OTL txt.

View previous topic View next topic Go down

OTL txt.

Post by snookiebird on Sat Apr 17, 2010 7:07 pm

OTL logfile created on: 4/17/2010 11:42:43 AM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Users\beaugina\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 236.00 Mb Available Physical Memory | 46.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 14.74 Gb Free Space | 39.56% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 7.45 Gb Total Space | 7.41 Gb Free Space | 99.48% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: BEAUGINA-PC
Current User Name: beaugina
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/04/17 11:40:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\beaugina\Desktop\OTL.exe
PRC - [2010/04/17 09:14:45 | 002,064,224 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/04/17 09:13:25 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/04/17 05:19:59 | 003,171,760 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2010/04/16 20:43:17 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/04/16 20:43:15 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/04/16 20:43:12 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/04/16 20:42:31 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/04/16 20:42:25 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/01/26 17:58:38 | 000,256,280 | R--- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashUtil10e.exe
PRC - [2009/10/15 02:51:51 | 000,263,600 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IEMonitor.exe
PRC - [2009/07/13 18:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/13 18:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sppsvc.exe
PRC - [2009/07/13 18:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007/05/28 15:29:14 | 000,303,104 | ---- | M] (EnGenius Technologies) -- C:\Program Files\EnGenius\ACU.exe


========== Modules (SafeList) ==========

MOD - [2010/04/17 11:40:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\beaugina\Desktop\OTL.exe
MOD - [2010/04/16 20:44:22 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
MOD - [2009/07/13 18:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/13 18:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/13 18:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/13 18:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/13 18:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/13 18:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/13 18:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/13 18:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/13 18:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/13 18:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/13 18:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/04/16 20:42:31 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/04/16 20:42:25 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2009/07/13 18:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/13 18:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/13 18:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/13 18:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/13 18:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/13 18:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/13 18:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/13 18:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/13 18:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/13 18:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/13 18:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/13 18:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/13 18:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/13 18:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/13 18:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2009/07/13 18:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/13 18:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2005/08/19 14:35:42 | 000,036,864 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\acs.exe -- (ACS)


