7AD3000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
    0xF6520000 \SystemRoot\system32\drivers\smwdm.sys
    0xF64FC000 \SystemRoot\system32\drivers\portcls.sys
    0xF7833000 \SystemRoot\system32\drivers\drmk.sys
    0xF64DC000 \SystemRoot\system32\drivers\aeaudio.sys
    0xF647C000 \SystemRoot\system32\drivers\senfilt.sys
    0xF7ADB000 \SystemRoot\system32\DRIVERS\usbohci.sys
    0xF6458000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF7AE3000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF6439000 \SystemRoot\system32\DRIVERS\SiSGbeXP.sys
    0xF6405000 \SystemRoot\system32\DRIVERS\HSFHWBS2.sys
    0xF6306000 \SystemRoot\system32\DRIVERS\HSF_DP.sys
    0xF6260000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    0xF7AEB000 \SystemRoot\System32\Drivers\Modem.SYS
    0xF7843000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xF7DC8000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xF78A3000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xF7C17000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xF6249000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xF78B3000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xF78C3000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xF7AFB000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xF6238000 \SystemRoot\system32\DRIVERS\psched.sys
    0xF78D3000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF7B03000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF7B0B000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xF78E3000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF7B13000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xF7B1B000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF7C6F000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xF61DA000 \SystemRoot\system32\DRIVERS\update.sys
    0xF7538000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xF7903000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xF7953000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xF7C7F000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xF7973000 \SystemRoot\system32\DRIVERS\avgmfx86.sys
    0xF7C81000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7D2E000 \SystemRoot\System32\Drivers\Null.SYS
    0xF7C83000 \SystemRoot\System32\Drivers\Beep.SYS
    0xF79C3000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xF79F3000 \SystemRoot\System32\drivers\vga.sys
    0xF7C85000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF7C87000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF79FB000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF7A03000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xF6AB8000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xAE72B000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xAE6D2000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xAE662000 \SystemRoot\system32\DRIVERS\avgtdix.sys
    0xAE63C000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xAE614000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xAE5F2000 \SystemRoot\System32\drivers\afd.sys
    0xF7993000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xAE5C7000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xAE557000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xF77F3000 \SystemRoot\System32\Drivers\Fips.SYS
    0xAE51B000 \SystemRoot\system32\DRIVERS\avgldx86.sys
    0xF7A0B000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xF6B83000 \SystemRoot\system32\drivers\lvusbsta.sys
    0xF7BCB000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0xF7A1B000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0xF7A2B000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
    0xF7BCF000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xF6B73000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xF7BD3000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0xAE4CB000 \SystemRoot\system32\DRIVERS\Camdrl.sys
    0xF6B53000 \SystemRoot\system32\DRIVERS\STREAM.SYS
    0xAE3A0000 \SystemRoot\system32\DRIVERS\lvsvf2.sys
    0xF6B43000 \SystemRoot\system32\drivers\usbaudio.sys
    0xF7BDB000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xF6B23000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xF7823000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xF7863000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xAE248000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xF7CBF000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xAE380000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF7A6B000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF7E1A000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ati2dvag.dll
    0xBF062000 \SystemRoot\System32\ati2cqag.dll
    0xBF0EB000 \SystemRoot\System32\atikvmag.dll
    0xBF158000 \SystemRoot\System32\atiok3x2.dll
    0xBF19B000 \SystemRoot\System32\ati3duag.dll
    0xBF583000 \SystemRoot\System32\ativvaxx.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xAE79E000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
    0xABF24000 \SystemRoot\system32\DRIVERS\mdc8021x.sys
    0xABD73000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xF7C2F000 \SystemRoot\System32\Drivers\ParVdm.SYS
    0xABFA8000 \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
    0xABCA3000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    0xABAB6000 \SystemRoot\system32\drivers\wdmaud.sys
    0xABA5E000 \SystemRoot\system32\DRIVERS\srv.sys
    0xABF88000 \SystemRoot\system32\drivers\sysaudio.sys
    0xAB7D0000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
    0xAB4D8000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
    0xAAD96000 \SystemRoot\System32\Drivers\HTTP.sys
    0xAA4FE000 \??\C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\ffwyraow.sy s
    0xAA343000 \SystemRoot\system32\drivers\kmixer.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 55):
    0 System Idle Process
    4 System
    596 C:\WINDOWS\system32\smss.exe
    628 C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    800 csrss.exe
    844 C:\WINDOWS\system32\winlogon.exe
    892 C:\WINDOWS\system32\services.exe
    916 C:\WINDOWS\system32\lsass.exe
    1084 C:\WINDOWS\system32\ati2evxx.exe
    1104 C:\WINDOWS\system32\svchost.exe
    1176 svchost.exe
    1216 C:\WINDOWS\system32\svchost.exe
    1256 C:\WINDOWS\system32\svchost.exe
    1316 svchost.exe
    1340 svchost.exe
    1388 C:\WINDOWS\system32\spoolsv.exe
    1468 svchost.exe
    1512 C:\WINDOWS\system32\ati2evxx.exe
    1560 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    1652 C:\Program Files\AVG\AVG10\avgwdsvc.exe
    1680 C:\Program Files\Bonjour\mDNSResponder.exe
    1756 C:\Program Files\Java\jre6\bin\jqs.exe
    2000 C:\Program Files\CyberLink\Shared files\RichVideo.exe
    200 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    236 C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
    392 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    440 C:\WINDOWS\system32\svchost.exe
    448 C:\WINDOWS\explorer.exe
    480 C:\WINDOWS\system32\searchindexer.exe
    768 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    1128 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    2132 C:\Program Files\AVG\AVG10\avgam.exe
    2148 C:\Program Files\AVG\AVG10\avgnsx.exe
    2212 C:\Program Files\AVG\AVG10\avgemcx.exe
    2688 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    2736 C:\Program Files\AVG\AVG10\avgtray.exe
    2748 C:\Program Files\iTunes\iTunesHelper.exe
    2800 C:\WINDOWS\system32\ctfmon.exe
    2820 C:\Program Files\Picasa2\PicasaMediaDetector.exe
    2848 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    3028 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
    3476 C:\Program Files\iPod\bin\iPodService.exe
    3640 alg.exe
    580 C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    2540 C:\Program Files\AVG\AVG10\avgcsrvx.exe
    2884 C:\WINDOWS\system32\wuauclt.exe
    2716 C:\Program Files\AVG\AVG10\avgcsrvx.exe
    244 C:\Program Files\Internet Explorer\iexplore.exe
    3112 C:\Program Files\Internet Explorer\iexplore.exe
    3460 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    568 C:\Program Files\Windows Live\Toolbar\wltuser.exe
    3716 C:\Program Files\Internet Explorer\iexplore.exe
    3804 C:\WINDOWS\system32\searchprotocolhost.exe
    728 searchfilterhost.exe
    4424 C:\Documents and Settings\Robert Smillie\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: WDCWD2500JS-55NCB1, Rev: 10.02E01

    Size Device Name MBR Status
    --------------------------------------------
    232 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!


    DDS (Ver_10-11-27.01) - NTFSx86
    Run by Robert Smillie at 10:20:20.15 on 27/11/2010
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.275 [GMT 0:00]

    AV: AVG Anti-Virus 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\Program Files\AVG\AVG10\avgam.exe
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\dds.scr

    ============== Pseudo HJT Report ===============

    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://aol.co.uk/
    uDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe"
    uInternet Settings,ProxyOverride = localhost;*.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Easy Gif Animator Toolbar Helper: {96372ab6-15eb-4316-b497-71c741bc548c} - c:\program files\easy gif animator extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll
    BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    TB: Easy Gif Animator Toolbar: {35065594-9169-4a34-b167-fc4865038e53} - c:\program files\easy gif animator extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; InfoPath.2; .NET CLR 2.0.50727; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.habbo.co.uk/shockwave_client"
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.8.05.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1202746562812
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    DPF: {BE71A78B-77DB-451C-A761-59B37022D544} - hxxp://o.aolcdn.com/pictures/ap/Resources/v2.13/cab/aolpPlugins.10.6.0.8.cab
    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game07.zylom.com/activex/zylomgamesplayer.cab
    DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - hxxps://ukplay.toontown.com/download/sv1.0.32.21/ttinst.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
    DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
    DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
    Hosts: 127.0.0.1 SpywareInfo.com

    ============= SERVICES / DRIVERS ===============

    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGI DSEH.sys [2010-9-13 25680]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 299984]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-11-10 6127184]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssflt r_tdi.sys [2009-5-4 54752]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\driv ers\AVGIDSDriver.sys [2010-8-19 123472]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\driv ers\AVGIDSFilter.sys [2010-8-19 30288]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\ AVGIDSShim.sys [2010-8-19 26192]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-2 136176]
    S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-10-28 517448]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]

    =============== Created Last 30 ================

    2010-11-26 16:31:31 -------- d-----w- c:\docume~1\robert~1\applic~1\Malwarebytes
    2010-11-26 16:31:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-11-26 16:31:19 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-11-26 16:31:16 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-26 16:31:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-11-20 19:00:57 -------- d-----w- c:\program files\iPod
    2010-11-20 19:00:38 -------- d-----w- c:\program files\iTunes
    2010-11-12 17:02:15 -------- d-----w- c:\program files\CCleaner
    2010-11-10 18:22:32 -------- d-----w- c:\docume~1\robert~1\applic~1\Windows Search
    2010-11-06 11:37:34 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
    2010-11-06 0656 -------- d-----w- c:\docume~1\robert~1\applic~1\Windows Desktop Search
    2010-11-06 06:55:44 -------- d-----w- c:\program files\Windows Desktop Search
    2010-11-06 06:55:43 -------- d-----w- c:\windows\system32\GroupPolicy
    2010-11-06 06:53:53 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
    2010-11-06 06:53:52 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
    2010-11-06 06:53:52 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
    2010-11-02 17:16:00 -------- d-----w- c:\docume~1\robert~1\locals~1\applic~1\Temp
    2010-11-02 17:15:07 -------- d-----w- c:\docume~1\robert~1\locals~1\applic~1\OpenCandy
    2010-11-02 17:15:02 -------- d-----w- c:\docume~1\robert~1\applic~1\OpenCandy
    2010-10-31 22:17:01 -------- d-sh--w- c:\windows\ftpcache
    2010-10-30 08:35:48 -------- d-----w- c:\docume~1\robert~1\applic~1\AVG
    2010-10-28 21:44:40 -------- d-----w- c:\docume~1\robert~1\applic~1\AVG10
    2010-10-28 21:42:08 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files
    2010-10-28 21:41:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
    2010-10-28 21:40:35 -------- d-----w- c:\windows\system32\drivers\AVG
    2010-10-28 21:40:35 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
    2010-10-28 21:00:26 -------- d-----w- c:\docume~1\robert~1\applic~1\AVG8

    ==================== Find3M ====================

    2010-09-18 11:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-09-08 10:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-09-08 10:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
    2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys

    ============= FINISH: 10:22:01.34 ===============

  4. #4
    broni is offline Senior Member
    Attach.txt part of DDS log is missing.
    Please, post it.

    Then....

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"

    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AVG Remover to uninstall it: AVG - Download tools
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.pif
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.


    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  5. #5
    smilliebob is offline Newbie
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-11-27.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 09/02/2008 19:59:18
    System Uptime: 26/11/2010 22:32:18 (12 hours ago)

    Motherboard: FUJITSU SIEMENS | | P5SD1-FM2
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Socket 775 | 3000/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 233 GiB total, 191.644 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP719: 29/08/2010 14:59:09 - System Checkpoint
    RP720: 30/08/2010 15:18:17 - System Checkpoint
    RP721: 31/08/2010 16:27:14 - System Checkpoint
    RP722: 01/09/2010 19:41:30 - System Checkpoint
    RP723: 02/09/2010 20:25:57 - System Checkpoint
    RP724: 03/09/2010 21:29:28 - System Checkpoint
    RP725: 04/09/2010 22:50:22 - System Checkpoint
    RP726: 06/09/2010 14:22:10 - System Checkpoint
    RP727: 07/09/2010 16:05:59 - System Checkpoint
    RP728: 08/09/2010 19:27:18 - System Checkpoint
    RP729: 09/09/2010 00:14:43 - Software Distribution Service 3.0
    RP730: 10/09/2010 11:36:08 - System Checkpoint
    RP731: 11/09/2010 20:19:00 - System Checkpoint
    RP732: 13/09/2010 14:55:51 - System Checkpoint
    RP733: 14/09/2010 17:52:36 - System Checkpoint
    RP734: 15/09/2010 18:04:11 - System Checkpoint
    RP735: 15/09/2010 22:47:36 - Software Distribution Service 3.0
    RP736: 16/09/2010 22:48:18 - System Checkpoint
    RP737: 18/09/2010 10:12:06 - System Checkpoint
    RP738: 19/09/2010 15:07:29 - System Checkpoint
    RP739: 20/09/2010 15:16:11 - System Checkpoint
    RP740: 21/09/2010 15:34:55 - System Checkpoint
    RP741: 22/09/2010 15:45:23 - System Checkpoint
    RP742: 23/09/2010 14:40:42 - Avg Update
    RP743: 23/09/2010 14:41:59 - Avg Update
    RP744: 24/09/2010 15:03:34 - System Checkpoint
    RP745: 26/09/2010 14:28:50 - System Checkpoint
    RP746: 27/09/2010 14:45:26 - System Checkpoint
    RP747: 28/09/2010 14:51:59 - System Checkpoint
    RP748: 29/09/2010 17:37:10 - System Checkpoint
    RP749: 30/09/2010 00:24:46 - Software Distribution Service 3.0
    RP750: 01/10/2010 0933 - System Checkpoint
    RP751: 02/10/2010 14:02:08 - System Checkpoint
    RP752: 03/10/2010 15:32:36 - System Checkpoint
    RP753: 04/10/2010 16:06:43 - System Checkpoint
    RP754: 05/10/2010 15:47:14 - Avg Update
    RP755: 06/10/2010 18:36:36 - System Checkpoint
    RP756: 07/10/2010 18:45:12 - System Checkpoint
    RP757: 08/10/2010 19:24:15 - System Checkpoint
    RP758: 09/10/2010 19:05:09 - Software Distribution Service 3.0
    RP759: 10/10/2010 1939 - System Checkpoint
    RP760: 11/10/2010 20:50:39 - System Checkpoint
    RP761: 12/10/2010 21:35:44 - System Checkpoint
    RP762: 13/10/2010 21:30:09 - Software Distribution Service 3.0
    RP763: 15/10/2010 12:26:28 - System Checkpoint
    RP764: 16/10/2010 12:43:59 - System Checkpoint
    RP765: 17/10/2010 14:27:55 - System Checkpoint
    RP766: 18/10/2010 14:53:26 - System Checkpoint
    RP767: 19/10/2010 16:41:23 - System Checkpoint
    RP768: 20/10/2010 17:34:16 - System Checkpoint
    RP769: 21/10/2010 17:38:55 - System Checkpoint
    RP770: 22/10/2010 17:40:14 - System Checkpoint
    RP771: 23/10/2010 18:43:24 - System Checkpoint
    RP772: 24/10/2010 19:05:06 - System Checkpoint
    RP773: 25/10/2010 1922 - System Checkpoint
    RP774: 26/10/2010 13:26:59 - Avg Update
    RP775: 27/10/2010 13:37:26 - System Checkpoint
    RP776: 28/10/2010 15:02:48 - System Checkpoint
    RP777: 28/10/2010 17:50:05 - Installed AVG 2011
    RP778: 28/10/2010 17:51:20 - Removed AVG Free 9.0
    RP779: 28/10/2010 1740 - Installed AVG 2011
    RP780: 28/10/2010 1755 - Removed AVG 2011
    RP781: 28/10/2010 22:40:08 - Installed AVG 2011
    RP782: 28/10/2010 22:40:29 - Installed AVG 2011
    RP783: 30/10/2010 07:54:30 - System Checkpoint
    RP784: 31/10/2010 15:59:15 - System Checkpoint
    RP785: 01/11/2010 18:06:15 - System Checkpoint
    RP786: 02/11/2010 18:37:05 - System Checkpoint
    RP787: 03/11/2010 16:33:58 - Installed Avery Wizard 3.1.
    RP788: 03/11/2010 18:37:57 - Removed Avery Wizard 3.1.
    RP789: 04/11/2010 19:14:55 - System Checkpoint
    RP790: 05/11/2010 19:31:46 - System Checkpoint
    RP791: 06/11/2010 06:54:54 - Installed Windows XP KB915800-v4.
    RP792: 06/11/2010 06:55:39 - Installed Windows XP Windows Search 4.0.
    RP793: 07/11/2010 07:20:17 - System Checkpoint
    RP794: 07/11/2010 08:51:01 - Software Distribution Service 3.0
    RP795: 08/11/2010 08:57:59 - System Checkpoint
    RP796: 09/11/2010 10:24:03 - System Checkpoint
    RP797: 10/11/2010 14:16:48 - System Checkpoint
    RP798: 11/11/2010 00:15:48 - Software Distribution Service 3.0
    RP799: 12/11/2010 07:19:26 - System Checkpoint
    RP800: 13/11/2010 07:48:46 - System Checkpoint
    RP801: 14/11/2010 13:24:51 - System Checkpoint
    RP802: 15/11/2010 1344 - System Checkpoint
    RP803: 16/11/2010 16:00:33 - System Checkpoint
    RP804: 17/11/2010 16:57:37 - System Checkpoint
    RP805: 18/11/2010 17:27:44 - System Checkpoint
    RP806: 19/11/2010 2051 - System Checkpoint
    RP807: 20/11/2010 21:58:30 - System Checkpoint
    RP808: 21/11/2010 22:29:58 - System Checkpoint
    RP809: 22/11/2010 22:55:32 - System Checkpoint
    RP810: 24/11/2010 15:30:04 - System Checkpoint
    RP811: 25/11/2010 18:12:29 - System Checkpoint
    RP812: 26/11/2010 20:11:27 - System Checkpoint

    ==== Installed Programs ======================


    Adobe Flash Player 10 ActiveX
    Adobe Reader 9.4.1
    Adobe Shockwave Player 11.5
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Ask.com Search Assistant 1.0.2
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    AutoUpdate
    AVG 2011
    AVG PC Tuneup 2011
    BAMZOOKi v3.1 (build 115.158)
    Bonjour
    Camera RAW Plug-In for EPSON Creativity Suite
    CamStudio
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    ccc-core-preinstall
    ccc-core-static
    ccc-utility
    CCC Help English
    CCleaner
    Coupon Printer
    Disney's Toontown Online
    Disney Toontown Online UK_LIVE
    DivX Codec
    DivX Content Uploader
    DivX Converter
    DivX Player
    DivX Web Player
    Driver Detective
    Easy GIF Animator 4.9
    Easy Gif Animator Extension
    EPSON Attach To Email
    EPSON Copy Utility 3
    EPSON Easy Photo Print
    EPSON File Manager
    EPSON Print CD
    EPSON Printer Software
    EPSON Scan
    EPSON Scan Assistant
    EPSON Stylus Photo RX585_RX610 Manual
    EPSON Web-To-Page
    ffdshow (remove only)
    Free Games Offer, Desktop Shortcut
    GIF Movie Gear 4.2
    Google Chrome
    Google Earth
    Google Update Helper
    High-Logic FontCreator 6.0
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB915800-v4)
    iTunes
    J2SE Runtime Environment 5.0
    Java(TM) 6 Update 12
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Junk Mail filter update
    Keepsake Catwalk
    Logitech Desktop Messenger
    Logitech Print Service
    Logitech QuickCam Software
    Logitech® Camera Driver
    Malwarebytes' Anti-Malware
    Messenger Plus! Live
    Microsoft .NET Compact Framework 2.0 SP2
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office Live Add-in 1.3
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Works
    MobileMe Control Panel
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Nero 7 Essentials
    Picasa 3
    Pivot Stickfigure Animator
    PowerDVD
    QuickTime
    Safari
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2289158)
    Security Update for 2007 Microsoft Office System (KB2344875)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB2345035)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office Outlook 2007 (KB2288953)
    Security Update for Microsoft Office PowerPoint 2007 (KB982158)
    Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
    Security Update for Microsoft Office Publisher 2007 (KB982124)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Search 4 - KB963093
    Segoe UI
    Skins
    SoftV92 Data Fax Modem with SmartCP
    Software Update for Web Folders
    SoundMAX
    Spybot - Search & Destroy
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Outlook 2007 Junk Email Filter (KB2443839)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Viewpoint Media Player
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Search 4.0
    Windows XP Service Pack 3
    Yahoo! Messenger
    Yahoo! Software Update
    Zoo Tycoon 2
    Zoo Tycoon 2 - African Adventure

    ==== Event Viewer Messages From Past Week ========

    26/11/2010 22:34:18, error: System Error [1003] - Error code 10000050, parameter1 f7e9b00b, parameter2 00000000, parameter3 aa940e15, parameter4 00000000.
    26/11/2010 16:17:27, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    26/11/2010 16:17:23, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    26/11/2010 16:17:22, error: Service Control Manager [7034] - The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s).

    ==== End Of File ===========================

  6. #6
    smilliebob is offline Newbie
    ComboFix 10-11-30.02 - Robert Smillie 30/11/2010 21:25:09.1.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.636 [GMT 0:00]
    Running from: c:\documents and settings\Robert Smillie\Desktop\BobSmillie.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Robert Smillie\Application Data\PriceGong
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\1.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\a.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\b.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\c.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\d.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\e.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\f.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\g.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\h.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\i.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\J.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\k.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\l.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\m.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\mru.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\n.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\o.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\p.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\q.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\r.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\s.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\t.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\u.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\v.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\w.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\x.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\y.xml
    c:\documents and settings\Robert Smillie\Application Data\PriceGong\Data\z.xml

    .
    ((((((((((((((((((((((((( Files Created from 2010-10-28 to 2010-11-30 )))))))))))))))))))))))))))))))
    .

    2010-11-26 16:31 . 2010-11-26 16:31 -------- d-----w- c:\documents and settings\Robert Smillie\Application Data\Malwarebytes
    2010-11-26 16:31 . 2010-04-29 15:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-11-26 16:31 . 2010-11-26 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-11-26 16:31 . 2010-11-26 16:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-11-26 16:31 . 2010-04-29 15:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-20 19:00 . 2010-11-20 19:00 -------- d-----w- c:\program files\iPod
    2010-11-20 19:00 . 2010-11-20 19:01 -------- d-----w- c:\program files\iTunes
    2010-11-20 18:48 . 2010-11-20 18:48 -------- d-----w- c:\program files\Safari
    2010-11-12 17:02 . 2010-11-12 17:02 -------- d-----w- c:\program files\CCleaner
    2010-11-10 18:22 . 2010-11-10 18:22 -------- d-----w- c:\documents and settings\Robert Smillie\Application Data\Windows Search
    2010-11-06 11:37 . 2010-11-06 11:37 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
    2010-11-06 07:08 . 2010-11-06 07:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
    2010-11-06 06:56 . 2010-11-06 06:56 -------- d-----w- c:\documents and settings\Robert Smillie\Application Data\Windows Desktop Search
    2010-11-06 06:55 . 2010-11-07 08:51 -------- d-----w- c:\program files\Windows Desktop Search
    2010-11-06 06:55 . 2010-11-06 06:55 -------- d-----w- c:\windows\system32\GroupPolicy
    2010-11-06 06:53 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
    2010-11-06 06:53 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
    2010-11-06 06:53 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
    2010-11-03 08:32 . 2010-11-03 08:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
    2010-11-02 17:16 . 2010-11-08 18:25 -------- d-----w- c:\documents and settings\Robert Smillie\Local Settings\Application Data\Temp
    2010-11-02 17:15 . 2010-11-02 17:18 -------- d-----w- c:\documents and settings\Robert Smillie\Local Settings\Application Data\OpenCandy
    2010-11-02 17:15 . 2010-11-02 17:15 -------- d-----w- c:\documents and settings\Robert Smillie\Application Data\OpenCandy
    2010-10-31 22:17 . 2010-10-31 22:17 -------- d-sh--w- c:\windows\ftpcache