========== Driver Services (SafeList) ==========

DRV - [2010/04/16 20:44:19 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2010/04/16 20:44:06 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2010/04/16 20:44:03 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/11/11 05:26:02 | 002,216,064 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\w29n51.sys -- (w29n51) Intel(R)
DRV - [2009/07/13 18:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009/07/13 18:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/13 18:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/13 18:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/13 18:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/13 18:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/13 18:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009/07/13 18:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/13 18:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009/07/13 18:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009/07/13 18:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009/07/13 18:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009/07/13 18:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/13 18:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/13 18:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009/07/13 18:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/13 18:20:36 | 000,133,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/07/13 18:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/13 18:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/13 18:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/13 18:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/13 18:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/13 18:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009/07/13 18:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/13 18:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/13 18:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/13 18:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/13 18:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/13 18:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 18:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009/07/13 18:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 18:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/13 18:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/13 18:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009/07/13 18:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/13 18:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009/07/13 18:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/13 18:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/13 18:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/13 18:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/13 18:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/13 18:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/13 17:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/13 17:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
DRV - [2009/07/13 17:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/13 16:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/13 16:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/13 16:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/13 16:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/13 16:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009/07/13 16:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/13 16:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/13 16:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/13 16:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009/07/13 16:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009/07/13 16:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009/07/13 16:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 16:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 16:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/13 16:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009/07/13 16:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009/07/13 16:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/13 15:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 15:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/13 15:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/13 15:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/13 15:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/13 15:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/13 15:13:48 | 001,035,776 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009/07/13 15:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/13 15:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/13 15:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2007/11/22 12:06:08 | 000,893,440 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\athrusb.sys -- (athrusb)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 06 11 C9 35 D9 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ACU] C:\Program Files\EnGenius\ACU.exe (EnGenius Technologies)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [UIUCU] C:\Users\beaugina\AppData\Local\Temp\UIUCU.EXE (Conexant Systems, Inc.)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O13 - gopher Prefix: missing
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [You must be registered and logged in to see this link.] (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/17 11:41:51 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Users\beaugina\Desktop\OTL.exe
[2010/04/17 05:19:28 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\IDM
[2010/04/17 05:19:28 | 000,000,000 | ---D | C] -- C:\Users\beaugina\Documents\Downloads
[2010/04/17 05:19:23 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\DMCache
[2010/04/17 05:19:09 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Download Manager
[2010/04/17 04:50:20 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Blitware
[2010/04/17 04:50:01 | 000,000,000 | ---D | C] -- C:\Program Files\Driver Fetch
[2010/04/16 20:44:20 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2010/04/16 20:44:13 | 000,242,696 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/04/16 20:44:05 | 000,216,200 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2010/04/16 20:44:01 | 000,029,512 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2010/04/16 20:43:52 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\Avg
[2010/04/16 16:16:43 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Malwarebytes
[2010/04/16 16:16:32 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/16 16:16:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/04/16 16:16:30 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/16 16:16:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/14 07:37:44 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010/04/14 07:35:55 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/04/14 07:35:53 | 000,000,000 | ---D | C] -- C:\ProgramData\avg9