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2010-09-18 11:23 . 2004-08-04 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
    2010-09-18 06:53 . 2004-08-04 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
    2010-09-18 06:53 . 2004-08-04 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
    2010-09-18 06:53 . 2004-08-04 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
    2010-09-10 05:58 . 2004-09-29 18:47 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-10 05:58 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-10 05:58 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-09-08 10:17 . 2010-09-08 10:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-09-08 10:17 . 2010-09-08 10:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-21 47904]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-17 421160]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Robert Smillie^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
    path=c:\documents and settings\Robert Smillie\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
    backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2006-06-01 13:32 94208 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo RX585 Series]
    2007-03-30 06:00 182272 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIC LE.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2008-10-25 11:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-11-17 20:59 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
    2007-01-08 22:17 52256 ------w- c:\program files\CyberLink\PowerDVD\Language\Language.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
    2008-02-11 14:29 20480 ----a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
    2004-10-08 12:06 196608 ----a-w- c:\program files\Logitech\Video\ManifestEngine.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
    2004-10-08 12:31 458752 ----a-w- c:\program files\Logitech\Video\ISStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
    2004-10-08 12:24 217088 ----a-w- c:\program files\Logitech\Video\LogiTray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
    2004-10-08 11:52 221184 ----a-w- c:\windows\system32\LVCOMSX.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2006-01-12 16:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-09-08 10:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    2007-03-14 21:01 71216 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
    2004-09-23 13:41 860160 ------w- c:\program files\Analog Devices\SoundMAX\SMax4.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
    2004-10-14 10:11 1388544 ------w- c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    2009-03-05 16:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
    2006-11-10 12:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2009-03-17 15:19 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\system32\\ftp.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
    "c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
    "c:\\WINDOWS\\system32\\rtcshare.exe"=
    "c:\\Program Files\\NetMeeting\\conf.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [02/11/2010 17:15 136176]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2010-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-02 17:15]

    2010-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-02 17:15]

    2010-11-30 c:\windows\Tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://aol.co.uk/
    uDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe"
    uInternet Settings,ProxyOverride = localhost;*.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
    DPF: {BE71A78B-77DB-451C-A761-59B37022D544} - hxxp://o.aolcdn.com/pictures/ap/Resources/v2.13/cab/aolpPlugins.10.6.0.8.cab
    DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game07.zylom.com/activex/zylomgamesplayer.cab
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    HKLM-RunOnce-AvgRemover - c:\documents and settings\Robert Smillie\Local Settings\Temporary Internet Files\Content.IE5\BHI3KLIK\avg_remover_stf_x86_201 1_1165[1].exe
    MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
    MSConfigStartUp-HostManager - c:\program files\Common Files\AOL\1202722044\ee\AOLSoftware.exe
    MSConfigStartUp-lphcnj6j0eg45 - c:\windows\system32\lphcnj6j0eg45.exe
    MSConfigStartUp-Nero PhotoShow Media Manager - c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
    MSConfigStartUp-SMrhcjj6j0eg45 - c:\program files\rhcjj6j0eg45\rhcjj6j0eg45.exe
    MSConfigStartUp-SMshcgj6j0eg45 - c:\program files\shcgj6j0eg45\shcgj6j0eg45.exe
    MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
    MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe



    ************************************************** ************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    ************************************************** ************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63 A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macrome d\\Flash\\FlashUtil10k_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63 A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63 A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUt il10k_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63 A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F 2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F 2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F 2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(676)
    c:\windows\system32\Ati2evxx.dll
    .
    Completion time: 2010-11-30 21:32:05
    ComboFix-quarantined-files.txt 2010-11-30 21:32

    Pre-Run: 207,032,741,888 bytes free
    Post-Run: 207,036,862,464 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    UnsupportedDebug="do not select this" /debug
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect

    Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
    - - End Of File - - EBB45F33CC314A93AA914DA04FF3D6BF

  7. #7
    broni is offline Senior Member
    The log looks clean now

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:



    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

  8. #8
    smilliebob is offline Newbie
    OTL Extras logfile created on: 03/12/2010 15:08:40 - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS

    Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows NT\SystemRestore]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\GloballyOpenPorts\List]

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications\List]
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List]
    "C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program -- (Microsoft Corporation)
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*isabled:Logitech Desktop Messenger -- (Logitech)
    "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:Cy berLink PowerDVD -- (CyberLink Corp.)
    "C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe" = C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable -- (Microsoft Corporation)
    "C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation)
    "C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
    "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*isabled:Nero ShowTime Essentials -- (Nero AG)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enable d:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
    "C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
    "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
    "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
    "{0A06D517-BEE7-2D03-9792-CF1A30E29A70}" = Skins
    "{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
    "{1481D8E3-EA17-7697-3738-F5AA7784C902}" = ccc-utility
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
    "{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 12
    "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
    "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
    "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
    "{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
    "{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
    "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
    "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print
    "{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
    "{4C0F15CA-2032-5D72-F209-A89E02A5FE0F}" = CCC Help English
    "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
    "{59A67AEF-CABF-32CA-5407-55049E899A11}" = Catalyst Control Center Graphics Light
    "{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
    "{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
    "{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
    "{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
    "{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
    "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{901A5511-070B-20DF-2F5A-5FA29C302C2A}" = Catalyst Control Center Graphics Full Existing
    "{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
    "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
    "{943803CB-20FA-F4EB-E4A6-A3B055A1DC2E}" = ccc-core-preinstall
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
    "{9EE5A621-A673-37C4-E31A-A7D5696B6F29}" = Catalyst Control Center Graphics Previews Common
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
    "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
    "{B2F6B336-798D-77C2-21C9-392D4B0188F9}" = Catalyst Control Center Core Implementation
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
    "{B78EAA23-2D9B-CD91-6ABF-B96EC49BBA37}" = ccc-core-static
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure
    "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
    "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
    "{D9758C4B-CDD0-536F-D90E-9D74AFC3A35E}" = Catalyst Control Center Graphics Full New
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
    "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F17F7703-1E72-40C1-A0DD-E5B365661033}" = Nero 7 Essentials
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
    "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
    "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "All ATI Software" = ATI - Software Uninstall Utility
    "Ask.com Search Assistant" = Ask.com Search Assistant 1.0.2
    "ATI Display Driver" = ATI Display Driver
    "AVG" = AVG 2011
    "CamStudio" = CamStudio
    "CCleaner" = CCleaner
    "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_20001 4F1" = SoftV92 Data Fax Modem with SmartCP
    "Coupon Printer2.0" = Coupon Printer
    "Disney Toontown Online_UK" = Disney Toontown Online UK_LIVE
    "Disney's Toontown Online" = Disney's Toontown Online
    "Easy Gif Animator Extension" = Easy Gif Animator Extension
    "Easy GIF Animator_is1" = Easy GIF Animator 4.9
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "EPSON Printer and Utilities" = EPSON Printer Software
    "EPSON Scanner" = EPSON Scan
    "EPSON Stylus Photo RX585_RX610 User’s Guide" = EPSON Stylus Photo RX585_RX610 Manual
    "ffdshow" = ffdshow (remove only)
    "FontCreator6_is1" = High-Logic FontCreator 6.0
    "GamewareBAMZOOKiCBBCTools1_is1" = BAMZOOKi v3.1 (build 115.158)
    "GIF Movie Gear_is1" = GIF Movie Gear 4.2
    "Google Chrome" = Google Chrome
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
    "InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "InstallShield_{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure
    "Keepsake_Catwalk" = Keepsake Catwalk
    "Logitech Print Service" = Logitech Print Service
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Messenger Plus! Live" = Messenger Plus! Live
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "MSNINST" = MSN
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "Picasa 3" = Picasa 3
    "QcDrv" = Logitech® Camera Driver
    "ViewpointMediaPlayer" = Viewpoint Media Player
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Yahoo! Messenger" = Yahoo! Messenger
    "Yahoo! Software Update" = Yahoo! Software Update
    "Zoo Tycoon 2" = Zoo Tycoon 2

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 04/11/2010 20:17:07 | Computer Name = HOME-A92CE30BAF | Source = Microsoft Office 12 | ID = 5000
    Description = EventType officelifeboathang, P1 winword.exe, P2 12.0.6545.5000, P3
    ntdll.dll, P4 5.1.2600.5755, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

    Error - 06/11/2010 02:57:04 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024
    Description = The update cannot be started because the content sources cannot be
    accessed. Fix the errors and try the update again. Context: Windows Application,
    SystemIndex Catalog

    Error - 06/11/2010 03:03:35 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application WINWORD.EXE, version 12.0.6545.5000, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 10/11/2010 19:32:53 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024
    Description = The update cannot be started because the content sources cannot be
    accessed. Fix the errors and try the update again. Context: Application, SystemIndex
    Catalog

    Error - 13/11/2010 12:07:00 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application wabmig.exe, version 6.0.2900.5512, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 19/11/2010 19:27:54 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 20/11/2010 03:50:01 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    Error - 20/11/2010 03:53:36 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    [ System Events ]
    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The fssfltr service depends on the TCP/IP Protocol Driver service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The DHCP Client service depends on the NetBios over Tcpip service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The DNS Client service depends on the TCP/IP Protocol Driver service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
    failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The IPSEC Services service depends on the IPSEC driver service which
    failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

    Error - 30/11/2010 17:16:27 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service wuauserv with
    arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error - 30/11/2010 17:18:18 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service EventSystem
    with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


    < End of report >

    OTL logfile created on: 03/12/2010 15:08:40 - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS

    Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe
    PRC - [2010/11/10 19:08:04 | 000,724,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
    PRC - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    PRC - [2010/10/27 05:15:24 | 001,073,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
    PRC - [2010/10/27 05:14:50 | 001,047,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
    PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
    PRC - [2010/10/22 04:57:54 | 002,745,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
    PRC - [2010/10/22 04:57:38 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
    PRC - [2010/10/22 0458 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
    PRC - [2010/10/22 0456 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
    PRC - [2010/10/22 0448 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
    PRC - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    PRC - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2008/02/26 01:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Program Files\Picasa2\PicasaMediaDetector.exe
    PRC - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe
    MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
    SRV - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
    SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
    SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2009/08/05 21:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
    SRV - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
    DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
    DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
    DRV - [2010/09/07 03:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
    DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
    DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
    DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
    DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
    DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)
    DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)
    DRV - [2009/08/05 21:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2008/08/21 04:52:41 | 003,299,840 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
    DRV - [2008/02/11 09:38:06 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
    DRV - [2005/04/20 08:44:12 | 000,124,672 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
    DRV - [2005/03/01 12:01:40 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
    DRV - [2004/10/08 11:59:11 | 000,326,656 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
    DRV - [2004/10/08 11:57:48 | 000,022,016 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
    DRV - [2004/09/14 12:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)
    DRV - [2003/11/13 18:19:48 | 000,210,304 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
    DRV - [2003/11/13 18:18:36 | 000,679,808 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
    DRV - [2003/11/13 18:17:00 | 001,042,816 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
    DRV - [2003/01/10 21:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========


    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = AOL.co.uk
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = localhost;*.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "AOL Search"
    FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=tbff50sbox&query ="
    FF - prefs.js..browser.search.selectedEngine: "Ask"
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "http://www.plusnetwork.com"
    FF - prefs.js..extensions.enabledItems: {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}:5.5.18.6
    FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
    FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=TBab-en-gb-web-aol-V55-winff&query="
    FF - prefs.js..network.proxy.no_proxies_on: "localhost,*.local"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5 b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/30 21:53:26 | 000,000,000 | ---D | M]

    [2008/12/22 22:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Extensions
    [2009/01/01 13:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions
    [2008/12/27 21:59:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
    [2008/12/27 22:05:29 | 000,001,774 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\aol-search.xml
    [2010/01/18 15:47:13 | 000,001,681 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\ask.uk.xml
    [2009/01/05 15:49:53 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2008/10/09 14:03:07 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2008/06/18 06:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2008/10/04 20:24:00 | 003,695,008 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll

    O1 HOSTS File: ([2010/11/30 21:30:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Easy Gif Animator Toolbar Helper) - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [MFARestart] C:\Documents and Settings\All Users\Application Data\MFAData\pack\avgrunasx.exe File not found
    O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
    O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.8.05.cab (Reg Error: Key error.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe...nttracking.cab (Reg Error: Key error.)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/micr...?1202746562812 (MUWebControl Class)
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} Page not found | Facebook (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary...o.cab56649.cab (Reg Error: Key error.)
    O16 - DPF: {BE71A78B-77DB-451C-A761-59B37022D544} Pixcetera.com (Reg Error: Key error.)
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game07.zylom.com/activex/zylomgamesplayer.cab (Reg Error: Key error.)
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} https://ukplay.toontown.com/download....21/ttinst.cab (Reg Error: Key error.)
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary...t.cab56907.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab (Reg Error: Key error.)
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary...r.cab56986.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O24 - Desktop WallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
    Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
    Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (16902109354000384)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/11/30 22:02:11 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
    [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
    [2010/11/30 21:41:52 | 000,000,000 | --SD | C] -- C:\BobSmillie28274B
    [2010/11/30 21:35:54 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/11/30 21:23:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/11/30 21:20:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/11/30 21:20:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/11/30 21:20:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/11/30 21:20:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/11/30 21:20:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/11/30 21:20:41 | 000,000,000 | ---D | C] -- C:\BobSmillie
    [2010/11/30 20:48:25 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/11/27 10:19:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus scan results
    [2010/11/27 10:18:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    [2010/11/26 16:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Malwarebytes
    [2010/11/26 16:31:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/11/26 16:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/11/26 16:31:16 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/11/26 16:31:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/11/20 19:00:57 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2010/11/20 19:00:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2010/11/20 18:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
    [2010/11/12 17:13:48 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Robert Smillie\Recent
    [2010/11/12 17:02:15 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2010/11/12 17:01:26 | 002,810,112 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/10 18:22:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search
    [2010/11/09 22:20:58 | 000,299,984 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/11/06 07:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
    [2010/11/06 0656 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search
    [2010/11/06 06:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
    [2010/11/06 06:55:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/11/06 0617 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Robert Smillie\My Documents\My Data Sources

    ========== Files - Modified Within 30 Days ==========

    [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job
    [2010/12/03 14:25:01 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2010/12/03 08:30:37 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2010/12/03 08:30:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/12/03 08:30:25 | 000,044,964 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
    [2010/12/02 19:25:37 | 100,786,927 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2010/12/01 00:42:54 | 000,636,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
    [2010/11/30 21:54:45 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
    [2010/11/30 21:30:10 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/27 17:47:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/11/23 17:01:50 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101125-162138.backup
    [2010/11/21 22:09:26 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101123-170150.backup
    [2010/11/20 23:35:04 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
    [2010/11/20 17:45:56 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101121-220926.backup
    [2010/11/20 08:31:21 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-174556.backup
    [2010/11/20 07:52:39 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-083121.backup
    [2010/11/16 15:36:39 | 000,010,415 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx
    [2010/11/16 15:01:24 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\Microsoft Office Word 2007.lnk
    [2010/11/13 16:55:17 | 000,426,907 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-075238.backup
    [2010/11/12 17:08:50 | 000,264,918 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg
    [2010/11/12 17:02:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/10 1832 | 000,000,148 | ---- | M] () -- C:\WINDOWS\wininit.ini
    [2010/11/10 18:17:46 | 000,000,004 | ---- | M] () -- C:\WINDOWS\msoffice.ini
    [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/11/08 22:02:24 | 004,247,040 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps
    [2010/11/08 12:30:41 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc
    [2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
    [2010/11/06 0600 | 000,466,026 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/11/06 0600 | 000,079,736 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/11/04 23:04:03 | 000,426,195 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101113-165517.backup
    [2010/11/04 17:13:53 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
    [2010/11/04 12:29:58 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc
    [2010/11/04 07:58:41 | 000,280,536 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/11/03 23:13:40 | 000,046,592 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc

    ========== Files Created - No Company Name ==========

    [2010/12/02 19:25:37 | 100,786,927 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2010/12/01 00:42:54 | 000,636,239 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
    [2010/11/30 21:54:45 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
    [2010/11/30 21:23:54 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/11/30 21:23:51 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2010/11/30 21:20:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/11/30 21:20:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/11/30 21:20:49 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/11/30 21:20:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/11/30 21:20:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/11/30 21:03:25 | 003,982,824 | R--- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
    [2010/11/16 15:36:39 | 000,010,415 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx
    [2010/11/12 17:08:45 | 000,264,918 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg
    [2010/11/12 17:02:16 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2010/11/08 22:01:41 | 004,247,040 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps
    [2010/11/08 12:30:38 | 000,076,800 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc
    [2010/11/04 17:13:53 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
    [2010/11/04 12:29:57 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc
    [2010/11/03 23:01:32 | 000,046,592 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc
    [2009/06/05 17:12:03 | 000,000,021 | ---- | C] () -- C:\WINDOWS\.picasa.ini
    [2009/05/06 09:36:40 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Smiley.ico
    [2009/02/01 19:57:04 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/12/19 19:33:06 | 000,000,111 | ---- | C] () -- C:\WINDOWS\ka.ini
    [2008/10/10 18:58:55 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys
    [2008/07/20 00:01:48 | 000,000,148 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2008/04/02 14:42:13 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
    [2008/03/26 15:52:54 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
    [2008/03/25 1638 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
    [2008/02/17 22:40:29 | 000,000,071 | ---- | C] () -- C:\WINDOWS\EPSONCD.INI
    [2008/02/11 15:18:42 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2008/02/11 14:33:42 | 000,006,812 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2008/02/11 13:52:28 | 000,000,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Setup.txt
    [2008/02/11 12:55:48 | 000,062,464 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/02/10 22:26:44 | 000,002,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\wklnhst.dat
    [2008/02/10 22:14:22 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
    [2008/02/10 22:11:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE RX585DEFGIPS.ini
    [2008/02/09 19:57:25 | 000,000,996 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2008/02/09 19:44:55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2008/01/04 21:58:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
    [2008/01/04 2124 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
    [2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
    [2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
    [2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
    [1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
    [1997/06/13 0708 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll

    ========== LOP Check ==========

    [2009/05/20 11:07:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\162CE
    [2009/05/07 09:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\302E
    [2009/05/06 09:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\33DA
    [2010/11/30 21:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
    [2010/10/28 16:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2010/10/28 21:42:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
    [2008/02/10 22:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
    [2008/05/22 22:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
    [2010/01/18 15:47:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    [2010/11/30 21:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
    [2008/05/28 14:33:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
    [2010/11/30 20:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2008/02/10 22:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
    [2008/02/11 09:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2009/03/20 15:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VUG
    [2008/04/22 09:36:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
    [2009/04/04 17:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    [2010/09/04 18:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/10/10 18:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009/05/02 20:03:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2010/10/28 21:44:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\AVG10
    [2009/05/25 07:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Bamzooki
    [2008/03/13 15:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\EPSON
    [2009/07/10 08:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FontCreator
    [2008/02/11 14:30:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FotoWire
    [2008/02/11 22:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Grisoft
    [2008/03/17 13:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\MSNInstaller
    [2010/11/02 17:15:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\OpenCandy
    [2008/02/11 13:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Simple Star
    [2008/02/12 14:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Template
    [2009/08/09 19:27:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Viewpoint
    [2010/11/06 0657 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search
    [2009/10/16 12:50:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Live Writer
    [2010/11/10 18:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search
    [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2005/01/24 11:36:50 | 010,810,909 | ---- | M] () -- C:\avg70free_300a419.exe
    [2009/03/20 15:46:55 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
    [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2008/02/11 14:29:42 | 000,000,183 | ---- | M] () -- C:\LogiSetup.log
    [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008/08/27 22:42:54 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2010/12/03 08:30:21 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
    [2008/10/13 23:03:02 | 000,002,510 | ---- | M] () -- C:\playground.log
    [2008/04/02 14:59:47 | 000,004,104 | ---- | M] () -- C:\RndisAdaptorMgr.log
    [2008/02/09 21:50:12 | 000,000,164 | ---- | M] () -- C:\soundmax.log
    [2008/04/11 14:32:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
    [2008/09/24 08:25:53 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
    [2008/09/24 08:25:53 | 000,000,148 | -H-- | M] () -- C:\sqmdata02.sqm
    [2009/01/07 15:25:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
    [2009/02/12 18:36:52 | 000,000,304 | -H-- | M] () -- C:\sqmdata04.sqm
    [2009/02/13 11:07:35 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
    [2009/03/03 15:16:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata07.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata08.sqm
    [2009/04/02 19:02:39 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
    [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata10.sqm
    [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata11.sqm
    [2008/04/11 14:32:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
    [2008/09/24 08:25:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
    [2008/09/24 08:25:53 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt02.sqm
    [2009/01/07 15:25:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
    [2009/02/12 18:36:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
    [2009/02/13 11:07:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
    [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
    [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt08.sqm
    [2009/04/02 19:02:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
    [2009/04/02 19:02:39 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt10.sqm
    [2008/04/02 14:59:46 | 000,004,815 | ---- | M] () -- C:\St121PrismAdaptorMgr.log
    [2008/04/02 14:59:47 | 000,032,030 | ---- | M] () -- C:\StInstall.log
    [2008/04/02 14:59:43 | 000,000,784 | ---- | M] () -- C:\XPWiFiAdaptorMgr.log

    < %systemroot%\Fonts\*.com >
    [2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2008/02/09 19:54:38 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpi pelineprintproc.dll
    [2006/10/26 1912 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr .dll
    [2008/07/06 10:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfil terpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2006/05/18 19:20:35 | 000,319,488 | ---- | M] (Nero AG / Nero Inc.) -- C:\WINDOWS\Nero PhotoShow.scr
    [2009/07/10 11:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2008/02/09 19:42:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2008/02/09 19:42:58 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2008/02/09 19:42:58 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2008/08/27 22:49:32 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >
    [2008/02/09 1946 | 000,002,189 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\dotNetFx. log

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2008/02/09 20:04:58 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2008/02/09 20:04:57 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2008/10/13 16:29:42 | 036,663,808 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\Robert Smillie\Desktop\8-9_xp32_dd_ccc_wdm_enu_68898.exe
    [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/08 10:07:16 | 011,701,704 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Robert Smillie\Desktop\windows-kb890830-v3.12.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2008/02/09 20:04:57 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2009/02/13 12:14:05 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\desktop.ini
    [2010/12/03 15:08:32 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/14 00:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2007/04/02 18:07:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2008/05/02 14:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 17:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/14 00:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2007/04/02 18:07:23 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2007/04/02 18:07:23 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2007/04/02 18:07:24 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2007/04/02 18:07:27 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2007/04/02 18:04:01 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto >

    < Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMPFC5A2B2

    < End of report >

  9. #9
    smilliebob is offline Newbie
    OTL Extras logfile created on: 03/12/2010 15:08:40 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\] ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] ========== System Restore Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows NT\SystemRestore] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Sr] "Start" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SrService] "Start" = 2 ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\DomainProfile] [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile] "EnableFirewall" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile] "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\GloballyOpenPorts\List] ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications\List] "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List] "C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program -- (Microsoft Corporation) "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*isabled:Logitech Desktop Messenger -- (Logitech) "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:Cy berLink PowerDVD -- (CyberLink Corp.) "C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe" = C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable -- (Microsoft Corporation) "C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation) "C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation) "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation) "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*isabled:Nero ShowTime Essentials -- (Nero AG) "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enable d:Yahoo! Messenger -- (Yahoo! Inc.) "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.) "C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG TechnologiesCZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.) ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall] "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack "{0A06D517-BEE7-2D03-9792-CF1A30E29A70}" = Skins "{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety "{1481D8E3-EA17-7697-3738-F5AA7784C902}" = ccc-utility "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate "{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSONAttach To Email "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 12 "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support "{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut "{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0 "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7 "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform "{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print "{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works "{4C0F15CA-2032-5D72-F209-A89E02A5FE0F}" = CCC Help English "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3 "{59A67AEF-CABF-32CA-5407-55049E899A11}" = Catalyst Control Center Graphics Light "{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011 "{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec "{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders "{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86) "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player "{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12 "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581) "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" = "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2) "{901A5511-070B-20DF-2F5A-5FA29C302C2A}" = Catalyst Control Center Graphics Full Existing "{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant "{943803CB-20FA-F4EB-E4A6-A3B055A1DC2E}" = ccc-core-preinstall "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar "{9EE5A621-A673-37C4-E31A-A7D5696B6F29}" = Catalyst Control Center Graphics Previews Common "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011 "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1 "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter "{B2F6B336-798D-77C2-21C9-392D4B0188F9}" = Catalyst Control Center Core Implementation "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player "{B78EAA23-2D9B-CD91-6ABF-B96EC49BBA37}" = ccc-core-static "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86) "{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery "{D9758C4B-CDD0-536F-D90E-9D74AFC3A35E}" = Catalyst Control Center Graphics Full New "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime "{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2 "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F17F7703-1E72-40C1-A0DD-E5B365661033}" = Nero 7 Essentials "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call "{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Shockwave Player" = Adobe Shockwave Player 11.5 "All ATI Software" = ATI - Software Uninstall Utility "Ask.com Search Assistant" = Ask.com Search Assistant 1.0.2 "ATI Display Driver" = ATI Display Driver "AVG" = AVG 2011 "CamStudio" = CamStudio "CCleaner" = CCleaner "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_20001 4F1" = SoftV92 Data Fax Modem with SmartCP "Coupon Printer2.0" = Coupon Printer "Disney Toontown Online_UK" = Disney Toontown Online UK_LIVE "Disney's Toontown Online" = Disney's Toontown Online "Easy Gif Animator Extension" = Easy Gif Animator Extension "Easy GIF Animator_is1" = Easy GIF Animator 4.9 "ENTERPRISE" = Microsoft Office Enterprise 2007 "EPSON Printer and Utilities" = EPSON Printer Software "EPSON Scanner" = EPSON Scan "EPSON Stylus Photo RX585_RX610 User’s Guide" = EPSON Stylus Photo RX585_RX610 Manual "ffdshow" = ffdshow (remove only) "FontCreator6_is1" = High-Logic FontCreator 6.0 "GamewareBAMZOOKiCBBCTools1_is1" = BAMZOOKi v3.1 (build 115.158) "GIF Movie Gear_is1" = GIF Movie Gear 4.2 "Google Chrome" = Google Chrome "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email "InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective "InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "InstallShield_{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure "Keepsake_Catwalk" = Keepsake Catwalk "Logitech Print Service" = Logitech Print Service "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Messenger Plus! Live" = Messenger Plus! Live "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "MSNINST" = MSN "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "Picasa 3" = Picasa 3 "QcDrv" = Logitech® Camera Driver "ViewpointMediaPlayer" = Viewpoint Media Player "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinLiveSuite_Wave3" = Windows Live Essentials "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update "Zoo Tycoon 2" = Zoo Tycoon 2 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083 Description = Failed extract of third-party root list from auto update cab at: with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. Error - 04/11/2010 20:17:07 | Computer Name = HOME-A92CE30BAF | Source = Microsoft Office 12 | ID = 5000 Description = EventType officelifeboathang, P1 winword.exe, P2 12.0.6545.5000, P3 ntdll.dll, P4 5.1.2600.5755, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL. Error - 06/11/2010 02:57:04 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024 Description = The update cannot be started because the content sources cannot be accessed. Fix the errors and try the update again. Context: Windows Application, SystemIndex Catalog Error - 06/11/2010 03:03:35 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002 Description = Hanging application WINWORD.EXE, version 12.0.6545.5000, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 10/11/2010 19:32:53 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024 Description = The update cannot be started because the content sources cannot be accessed. Fix the errors and try the update again. Context: Application, SystemIndex Catalog Error - 13/11/2010 12:07:00 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002 Description = Hanging application wabmig.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 19/11/2010 19:27:54 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 20/11/2010 03:50:01 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002 Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 20/11/2010 03:53:36 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002 Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp, version 0.0.0.0, hang address 0x00000000. [ System Events ] Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The fssfltr service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001 Description = The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31 Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip Error - 30/11/2010 17:16:27 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} Error - 30/11/2010 17:18:18 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005 Description = DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} < End of report > OTL logfile created on: 03/12/2010 15:08:40 - Run 1 OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free 2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free Paging file location(s): C:\pagefile.sys 1536 3072 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe PRC - [2010/11/10 19:08:04 | 000,724,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe PRC - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe PRC - [2010/10/27 05:15:24 | 001,073,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe PRC - [2010/10/27 05:14:50 | 001,047,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe PRC - [2010/10/22 04:57:54 | 002,745,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe PRC - [2010/10/22 04:57:38 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe PRC - [2010/10/22 0458 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe PRC - [2010/10/22 0456 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe PRC - [2010/10/22 0448 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe PRC - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe PRC - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe PRC - [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PRC - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2008/02/26 01:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Program Files\Picasa2\PicasaMediaDetector.exe PRC - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe ========== Modules (SafeList) ========== MOD - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll ========== Win32 Services (SafeList) ========== SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt) SRV - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd) SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device) SRV - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort) SRV - [2009/08/05 21:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc) SRV - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService) SRV - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default)) ========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\catchme.sys -- (catchme) DRV - [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2010/09/07 03:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd) DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx) DRV - [2009/08/05 21:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr) DRV - [2008/08/21 04:52:41 | 003,299,840 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM) DRV - [2008/02/11 09:38:06 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x) DRV - [2005/04/20 08:44:12 | 000,124,672 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP) DRV - [2005/03/01 12:01:40 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt) DRV - [2004/10/08 11:59:11 | 000,326,656 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl) DRV - [2004/10/08 11:57:48 | 000,022,016 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta) DRV - [2004/09/14 12:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn) DRV - [2003/11/13 18:19:48 | 000,210,304 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2) DRV - [2003/11/13 18:18:36 | 000,679,808 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2003/11/13 18:17:00 | 001,042,816 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP) DRV - [2003/01/10 21:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = AOL.co.uk IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = localhost;*.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AOL Search" FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=tbff50sbox&query =" FF - prefs.js..browser.search.selectedEngine: "Ask" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.plusnetwork.com" FF - prefs.js..extensions.enabledItems: {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}:5.5.18.6 FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0 FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=TBab-en-gb-web-aol-V55-winff&query=" FF - prefs.js..network.proxy.no_proxies_on: "localhost,*.local" FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5 b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/30 21:53:26 | 000,000,000 | ---D | M] [2008/12/22 22:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Extensions [2009/01/01 13:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions [2008/12/27 21:59:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1} [2008/12/27 22:05:29 | 000,001,774 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\aol-search.xml [2010/01/18 15:47:13 | 000,001,681 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\ask.uk.xml [2009/01/05 15:49:53 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions [2008/10/09 14:03:07 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2008/06/18 06:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll [2008/10/04 20:24:00 | 003,695,008 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll O1 HOSTS File: ([2010/11/30 21:30:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation) O2 - BHO: (Easy Gif Animator Toolbar Helper) - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll () O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found. O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKLM\..\Toolbar: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll () O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation) O3 - HKCU\..\Toolbar\WebBrowser: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll () O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION) O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [MFARestart] C:\Documents and Settings\All Users\Application Data\MFAData\pack\avgrunasx.exe File not found O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.) O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0 O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.) O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.8.05.cab (Reg Error: Key error.) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control) O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe...nttracking.cab (Reg Error: Key error.) O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/micr...?1202746562812 (MUWebControl Class) O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} Page not found | Facebook (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary...o.cab56649.cab (Reg Error: Key error.) O16 - DPF: {BE71A78B-77DB-451C-A761-59B37022D544} Pixcetera.com (Reg Error: Key error.) O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game07.zylom.com/activex/zylomgamesplayer.cab (Reg Error: Key error.) O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} https://ukplay.toontown.com/download....21/ttinst.cab (Reg Error: Key error.) O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary...t.cab56907.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07) O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12) O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab (Reg Error: Key error.) O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary...r.cab56986.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.) O24 - Desktop WallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* NetSvcs: 6to4 - File not found NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found NetSvcs: Ias - File not found NetSvcs: Iprip - File not found NetSvcs: Irmon - File not found NetSvcs: NWCWorkstation - File not found NetSvcs: Nwsapagent - File not found NetSvcs: WmdmPmSp - File not found Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation) Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS) Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.) Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.) Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation) Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.) Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.) Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.) Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll () Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation) Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation) Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.) CREATERESTOREPOINT Restore point Set: OTL Restore Point (16902109354000384) ========== Files/Folders - Created Within 30 Days ========== [2010/11/30 22:02:11 | 000,000,000 | -HSD | C] -- C:\Config.Msi [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10 [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG [2010/11/30 21:41:52 | 000,000,000 | --SD | C] -- C:\BobSmillie28274B [2010/11/30 21:35:54 | 000,000,000 | -HSD | C] -- C:\RECYCLER [2010/11/30 21:23:50 | 000,000,000 | RHSD | C] -- C:\cmdcons [2010/11/30 21:20:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2010/11/30 21:20:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2010/11/30 21:20:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2010/11/30 21:20:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2010/11/30 21:20:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2010/11/30 21:20:41 | 000,000,000 | ---D | C] -- C:\BobSmillie [2010/11/30 20:48:25 | 000,000,000 | ---D | C] -- C:\Qoobox [2010/11/27 10:19:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus scan results [2010/11/27 10:18:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs [2010/11/26 16:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Malwarebytes [2010/11/26 16:31:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2010/11/26 16:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2010/11/26 16:31:16 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2010/11/26 16:31:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2010/11/20 19:00:57 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2010/11/20 19:00:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2010/11/20 18:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Safari [2010/11/12 17:13:48 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Robert Smillie\Recent [2010/11/12 17:02:15 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2010/11/12 17:01:26 | 002,810,112 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe [2010/11/10 18:22:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search [2010/11/09 22:20:58 | 000,299,984 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2010/11/06 07:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe [2010/11/06 0656 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search [2010/11/06 06:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search [2010/11/06 06:55:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy [2010/11/06 0617 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Robert Smillie\My Documents\My Data Sources ========== Files - Modified Within 30 Days ========== [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job [2010/12/03 14:25:01 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2010/12/03 08:30:37 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2010/12/03 08:30:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2010/12/03 08:30:25 | 000,044,964 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap [2010/12/02 19:25:37 | 100,786,927 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2010/12/01 00:42:54 | 000,636,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm [2010/11/30 21:54:45 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk [2010/11/30 21:30:10 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe [2010/11/27 17:47:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2010/11/23 17:01:50 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101125-162138.backup [2010/11/21 22:09:26 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101123-170150.backup [2010/11/20 23:35:04 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk [2010/11/20 17:45:56 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101121-220926.backup [2010/11/20 08:31:21 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-174556.backup [2010/11/20 07:52:39 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-083121.backup [2010/11/16 15:36:39 | 000,010,415 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx [2010/11/16 15:01:24 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\Microsoft Office Word 2007.lnk [2010/11/13 16:55:17 | 000,426,907 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-075238.backup [2010/11/12 17:08:50 | 000,264,918 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg [2010/11/12 17:02:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe [2010/11/10 1832 | 000,000,148 | ---- | M] () -- C:\WINDOWS\wininit.ini [2010/11/10 18:17:46 | 000,000,004 | ---- | M] () -- C:\WINDOWS\msoffice.ini [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys [2010/11/08 22:02:24 | 004,247,040 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps [2010/11/08 12:30:41 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc [2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe [2010/11/06 0600 | 000,466,026 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2010/11/06 0600 | 000,079,736 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2010/11/04 23:04:03 | 000,426,195 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101113-165517.backup [2010/11/04 17:13:53 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk [2010/11/04 12:29:58 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc [2010/11/04 07:58:41 | 000,280,536 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2010/11/03 23:13:40 | 000,046,592 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc ========== Files Created - No Company Name ========== [2010/12/02 19:25:37 | 100,786,927 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm [2010/12/01 00:42:54 | 000,636,239 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm [2010/11/30 21:54:45 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk [2010/11/30 21:23:54 | 000,000,211 | ---- | C] () -- C:\Boot.bak [2010/11/30 21:23:51 | 000,260,272 | RHS- | C] () -- C:\cmldr [2010/11/30 21:20:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe [2010/11/30 21:20:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2010/11/30 21:20:49 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe [2010/11/30 21:20:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2010/11/30 21:20:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2010/11/30 21:03:25 | 003,982,824 | R--- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk [2010/11/16 15:36:39 | 000,010,415 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx [2010/11/12 17:08:45 | 000,264,918 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg [2010/11/12 17:02:16 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk [2010/11/08 22:01:41 | 004,247,040 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps [2010/11/08 12:30:38 | 000,076,800 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc [2010/11/04 17:13:53 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk [2010/11/04 12:29:57 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc [2010/11/03 23:01:32 | 000,046,592 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc [2009/06/05 17:12:03 | 000,000,021 | ---- | C] () -- C:\WINDOWS\.picasa.ini [2009/05/06 09:36:40 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Smiley.ico [2009/02/01 19:57:04 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2008/12/19 19:33:06 | 000,000,111 | ---- | C] () -- C:\WINDOWS\ka.ini [2008/10/10 18:58:55 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys [2008/07/20 00:01:48 | 000,000,148 | ---- | C] () -- C:\WINDOWS\wininit.ini [2008/04/02 14:42:13 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini [2008/03/26 15:52:54 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI [2008/03/25 1638 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI [2008/02/17 22:40:29 | 000,000,071 | ---- | C] () -- C:\WINDOWS\EPSONCD.INI [2008/02/11 15:18:42 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2008/02/11 14:33:42 | 000,006,812 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2008/02/11 13:52:28 | 000,000,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Setup.txt [2008/02/11 12:55:48 | 000,062,464 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2008/02/10 22:26:44 | 000,002,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\wklnhst.dat [2008/02/10 22:14:22 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini [2008/02/10 22:11:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE RX585DEFGIPS.ini [2008/02/09 19:57:25 | 000,000,996 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2008/02/09 19:44:55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2008/01/04 21:58:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll [2008/01/04 2124 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll [2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini [2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini [2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini [1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll [1997/06/13 0708 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll ========== LOP Check ========== [2009/05/20 11:07:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\162CE [2009/05/07 09:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\302E [2009/05/06 09:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\33DA [2010/11/30 21:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10 [2010/10/28 16:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9 [2010/10/28 21:42:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files [2008/02/10 22:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON [2008/05/22 22:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft [2010/01/18 15:47:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus! [2010/11/30 21:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData [2008/05/28 14:33:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters [2010/11/30 20:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP [2008/02/10 22:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL [2008/02/11 09:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint [2009/03/20 15:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VUG [2008/04/22 09:36:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom [2009/04/04 17:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} [2010/09/04 18:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521} [2009/10/10 18:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} [2009/05/02 20:03:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} [2010/10/28 21:44:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\AVG10 [2009/05/25 07:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Bamzooki [2008/03/13 15:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\EPSON [2009/07/10 08:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FontCreator [2008/02/11 14:30:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FotoWire [2008/02/11 22:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Grisoft [2008/03/17 13:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\MSNInstaller [2010/11/02 17:15:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\OpenCandy [2008/02/11 13:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Simple Star [2008/02/12 14:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Template [2009/08/09 19:27:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Viewpoint [2010/11/06 0657 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search [2009/10/16 12:50:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Live Writer [2010/11/10 18:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job ========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* > [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT [2005/01/24 11:36:50 | 010,810,909 | ---- | M] () -- C:\avg70free_300a419.exe [2009/03/20 15:46:55 | 000,000,211 | ---- | M] () -- C:\Boot.bak [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini [2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS [2008/02/11 14:29:42 | 000,000,183 | ---- | M] () -- C:\LogiSetup.log [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS [2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM [2008/08/27 22:42:54 | 000,250,048 | RHS- | M] () -- C:\ntldr [2010/12/03 08:30:21 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys [2008/10/13 23:03:02 | 000,002,510 | ---- | M] () -- C:\playground.log [2008/04/02 14:59:47 | 000,004,104 | ---- | M] () -- C:\RndisAdaptorMgr.log [2008/02/09 21:50:12 | 000,000,164 | ---- | M] () -- C:\soundmax.log [2008/04/11 14:32:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm [2008/09/24 08:25:53 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm [2008/09/24 08:25:53 | 000,000,148 | -H-- | M] () -- C:\sqmdata02.sqm [2009/01/07 15:25:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm [2009/02/12 18:36:52 | 000,000,304 | -H-- | M] () -- C:\sqmdata04.sqm [2009/02/13 11:07:35 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm [2009/03/03 15:16:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata07.sqm [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata08.sqm [2009/04/02 19:02:39 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata10.sqm [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata11.sqm [2008/04/11 14:32:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm [2008/09/24 08:25:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm [2008/09/24 08:25:53 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt02.sqm [2009/01/07 15:25:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm [2009/02/12 18:36:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm [2009/02/13 11:07:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt08.sqm [2009/04/02 19:02:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm [2009/04/02 19:02:39 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt10.sqm [2008/04/02 14:59:46 | 000,004,815 | ---- | M] () -- C:\St121PrismAdaptorMgr.log [2008/04/02 14:59:47 | 000,032,030 | ---- | M] () -- C:\StInstall.log [2008/04/02 14:59:43 | 000,000,784 | ---- | M] () -- C:\XPWiFiAdaptorMgr.log < %systemroot%\Fonts\*.com > [2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont [2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont [2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont [2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont < %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini > [2008/02/09 19:54:38 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini < %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* > [2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpi pelineprintproc.dll [2006/10/26 1912 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr .dll [2008/07/06 10:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfil terpipelinesvc.exe < %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > [2006/05/18 19:20:35 | 000,319,488 | ---- | M] (Nero AG / Nero Inc.) -- C:\WINDOWS\Nero PhotoShow.scr [2009/07/10 11:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav > [2008/02/09 19:42:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav [2008/02/09 19:42:58 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav [2008/02/09 19:42:58 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav < %PROGRAMFILES%\bak. /s > < %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x > [2008/08/27 22:49:32 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini < %systemroot%\system32\config\systemprofile\*.dat /x > [2008/02/09 1946 | 000,002,189 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\dotNetFx. log < %systemroot%\*.config > < %systemroot%\system32\*.db > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x > [2008/02/09 20:04:58 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini [2008/02/09 20:04:57 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf < %USERPROFILE%\Desktop\*.exe > [2008/10/13 16:29:42 | 036,663,808 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\Robert Smillie\Desktop\8-9_xp32_dd_ccc_wdm_enu_68898.exe [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe [2010/11/08 10:07:16 | 011,701,704 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Robert Smillie\Desktop\windows-kb890830-v3.12.exe < %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src > < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x > < %PROGRAMFILES%\PC-Doctor\Downloads\*.* > < %PROGRAMFILES%\Internet Explorer\*.tmp > < %PROGRAMFILES%\Internet Explorer\*.dat > < %USERPROFILE%\My Documents\*.exe > < %USERPROFILE%\*.exe > < %systemroot%\ADDINS\*.* > < %systemroot%\assembly\*.bak2 > < %systemroot%\Config\*.* > < %systemroot%\REPAIR\*.bak2 > < %systemroot%\SECURITY\Database\*.sdb /x > < %systemroot%\SYSTEM\*.bak2 > < %systemroot%\Web\*.bak2 > < %systemroot%\Driver Cache\*.* > < %PROGRAMFILES%\Mozilla Firefox\0*.exe > < %ProgramFiles%\Microsoft Common\*.* > < %ProgramFiles%\TinyProxy. > < %USERPROFILE%\Favorites\*.url /x > [2008/02/09 20:04:57 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Favorites\Desktop.ini < %systemroot%\system32\*.bk > < %systemroot%\*.te > < %systemroot%\system32\system32\*.* > < %ALLUSERSPROFILE%\*.dat /x > < %systemroot%\system32\drivers\*.rmv > < dir /b "%systemroot%\system32\*.exe" | find /i " " /c > < dir /b "%systemroot%\*.exe" | find /i " " /c > < %PROGRAMFILES%\Microsoft\*.* > < %systemroot%\System32\Wbem\proquota.exe > < %PROGRAMFILES%\Mozilla Firefox\*.dat > < %USERPROFILE%\Cookies\*.txt /x > [2009/02/13 12:14:05 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\desktop.ini [2010/12/03 15:08:32 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\index.dat < %SystemRoot%\system32\fonts\*.* > < %systemroot%\system32\winlog\*.* > < %systemroot%\system32\Language\*.* > < %systemroot%\system32\Settings\*.* > < %systemroot%\system32\*.quo > < %SYSTEMROOT%\AppPatch\*.exe > < %SYSTEMROOT%\inf\*.exe > [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe < %SYSTEMROOT%\Installer\*.exe > < %systemroot%\system32\config\*.bak2 > < %systemroot%\system32\Computers\*.* > < %SystemRoot%\system32\Sound\*.* > < %SystemRoot%\system32\SpecialImg\*.* > < %SystemRoot%\system32\code\*.* > < %SystemRoot%\system32\draft\*.* > < %SystemRoot%\system32\MSSSys\*.* > < %ProgramFiles%\Javascript\*.* > < %systemroot%\pchealth\helpctr\System\*.exe /s > < %systemroot%\Web\*.exe > < %systemroot%\system32\msn\*.* > < %systemroot%\system32\*.tro > < %AppData%\Microsoft\Installer\msupdates\*.* > < %ProgramFiles%\Messenger\*.* > [2008/04/14 00:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll [2007/04/02 18:07:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif [2008/05/02 14:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll [2008/04/13 17:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll [2008/04/14 00:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe [2007/04/02 18:07:23 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav [2007/04/02 18:07:23 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav [2007/04/02 18:07:24 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav [2007/04/02 18:07:27 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav [2007/04/02 18:04:01 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm < %systemroot%\system32\systhem32\*.* > < %systemroot%\system\*.exe > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto > < Update\Results\Install|LastSuccessTime /rs > ========== Alternate Data Streams ========== @Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4 @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMPFC5A2B2 < End of report >