[2010/04/14 00:11:33 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/04/14 00:11:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/04/14 00:11:04 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
[2010/04/13 23:51:31 | 000,000,000 | ---D | C] -- C:\Program Files\Analog Devices
[2010/04/12 15:47:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Hewlett-Packard
[2010/04/12 15:43:21 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2010/04/12 03:55:36 | 000,292,864 | ---- | C] (Conexant Systems Inc.) -- C:\Windows\System32\drivers\CAMCAUD.SYS
[2010/04/12 03:55:36 | 000,276,480 | ---- | C] (Conexant Systems Inc.) -- C:\Windows\System32\drivers\CAMCHAL.SYS
[2010/04/12 03:55:36 | 000,032,248 | ---- | C] (Conexant Systems, Inc.) -- C:\Windows\System32\CAUDINST.DLL
[2010/04/12 03:55:36 | 000,028,672 | ---- | C] (Conexant Systems Inc.) -- C:\Windows\CIAUNWDM.EXE
[2010/04/12 03:55:24 | 000,000,000 | ---D | C] -- C:\Windows\OPTIONS
[2010/04/12 03:54:57 | 000,000,000 | ---D | C] -- C:\swsetup
[2010/04/12 02:37:39 | 000,000,000 | ---D | C] -- C:\Download
[2010/04/11 19:57:14 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\beaugina\AppData\Roaming\pcouffin.sys
[2010/04/11 19:57:13 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Vso
[2010/04/11 19:57:13 | 000,000,000 | ---D | C] -- C:\Users\beaugina\Documents\PcSetup
[2010/04/11 06:25:17 | 000,000,000 | ---D | C] -- C:\tmp
[2010/04/11 06:24:16 | 000,000,000 | ---D | C] -- C:\tmpDownload
[2010/04/11 06:23:24 | 000,000,000 | ---D | C] -- C:\YouTubeGet
[2010/04/11 02:25:45 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\Microsoft Games
[2010/04/11 01:12:55 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\Adobe
[2010/04/11 01:11:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2010/04/11 01:10:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2010/04/11 01:10:28 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2010/04/11 01:09:29 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2010/04/11 00:54:40 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\ElevatedDiagnostics
[2010/04/10 22:29:15 | 000,181,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/04/10 22:27:10 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\WinRAR
[2010/04/10 22:20:11 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Macromedia
[2010/04/10 22:20:11 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Adobe
[2010/04/10 22:20:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2010/04/10 22:12:18 | 000,893,440 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athrusb.sys
[2010/04/10 22:11:45 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\InstallShield
[2010/04/10 22:04:13 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\Diagnostics
[2010/04/10 21:57:54 | 000,343,904 | ---- | C] (WLAN Communications, Inc.) -- C:\Windows\System32\ar5523.sys
[2010/04/10 21:57:43 | 001,396,835 | ---- | C] (Meetinghouse Data Communications) -- C:\Windows\System32\AegisE5.dll
[2010/04/10 21:57:43 | 000,385,024 | ---- | C] (Atheros) -- C:\Windows\System32\athcfg11.dll
[2010/04/10 21:57:43 | 000,249,856 | ---- | C] (EnGenius) -- C:\Windows\System32\wgapi.dll
[2010/04/10 21:57:43 | 000,237,568 | ---- | C] (Atheros) -- C:\Windows\System32\wcapi.dll
[2010/04/10 21:57:43 | 000,077,824 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\System32\athcfg11res.dll
[2010/04/10 21:57:43 | 000,000,000 | ---D | C] -- C:\Program Files\EnGenius
[2010/04/10 21:57:40 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2010/04/10 21:56:47 | 000,000,000 | ---D | C] -- C:\temp
[2010/04/10 21:56:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/04/10 21:50:39 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2010/04/10 21:40:59 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/04/10 21:37:46 | 000,000,000 | ---D | C] -- C:\Windows.old
[2010/04/10 21:36:58 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Searches
[2010/04/10 21:36:41 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Identities
[2010/04/10 21:36:38 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Contacts
[2010/04/10 21:36:29 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\VirtualStore
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\AppData\Local\Temporary Internet Files
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Templates
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Start Menu
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\SendTo
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Recent
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\PrintHood
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\NetHood
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Documents\My Videos
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Documents\My Pictures
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Documents\My Music
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\My Documents
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Local Settings
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\AppData\Local\History
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Cookies
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\Application Data
[2010/04/10 21:36:25 | 000,000,000 | -HSD | C] -- C:\Users\beaugina\AppData\Local\Application Data
[2010/04/10 21:36:24 | 000,000,000 | --SD | C] -- C:\Users\beaugina\AppData\Roaming\Microsoft
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Videos
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Saved Games
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Pictures
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Music
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Links
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Favorites
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Downloads
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\My Documents
[2010/04/10 21:36:24 | 000,000,000 | R--D | C] -- C:\Users\beaugina\Desktop
[2010/04/10 21:36:24 | 000,000,000 | -H-D | C] -- C:\Users\beaugina\AppData
[2010/04/10 21:36:24 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\Temp
[2010/04/10 21:36:24 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Local\Microsoft
[2010/04/10 21:36:24 | 000,000,000 | ---D | C] -- C:\Users\beaugina\AppData\Roaming\Media Center Programs
[2010/04/10 21:36:09 | 000,000,000 | -HSD | C] -- C:\Recovery
[2010/04/10 20:55:48 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/04/10 20:52:15 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010/04/10 13:06:55 | 000,000,000 | -H-D | C] -- C:\Config.Msi
[2010/04/08 17:06:23 | 000,000,000 | -HSD | C] -- C:\Boot
[2010/04/08 16:10:51 | 000,000,000 | -HSD | C] -- C:\System Volume Information