  10. #10
    smilliebob is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    OTL logfile created on: 03/12/2010 15:08:40 - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS

    Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe
    PRC - [2010/11/10 19:08:04 | 000,724,048 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
    PRC - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    PRC - [2010/10/27 05:15:24 | 001,073,504 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
    PRC - [2010/10/27 05:14:50 | 001,047,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
    PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
    PRC - [2010/10/22 04:57:54 | 002,745,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
    PRC - [2010/10/22 04:57:38 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
    PRC - [2010/10/22 0458 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
    PRC - [2010/10/22 0456 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
    PRC - [2010/10/22 0448 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
    PRC - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    PRC - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    PRC - [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    PRC - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    PRC - [2008/04/14 00:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
    PRC - [2008/02/26 01:23:34 | 000,443,968 | ---- | M] (Google Inc.) -- C:\Program Files\Picasa2\PicasaMediaDetector.exe
    PRC - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


    ========== Modules (SafeList) ==========

    MOD - [2010/12/03 15:05:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs\OTL.exe
    MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
    SRV - [2010/11/10 19:08:02 | 006,127,184 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
    SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
    SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
    SRV - [2010/05/14 10:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
    SRV - [2009/08/05 21:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
    SRV - [2008/11/09 20:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
    SRV - [2002/09/20 15:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\ROBERT~1\LOCALS~1\Temp\catchme.sys -- (catchme)
    DRV - [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
    DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
    DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
    DRV - [2010/09/07 03:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
    DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
    DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
    DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
    DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
    DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)
    DRV - [2010/07/12 04:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)
    DRV - [2009/08/05 21:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
    DRV - [2008/08/21 04:52:41 | 003,299,840 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
    DRV - [2008/04/13 18:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
    DRV - [2008/02/11 09:38:06 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys -- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
    DRV - [2005/04/20 08:44:12 | 000,124,672 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
    DRV - [2005/03/01 12:01:40 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
    DRV - [2004/10/08 11:59:11 | 000,326,656 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Camdrl.sys -- (CamDrL) Logitech QuickCam Pro 3000(CamDrl)
    DRV - [2004/10/08 11:57:48 | 000,022,016 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
    DRV - [2004/09/14 12:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)
    DRV - [2003/11/13 18:19:48 | 000,210,304 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
    DRV - [2003/11/13 18:18:36 | 000,679,808 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
    DRV - [2003/11/13 18:17:00 | 001,042,816 | R--- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
    DRV - [2003/01/10 21:13:04 | 000,033,588 | R--- | M] (America Online, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========


    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = Google Toolbar
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = AOL.co.uk
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = Google Toolbar
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = Google Toolbar
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = localhost;*.local

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "AOL Search"
    FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=tbff50sbox&query ="
    FF - prefs.js..browser.search.selectedEngine: "Ask"
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "http://www.plusnetwork.com"
    FF - prefs.js..extensions.enabledItems: {7affbfae-c4e2-4915-8c0f-00fa3ec610a1}:5.5.18.6
    FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
    FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=3235&invocationType=TBab-en-gb-web-aol-V55-winff&query="
    FF - prefs.js..network.proxy.no_proxies_on: "localhost,*.local"

    FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5 b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/30 21:53:26 | 000,000,000 | ---D | M]

    [2008/12/22 22:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Extensions
    [2009/01/01 13:38:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions
    [2008/12/27 21:59:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\ext ensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}
    [2008/12/27 22:05:29 | 000,001,774 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\aol-search.xml
    [2010/01/18 15:47:13 | 000,001,681 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Mozilla\Firefox\Profiles\nh397cjo.default\sea rchplugins\ask.uk.xml
    [2009/01/05 15:49:53 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
    [2008/10/09 14:03:07 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
    [2008/06/18 06:43:04 | 000,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
    [2008/10/04 20:24:00 | 003,695,008 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll

    O1 HOSTS File: ([2010/11/30 21:30:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
    O2 - BHO: (Easy Gif Animator Toolbar Helper) - {96372AB6-15EB-4316-B497-71C741BC548C} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
    O3 - HKCU\..\Toolbar\WebBrowser: (Easy Gif Animator Toolbar) - {35065594-9169-4A34-B167-FC4865038E53} - C:\Program Files\Easy Gif Animator Extension\v3.3.0.2\EasyGifAnimator_Toolbar.dll ()
    O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
    O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [MFARestart] C:\Documents and Settings\All Users\Application Data\MFAData\pack\avgrunasx.exe File not found
    O4 - HKCU..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
    O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: HonorAutoRunSetting = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoCDBurning = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveTypeAutoRun = 323
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDriveAutoRun = 67108863
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer: NoDrives = 0
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
    O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
    O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} http://www.bebo.com/files/BeboUploader.5.8.05.cab (Reg Error: Key error.)
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/s...irector/sw.cab (Shockwave ActiveX Control)
    O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} https://moneymanager.egg.com/Pinsafe...nttracking.cab (Reg Error: Key error.)
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/micr...?1202746562812 (MUWebControl Class)
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} Page not found | Facebook (Reg Error: Key error.)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary...o.cab56649.cab (Reg Error: Key error.)
    O16 - DPF: {BE71A78B-77DB-451C-A761-59B37022D544} Pixcetera.com (Reg Error: Key error.)
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} http://game07.zylom.com/activex/zylomgamesplayer.cab (Reg Error: Key error.)
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} https://ukplay.toontown.com/download....21/ttinst.cab (Reg Error: Key error.)
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary...t.cab56907.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_07)
    O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_12)
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab (Reg Error: Key error.)
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary...r.cab56986.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll File not found
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
    O24 - Desktop WallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O24 - Desktop BackupWallPaper: C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: 6to4 - File not found
    NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
    NetSvcs: Ias - File not found
    NetSvcs: Iprip - File not found
    NetSvcs: Irmon - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: WmdmPmSp - File not found

    Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
    Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
    Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
    Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
    Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
    Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
    Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
    Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point (16902109354000384)

    ========== Files/Folders - Created Within 30 Days ==========

    [2010/11/30 22:02:11 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
    [2010/11/30 21:53:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
    [2010/11/30 21:41:52 | 000,000,000 | --SD | C] -- C:\BobSmillie28274B
    [2010/11/30 21:35:54 | 000,000,000 | -HSD | C] -- C:\RECYCLER
    [2010/11/30 21:23:50 | 000,000,000 | RHSD | C] -- C:\cmdcons
    [2010/11/30 21:20:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
    [2010/11/30 21:20:49 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
    [2010/11/30 21:20:49 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
    [2010/11/30 21:20:49 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
    [2010/11/30 21:20:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
    [2010/11/30 21:20:41 | 000,000,000 | ---D | C] -- C:\BobSmillie
    [2010/11/30 20:48:25 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2010/11/27 10:19:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus scan results
    [2010/11/27 10:18:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    [2010/11/26 16:31:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Malwarebytes
    [2010/11/26 16:31:20 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
    [2010/11/26 16:31:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    [2010/11/26 16:31:16 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
    [2010/11/26 16:31:16 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
    [2010/11/20 19:00:57 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2010/11/20 19:00:38 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2010/11/20 18:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\Safari
    [2010/11/12 17:13:48 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Robert Smillie\Recent
    [2010/11/12 17:02:15 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2010/11/12 17:01:26 | 002,810,112 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/10 18:22:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search
    [2010/11/09 22:20:58 | 000,299,984 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/11/06 07:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
    [2010/11/06 0656 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search
    [2010/11/06 06:55:44 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
    [2010/11/06 06:55:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
    [2010/11/06 0617 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Robert Smillie\My Documents\My Data Sources

    ========== Files - Modified Within 30 Days ==========

    [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job
    [2010/12/03 14:25:01 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
    [2010/12/03 08:30:37 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
    [2010/12/03 08:30:27 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
    [2010/12/03 08:30:25 | 000,044,964 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
    [2010/12/02 19:25:37 | 100,786,927 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2010/12/01 00:42:54 | 000,636,239 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
    [2010/11/30 21:54:45 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
    [2010/11/30 21:30:10 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
    [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/27 17:47:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [2010/11/23 17:01:50 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101125-162138.backup
    [2010/11/21 22:09:26 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101123-170150.backup
    [2010/11/20 23:35:04 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
    [2010/11/20 17:45:56 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101121-220926.backup
    [2010/11/20 08:31:21 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-174556.backup
    [2010/11/20 07:52:39 | 000,427,353 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-083121.backup
    [2010/11/16 15:36:39 | 000,010,415 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx
    [2010/11/16 15:01:24 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\Microsoft Office Word 2007.lnk
    [2010/11/13 16:55:17 | 000,426,907 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101120-075238.backup
    [2010/11/12 17:08:50 | 000,264,918 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg
    [2010/11/12 17:02:16 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/10 1832 | 000,000,148 | ---- | M] () -- C:\WINDOWS\wininit.ini
    [2010/11/10 18:17:46 | 000,000,004 | ---- | M] () -- C:\WINDOWS\msoffice.ini
    [2010/11/09 22:20:58 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
    [2010/11/08 22:02:24 | 004,247,040 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps
    [2010/11/08 12:30:41 | 000,076,800 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc
    [2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
    [2010/11/06 0600 | 000,466,026 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
    [2010/11/06 0600 | 000,079,736 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
    [2010/11/04 23:04:03 | 000,426,195 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20101113-165517.backup
    [2010/11/04 17:13:53 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
    [2010/11/04 12:29:58 | 000,026,112 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc
    [2010/11/04 07:58:41 | 000,280,536 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
    [2010/11/03 23:13:40 | 000,046,592 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc

    ========== Files Created - No Company Name ==========

    [2010/12/02 19:25:37 | 100,786,927 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
    [2010/12/01 00:42:54 | 000,636,239 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
    [2010/11/30 21:54:45 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
    [2010/11/30 21:23:54 | 000,000,211 | ---- | C] () -- C:\Boot.bak
    [2010/11/30 21:23:51 | 000,260,272 | RHS- | C] () -- C:\cmldr
    [2010/11/30 21:20:49 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
    [2010/11/30 21:20:49 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
    [2010/11/30 21:20:49 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
    [2010/11/30 21:20:49 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
    [2010/11/30 21:20:49 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
    [2010/11/30 21:03:25 | 003,982,824 | R--- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Safari.lnk
    [2010/11/20 18:48:57 | 000,001,854 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
    [2010/11/16 15:36:39 | 000,010,415 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\Garden and Home auth No..docx
    [2010/11/12 17:08:45 | 000,264,918 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Desktop\cc_20101112_170837.reg
    [2010/11/12 17:02:16 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
    [2010/11/08 22:01:41 | 004,247,040 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\HUMAN-LIKEFLOWERS.pps
    [2010/11/08 12:30:38 | 000,076,800 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\DOC1047579.doc
    [2010/11/04 17:13:53 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
    [2010/11/04 12:29:57 | 000,026,112 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\SongChildrensDownInMyHeart.doc
    [2010/11/03 23:01:32 | 000,046,592 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\My Documents\William.doc
    [2009/06/05 17:12:03 | 000,000,021 | ---- | C] () -- C:\WINDOWS\.picasa.ini
    [2009/05/06 09:36:40 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Smiley.ico
    [2009/02/01 19:57:04 | 000,000,050 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
    [2008/12/19 19:33:06 | 000,000,111 | ---- | C] () -- C:\WINDOWS\ka.ini
    [2008/10/10 18:58:55 | 000,000,031 | -H-- | C] () -- C:\WINDOWS\UKCpInfo.sys
    [2008/07/20 00:01:48 | 000,000,148 | ---- | C] () -- C:\WINDOWS\wininit.ini
    [2008/04/02 14:42:13 | 000,000,004 | ---- | C] () -- C:\WINDOWS\msoffice.ini
    [2008/03/26 15:52:54 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
    [2008/03/25 1638 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
    [2008/02/17 22:40:29 | 000,000,071 | ---- | C] () -- C:\WINDOWS\EPSONCD.INI
    [2008/02/11 15:18:42 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
    [2008/02/11 14:33:42 | 000,006,812 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
    [2008/02/11 13:52:28 | 000,000,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\Setup.txt
    [2008/02/11 12:55:48 | 000,062,464 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/02/10 22:26:44 | 000,002,066 | ---- | C] () -- C:\Documents and Settings\Robert Smillie\Application Data\wklnhst.dat
    [2008/02/10 22:14:22 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
    [2008/02/10 22:11:18 | 000,000,025 | ---- | C] () -- C:\WINDOWS\CDE RX585DEFGIPS.ini
    [2008/02/09 19:57:25 | 000,000,996 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
    [2008/02/09 19:44:55 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
    [2008/01/04 21:58:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
    [2008/01/04 2124 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
    [2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
    [2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
    [2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
    [1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
    [1997/06/13 0708 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll

    ========== LOP Check ==========

    [2009/05/20 11:07:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\162CE
    [2009/05/07 09:51:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\302E
    [2009/05/06 09:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\33DA
    [2010/11/30 21:55:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
    [2010/10/28 16:50:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
    [2010/10/28 21:42:08 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
    [2008/02/10 22:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
    [2008/05/22 22:39:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
    [2010/01/18 15:47:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    [2010/11/30 21:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
    [2008/05/28 14:33:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
    [2010/11/30 20:52:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
    [2008/02/10 22:17:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
    [2008/02/11 09:28:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
    [2009/03/20 15:45:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\VUG
    [2008/04/22 09:36:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zylom
    [2009/04/04 17:44:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    [2010/09/04 18:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2009/10/10 18:41:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    [2009/05/02 20:03:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
    [2010/10/28 21:44:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\AVG10
    [2009/05/25 07:49:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Bamzooki
    [2008/03/13 15:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\EPSON
    [2009/07/10 08:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FontCreator
    [2008/02/11 14:30:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\FotoWire
    [2008/02/11 22:12:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Grisoft
    [2008/03/17 13:55:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\MSNInstaller
    [2010/11/02 17:15:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\OpenCandy
    [2008/02/11 13:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Simple Star
    [2008/02/12 14:10:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Template
    [2009/08/09 19:27:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Viewpoint
    [2010/11/06 0657 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Desktop Search
    [2009/10/16 12:50:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Live Writer
    [2010/11/10 18:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Robert Smillie\Application Data\Windows Search
    [2010/12/03 14:38:16 | 000,000,440 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{A0034571-0EBB-4498-B640-A1049143BCA4}.job

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2005/01/24 11:36:50 | 010,810,909 | ---- | M] () -- C:\avg70free_300a419.exe
    [2009/03/20 15:46:55 | 000,000,211 | ---- | M] () -- C:\Boot.bak
    [2010/11/30 21:23:54 | 000,000,327 | RHS- | M] () -- C:\boot.ini
    [2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
    [2008/02/09 19:55:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
    [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2008/02/11 14:29:42 | 000,000,183 | ---- | M] () -- C:\LogiSetup.log
    [2008/02/09 19:55:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
    [2008/08/27 22:42:54 | 000,250,048 | RHS- | M] () -- C:\ntldr
    [2010/12/03 08:30:21 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
    [2008/10/13 23:03:02 | 000,002,510 | ---- | M] () -- C:\playground.log
    [2008/04/02 14:59:47 | 000,004,104 | ---- | M] () -- C:\RndisAdaptorMgr.log
    [2008/02/09 21:50:12 | 000,000,164 | ---- | M] () -- C:\soundmax.log
    [2008/04/11 14:32:33 | 000,000,268 | -H-- | M] () -- C:\sqmdata00.sqm
    [2008/09/24 08:25:53 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
    [2008/09/24 08:25:53 | 000,000,148 | -H-- | M] () -- C:\sqmdata02.sqm
    [2009/01/07 15:25:26 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
    [2009/02/12 18:36:52 | 000,000,304 | -H-- | M] () -- C:\sqmdata04.sqm
    [2009/02/13 11:07:35 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
    [2009/03/03 15:16:08 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata07.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmdata08.sqm
    [2009/04/02 19:02:39 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
    [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata10.sqm
    [2009/04/02 19:02:40 | 000,000,136 | -H-- | M] () -- C:\sqmdata11.sqm
    [2008/04/11 14:32:33 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
    [2008/09/24 08:25:53 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
    [2008/09/24 08:25:53 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt02.sqm
    [2009/01/07 15:25:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
    [2009/02/12 18:36:52 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
    [2009/02/13 11:07:35 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
    [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
    [2009/03/03 15:16:08 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
    [2009/03/03 15:16:08 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt08.sqm
    [2009/04/02 19:02:39 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
    [2009/04/02 19:02:39 | 000,000,136 | -H-- | M] () -- C:\sqmnoopt10.sqm
    [2008/04/02 14:59:46 | 000,004,815 | ---- | M] () -- C:\St121PrismAdaptorMgr.log
    [2008/04/02 14:59:47 | 000,032,030 | ---- | M] () -- C:\StInstall.log
    [2008/04/02 14:59:43 | 000,000,784 | ---- | M] () -- C:\XPWiFiAdaptorMgr.log

    < %systemroot%\Fonts\*.com >
    [2006/04/18 14:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
    [2006/06/29 13:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
    [2006/04/18 14:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
    [2006/06/29 13:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2008/02/09 19:54:38 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/07/06 12:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpi pelineprintproc.dll
    [2006/10/26 1912 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr .dll
    [2008/07/06 10:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfil terpipelinesvc.exe

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2006/05/18 19:20:35 | 000,319,488 | ---- | M] (Nero AG / Nero Inc.) -- C:\WINDOWS\Nero PhotoShow.scr
    [2009/07/10 11:15:46 | 000,306,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2008/02/09 19:42:58 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
    [2008/02/09 19:42:58 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
    [2008/02/09 19:42:58 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
    [2008/08/27 22:49:32 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini

    < %systemroot%\system32\config\systemprofile\*.dat /x >
    [2008/02/09 1946 | 000,002,189 | ---- | M] () -- C:\WINDOWS\system32\config\systemprofile\dotNetFx. log

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2008/02/09 20:04:58 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
    [2008/02/09 20:04:57 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

    < %USERPROFILE%\Desktop\*.exe >
    [2008/10/13 16:29:42 | 036,663,808 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Documents and Settings\Robert Smillie\Desktop\8-9_xp32_dd_ccc_wdm_enu_68898.exe
    [2010/11/30 21:03:25 | 003,982,824 | R--- | M] () -- C:\Documents and Settings\Robert Smillie\Desktop\BobSmillie.exe
    [2010/11/12 17:01:35 | 002,810,112 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Robert Smillie\Desktop\ccsetup300.exe
    [2010/11/08 10:07:16 | 011,701,704 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Robert Smillie\Desktop\windows-kb890830-v3.12.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2008/02/09 20:04:57 | 000,000,122 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Favorites\Desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2009/02/13 12:14:05 | 000,000,067 | -HS- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\desktop.ini
    [2010/12/03 15:08:32 | 000,294,912 | ---- | M] () -- C:\Documents and Settings\Robert Smillie\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >
    [2007/06/26 22:10:26 | 000,317,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\inf\unregmp2.exe

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >
    [2008/04/14 00:11:51 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
    [2007/04/02 18:07:22 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
    [2008/05/02 14:01:49 | 000,083,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgsc.dll
    [2008/04/13 17:30:28 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
    [2008/04/14 00:12:28 | 001,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
    [2007/04/02 18:07:23 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
    [2007/04/02 18:07:23 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
    [2007/04/02 18:07:24 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
    [2007/04/02 18:07:27 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
    [2007/04/02 18:04:01 | 000,115,981 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto >

    < Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMPFC5A2B2

    < End of report >
    OTL Extras logfile created on: 03/12/2010 15:08:40 - Run 1
    OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Robert Smillie\Desktop\Anti virus programs
    Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

    1,023.00 Mb Total Physical Memory | 392.00 Mb Available Physical Memory | 38.00% Memory free
    2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
    Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 232.88 Gb Total Space | 192.15 Gb Free Space | 82.51% Space Free | Partition Type: NTFS

    Computer Name: HOME-A92CE30BAF | User Name: Robert Smillie | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows NT\SystemRestore]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Sr]
    "Start" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SrService]
    "Start" = 2

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile]
    "EnableFirewall" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile]
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\GloballyOpenPorts\List]

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\DomainPr ofile\AuthorizedApplications\List]
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SharedAccess\Parameters\FirewallPolicy\Standard Profile\AuthorizedApplications\List]
    "C:\WINDOWS\system32\ftp.exe" = C:\WINDOWS\system32\ftp.exe:*:Enabled:File Transfer Program -- (Microsoft Corporation)
    "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe:*isabled:Logitech Desktop Messenger -- (Logitech)
    "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:Cy berLink PowerDVD -- (CyberLink Corp.)
    "C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe" = C:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable -- (Microsoft Corporation)
    "C:\WINDOWS\system32\rtcshare.exe" = C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing -- (Microsoft Corporation)
    "C:\Program Files\NetMeeting\conf.exe" = C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting® -- (Microsoft Corporation)
    "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
    "C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe" = C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe:*isabled:Nero ShowTime Essentials -- (Nero AG)
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enable d:Yahoo! Messenger -- (Yahoo! Inc.)
    "C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
    "C:\Program Files\AVG\AVG10\avgdiagex.exe" = C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011 -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgam.exe" = C:\Program Files\AVG\AVG10\avgam.exe:*:Enabled:AVG Alert manager -- (AVG Technologies CZ, s.r.o.)
    "C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall]
    "{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
    "{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
    "{0A06D517-BEE7-2D03-9792-CF1A30E29A70}" = Skins
    "{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
    "{1481D8E3-EA17-7697-3738-F5AA7784C902}" = ccc-utility
    "{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
    "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
    "{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 12
    "{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
    "{2EB81825-E9EE-44F4-8F51-1240C3898DC6}" = EPSON File Manager
    "{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
    "{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
    "{3248F0A8-6813-11D6-A77B-00B0D0150000}" = J2SE Runtime Environment 5.0
    "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
    "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{3D78F2A2-C893-4ABD-B5FE-AD7011837755}" = EPSON Easy Photo Print
    "{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
    "{4C0F15CA-2032-5D72-F209-A89E02A5FE0F}" = CCC Help English
    "{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
    "{59A67AEF-CABF-32CA-5407-55049E899A11}" = Catalyst Control Center Graphics Light
    "{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
    "{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
    "{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
    "{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
    "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
    "{7CCEBC24-62DB-4280-A8EC-BFA49F167920}" = Software Update for Web Folders
    "{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
    "{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
    "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
    "{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
    "{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
    "{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{926CC8AE-8414-43DF-8EB4-CF26D9C3C663}" =
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{901A5511-070B-20DF-2F5A-5FA29C302C2A}" = Catalyst Control Center Graphics Full Existing
    "{93EA9C3E-BDFD-4309-A605-9B5BBC0CCEFD}" = Camera RAW Plug-In for EPSON Creativity Suite
    "{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
    "{943803CB-20FA-F4EB-E4A6-A3B055A1DC2E}" = ccc-core-preinstall
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
    "{9EE5A621-A673-37C4-E31A-A7D5696B6F29}" = Catalyst Control Center Graphics Previews Common
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
    "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
    "{B2F6B336-798D-77C2-21C9-392D4B0188F9}" = Catalyst Control Center Core Implementation
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
    "{B78EAA23-2D9B-CD91-6ABF-B96EC49BBA37}" = ccc-core-static
    "{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
    "{BEAD39CD-901D-4267-8B8B-EAA83CB4B70D}" = Pivot Stickfigure Animator
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C43048A9-742C-4DAD-90D2-E3B53C9DB825}" = Logitech QuickCam Software
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure
    "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
    "{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
    "{D9758C4B-CDD0-536F-D90E-9D74AFC3A35E}" = Catalyst Control Center Graphics Full New
    "{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
    "{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
    "{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2
    "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
    "{F17F7703-1E72-40C1-A0DD-E5B365661033}" = Nero 7 Essentials
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
    "{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
    "{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "All ATI Software" = ATI - Software Uninstall Utility
    "Ask.com Search Assistant" = Ask.com Search Assistant 1.0.2
    "ATI Display Driver" = ATI Display Driver
    "AVG" = AVG 2011
    "CamStudio" = CamStudio
    "CCleaner" = CCleaner
    "CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_20001 4F1" = SoftV92 Data Fax Modem with SmartCP
    "Coupon Printer2.0" = Coupon Printer
    "Disney Toontown Online_UK" = Disney Toontown Online UK_LIVE
    "Disney's Toontown Online" = Disney's Toontown Online
    "Easy Gif Animator Extension" = Easy Gif Animator Extension
    "Easy GIF Animator_is1" = Easy GIF Animator 4.9
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "EPSON Printer and Utilities" = EPSON Printer Software
    "EPSON Scanner" = EPSON Scan
    "EPSON Stylus Photo RX585_RX610 User’s Guide" = EPSON Stylus Photo RX585_RX610 Manual
    "ffdshow" = ffdshow (remove only)
    "FontCreator6_is1" = High-Logic FontCreator 6.0
    "GamewareBAMZOOKiCBBCTools1_is1" = BAMZOOKi v3.1 (build 115.158)
    "GIF Movie Gear_is1" = GIF Movie Gear 4.2
    "Google Chrome" = Google Chrome
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
    "InstallShield_{621C02EA-AAFF-4026-A903-165D59529A16}" = Driver Detective
    "InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
    "InstallShield_{CE7062BD-BE6F-4153-9654-3D72D0C1CC17}" = Zoo Tycoon 2 - African Adventure
    "Keepsake_Catwalk" = Keepsake Catwalk
    "Logitech Print Service" = Logitech Print Service
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Messenger Plus! Live" = Messenger Plus! Live
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "MSNINST" = MSN
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "Picasa 3" = Picasa 3
    "QcDrv" = Logitech® Camera Driver
    "ViewpointMediaPlayer" = Viewpoint Media Player
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinLiveSuite_Wave3" = Windows Live Essentials
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Yahoo! Messenger" = Yahoo! Messenger
    "Yahoo! Software Update" = Yahoo! Software Update
    "Zoo Tycoon 2" = Zoo Tycoon 2

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 25/10/2010 13:06:55 | Computer Name = HOME-A92CE30BAF | Source = crypt32 | ID = 131083
    Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
    with error: A required certificate is not within its validity period when verifying
    against the current system clock or the timestamp in the signed file.

    Error - 04/11/2010 20:17:07 | Computer Name = HOME-A92CE30BAF | Source = Microsoft Office 12 | ID = 5000
    Description = EventType officelifeboathang, P1 winword.exe, P2 12.0.6545.5000, P3
    ntdll.dll, P4 5.1.2600.5755, P5 NIL, P6 NIL, P7 NIL, P8 NIL, P9 NIL, P10 NIL.

    Error - 06/11/2010 02:57:04 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024
    Description = The update cannot be started because the content sources cannot be
    accessed. Fix the errors and try the update again. Context: Windows Application,
    SystemIndex Catalog

    Error - 06/11/2010 03:03:35 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application WINWORD.EXE, version 12.0.6545.5000, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 10/11/2010 19:32:53 | Computer Name = HOME-A92CE30BAF | Source = Windows Search Service | ID = 3024
    Description = The update cannot be started because the content sources cannot be
    accessed. Fix the errors and try the update again. Context: Application, SystemIndex
    Catalog

    Error - 13/11/2010 12:07:00 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application wabmig.exe, version 6.0.2900.5512, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 19/11/2010 19:27:54 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
    hungapp, version 0.0.0.0, hang address 0x00000000.

    Error - 20/11/2010 03:50:01 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    Error - 20/11/2010 03:53:36 | Computer Name = HOME-A92CE30BAF | Source = Application Hang | ID = 1002
    Description = Hanging application SDUpdate.exe, version 1.6.0.12, hang module hungapp,
    version 0.0.0.0, hang address 0x00000000.

    [ System Events ]
    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The fssfltr service depends on the TCP/IP Protocol Driver service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The DHCP Client service depends on the NetBios over Tcpip service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The DNS Client service depends on the TCP/IP Protocol Driver service
    which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
    failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The Bonjour Service service depends on the TCP/IP Protocol Driver
    service which failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7001
    Description = The IPSEC Services service depends on the IPSEC driver service which
    failed to start because of the following error: %%31

    Error - 30/11/2010 17:15:40 | Computer Name = HOME-A92CE30BAF | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip

    Error - 30/11/2010 17:16:27 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service wuauserv with
    arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error - 30/11/2010 17:18:18 | Computer Name = HOME-A92CE30BAF | Source = DCOM | ID = 10005
    Description = DCOM got error "%1084" attempting to start the service EventSystem
    with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


    < End of report >

+ Reply to Thread
Page 1 of 3 1 2 3 LastLast