========== Files - Modified Within 30 Days ==========

[2010/04/17 11:45:15 | 001,048,576 | -HS- | M] () -- C:\Users\beaugina\ntuser.dat
[2010/04/17 11:40:27 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Users\beaugina\Desktop\OTL.exe
[2010/04/17 11:18:21 | 000,009,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/17 11:18:21 | 000,009,584 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/17 09:14:25 | 058,998,812 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010/04/17 08:20:26 | 000,713,888 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/04/17 08:20:26 | 000,615,360 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/04/17 08:20:26 | 000,103,702 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/04/17 08:15:48 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/04/17 08:15:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/04/17 08:15:16 | 402,202,624 | -HS- | M] () -- C:\hiberfil.sys
[2010/04/17 07:57:08 | 001,500,334 | -H-- | M] () -- C:\Users\beaugina\AppData\Local\IconCache.db
[2010/04/17 05:23:58 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\Driver Fetch.job
[2010/04/16 20:44:23 | 000,001,812 | ---- | M] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/04/16 20:44:22 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
[2010/04/16 20:44:19 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgtdix.sys
[2010/04/16 20:44:06 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgldx86.sys
[2010/04/16 20:44:03 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\drivers\avgmfx86.sys
[2010/04/16 20:44:01 | 000,113,461 | ---- | M] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/04/16 16:35:17 | 000,001,984 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/16 16:16:35 | 000,000,979 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/15 00:04:41 | 000,524,288 | -HS- | M] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TMContainer00000000000000000002.regtrans-ms
[2010/04/15 00:04:41 | 000,524,288 | -HS- | M] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TMContainer00000000000000000001.regtrans-ms
[2010/04/15 00:04:41 | 000,065,536 | -HS- | M] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TM.blf
[2010/04/12 04:54:57 | 000,087,608 | ---- | M] () -- C:\Users\beaugina\AppData\Roaming\inst.exe
[2010/04/12 04:54:57 | 000,047,360 | ---- | M] (VSO Software) -- C:\Users\beaugina\AppData\Roaming\pcouffin.sys
[2010/04/12 04:54:57 | 000,007,887 | ---- | M] () -- C:\Users\beaugina\AppData\Roaming\pcouffin.cat
[2010/04/12 04:54:57 | 000,001,144 | ---- | M] () -- C:\Users\beaugina\AppData\Roaming\pcouffin.inf
[2010/04/11 21:42:06 | 000,000,668 | ---- | M] () -- C:\Users\beaugina\AppData\Roaming\vso_ts_preview.xml
[2010/04/11 06:23:57 | 000,034,308 | ---- | M] () -- C:\ProgramData\mazuki.dll
[2010/04/11 02:24:53 | 000,057,560 | ---- | M] () -- C:\Users\beaugina\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/11 01:31:40 | 000,000,232 | ---- | M] () -- C:\Users\beaugina\Desktop\Umatilla County Jail Roster.url
[2010/04/10 22:36:16 | 000,001,413 | ---- | M] () -- C:\Users\beaugina\Desktop\Internet Explorer.lnk
[2010/04/10 22:27:10 | 016,350,245 | ---- | M] () -- C:\Users\beaugina\Documents\Windows_7_All_versions.rar
[2010/04/10 21:58:07 | 000,524,288 | -HS- | M] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/04/10 21:58:07 | 000,524,288 | -HS- | M] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/04/10 21:58:07 | 000,065,536 | -HS- | M] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/04/10 21:50:27 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/04/10 21:36:25 | 000,000,020 | -HS- | M] () -- C:\Users\beaugina\ntuser.ini
[2010/04/10 21:36:03 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/04/10 21:09:04 | 000,266,808 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/04/10 20:57:33 | 000,042,045 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2010/04/17 04:50:23 | 000,000,340 | ---- | C] () -- C:\Windows\tasks\Driver Fetch.job
[2010/04/16 20:44:23 | 000,001,812 | ---- | C] () -- C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/04/16 20:44:01 | 000,113,461 | ---- | C] () -- C:\Windows\System32\drivers\Avg\iavichjw.avm
[2010/04/16 20:43:52 | 058,998,812 | ---- | C] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010/04/16 16:16:35 | 000,000,979 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/14 22:48:56 | 000,524,288 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TMContainer00000000000000000002.regtrans-ms
[2010/04/14 22:48:56 | 000,524,288 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TMContainer00000000000000000001.regtrans-ms
[2010/04/14 22:48:56 | 000,065,536 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat{1e4cb863-4850-11df-9156-000fb391f0b1}.TM.blf
[2010/04/12 15:43:34 | 000,000,618 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010/04/12 02:56:58 | 016,350,245 | ---- | C] () -- C:\Users\beaugina\Documents\Windows_7_All_versions.rar
[2010/04/11 19:59:14 | 000,000,668 | ---- | C] () -- C:\Users\beaugina\AppData\Roaming\vso_ts_preview.xml
[2010/04/11 19:58:26 | 000,000,033 | ---- | C] () -- C:\Users\beaugina\AppData\Roaming\pcouffin.log
[2010/04/11 19:57:14 | 000,087,608 | ---- | C] () -- C:\Users\beaugina\AppData\Roaming\inst.exe
[2010/04/11 19:57:14 | 000,007,887 | ---- | C] () -- C:\Users\beaugina\AppData\Roaming\pcouffin.cat
[2010/04/11 19:57:14 | 000,001,144 | ---- | C] () -- C:\Users\beaugina\AppData\Roaming\pcouffin.inf
[2010/04/11 06:23:57 | 000,034,308 | ---- | C] () -- C:\ProgramData\mazuki.dll
[2010/04/11 01:31:40 | 000,000,232 | ---- | C] () -- C:\Users\beaugina\Desktop\Umatilla County Jail Roster.url
[2010/04/11 01:17:46 | 000,001,984 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/10 22:36:16 | 000,001,413 | ---- | C] () -- C:\Users\beaugina\Desktop\Internet Explorer.lnk
[2010/04/10 21:57:54 | 000,149,544 | ---- | C] () -- C:\Windows\System32\ar5523.bin
[2010/04/10 21:57:54 | 000,013,005 | ---- | C] () -- C:\Windows\System32\net5523.inf
[2010/04/10 21:57:43 | 000,192,512 | ---- | C] () -- C:\Windows\System32\AegisI5.exe
[2010/04/10 21:57:43 | 000,036,864 | ---- | C] () -- C:\Windows\System32\acs.exe
[2010/04/10 21:36:25 | 000,524,288 | -HS- | C] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/04/10 21:36:25 | 000,524,288 | -HS- | C] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/04/10 21:36:25 | 000,000,020 | -HS- | C] () -- C:\Users\beaugina\ntuser.ini
[2010/04/10 21:36:24 | 001,048,576 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat
[2010/04/10 21:36:24 | 000,262,144 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat.LOG1
[2010/04/10 21:36:24 | 000,065,536 | -HS- | C] () -- C:\Users\beaugina\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/04/10 21:36:24 | 000,000,000 | -HS- | C] () -- C:\Users\beaugina\ntuser.dat.LOG2
[2010/04/10 21:36:03 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/04/10 20:51:38 | 402,202,624 | -HS- | C] () -- C:\hiberfil.sys
[2010/04/08 17:06:27 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2010/04/08 17:06:24 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2010/04/08 16:24:06 | 000,171,136 | RHS- | C] () -- C:\LHLDR
[2009/07/13 16:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >

snookiebird
Novice
Novice

Posts Posts : 18
Joined Joined : 2009-07-04
OS OS : xp
Points Points : 27210
# Likes # Likes : 0

View user profile

Back to top Go down

Re: OTL txt.

Post by Belahzur on Sat Apr 17, 2010 7:19 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum