Random adverts playing in background with no windows open

Page 2 of 2 Previous  1, 2

View previous topic View next topic Go down

Random adverts playing in background with no windows open

Post by MBvash on Wed 28 Jul 2010, 3:52 pm

First topic message reminder :

Several random advert audio clips have been periodically playing in the background even when no windows are open. This started happening about 8 hours ago just after I had completed my install of Starcraft II. (great game so far! aside from the random advertisement interruptions!) Not sure if there is a correlation here but I had some problems with Antivir pro starting about a month ago. I have had two encounters with it, both times I did a system restore and things were fine. I've done a full AVG scan and Malwarebyte scans with no results.

Thanks!

OTL logfile created on: 7/27/2010 11:10:38 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\JAg\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 51.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 87.89 Gb Total Space | 15.25 Gb Free Space | 17.35% Space Free | Partition Type: NTFS
Drive D: | 210.14 Gb Total Space | 22.90 Gb Free Space | 10.90% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 641.66 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: LAPTOP
Current User Name: JAg
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2010/07/27 23:09:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\JAg\Desktop\OTL.com
PRC - [2010/07/09 12:10:18 | 002,048,352 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2010/04/28 13:15:02 | 002,633,976 | ---- | M] (Veoh Networks) -- C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
PRC - [2009/08/24 09:19:57 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/08/24 09:19:57 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/24 09:19:54 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/24 09:19:49 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/08/24 09:19:45 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/04/07 00:02:13 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/12 18:36:24 | 000,086,016 | ---- | M] () -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
PRC - [2008/12/11 07:08:52 | 003,575,808 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
PRC - [2008/06/11 22:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2008/02/15 19:25:34 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe
PRC - [2008/02/15 19:23:20 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2008/01/18 23:38:40 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/09/20 16:31:10 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\AEstSrv.exe
PRC - [2007/07/25 16:41:42 | 000,647,168 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2007/07/25 16:22:44 | 000,327,680 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2007/05/28 11:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
PRC - [2007/05/09 17:01:00 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM02Mon.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2010/07/27 23:09:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\JAg\Desktop\OTL.com
MOD - [2009/08/24 09:19:57 | 000,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Windows\System32\avgrsstx.dll
MOD - [2008/01/18 23:33:02 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2008/01/18 23:26:36 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - [2009/08/24 09:19:49 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2009/08/24 09:19:45 | 000,908,056 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc)
SRV - [2009/07/16 17:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/04/15 15:46:49 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/03/12 18:36:24 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe -- (mi-raysat_3dsmax2010_32)
SRV - [2008/12/11 07:08:52 | 003,575,808 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe -- (NVIDIA Performance Driver Service)
SRV - [2008/06/06 00:41:12 | 001,322,648 | ---- | M] (Autodesk, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service)
SRV - [2008/02/15 19:25:34 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\stacsv.exe -- (STacSV)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/09/20 16:31:10 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\AEstSrv.exe -- (AESTFilters)
SRV - [2007/07/25 16:41:42 | 000,647,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2007/07/25 16:22:44 | 000,327,680 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2007/05/28 11:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2009/09/28 03:02:42 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV - [2009/08/24 09:19:57 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2009/08/24 09:19:57 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/08/01 16:22:11 | 000,716,272 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/06/03 16:16:16 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2009/04/28 03:08:00 | 009,838,400 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2008/02/15 19:27:02 | 000,330,752 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008/02/15 19:01:18 | 000,046,592 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/10/10 17:03:00 | 000,235,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/09/26 08:12:00 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R)
DRV - [2007/09/17 11:22:00 | 000,278,528 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\yk60x86.sys -- (yukonwlh)
DRV - [2007/07/30 12:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 11:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/06/02 15:59:42 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerGuardian2\pgfilter.sys -- (pgfilter)
DRV - [2007/03/05 10:45:04 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2007/02/21 14:49:47 | 000,017,512 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2007/02/21 14:49:47 | 000,016,488 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2007/02/21 14:49:47 | 000,014,952 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/01/06 00:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2007/01/06 00:59:34 | 000,086,096 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid) NVIDIA nForce(tm)
DRV - [2006/11/02 04:51:45 | 000,900,712 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2006/11/02 04:51:25 | 000,232,040 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2006/11/02 04:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2006/11/02 04:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2006/11/02 04:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid2.sys -- (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2006/11/02 03:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,117,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel(R)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:7
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 9
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.backup.ftp: "141.24.33.192"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "141.24.33.192"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "141.24.33.192"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "141.24.33.192"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "93.186.192.85"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "93.186.192.85"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "93.186.192.85"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "93.186.192.85"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "93.186.192.85"
FF - prefs.js..network.proxy.ssl_port: 3128

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 10:32:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/25 09:13:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/27 23:01:30 | 000,000,000 | ---D | M]

[2009/04/06 21:37:22 | 000,000,000 | ---D | M] -- C:\Users\JAg\AppData\Roaming\Mozilla\Extensions
[2010/07/27 22:46:38 | 000,000,000 | ---D | M] -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions
[2009/11/09 06:22:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions\{11483926-db67-4190-91b1-ef20fcec5f33}
[2009/07/01 17:10:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/07/22 06:34:50 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/12/10 23:46:46 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/10/25 09:05:16 | 000,000,000 | ---D | M] -- C:\Users\JAg\AppData\Roaming\Mozilla\Firefox\Profiles\0lbuexr3.default\extensions\firefox@tvunetworks.com
[2010/07/27 22:46:39 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/07/27 22:44:40 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/27 22:44:32 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/05/03 00:24:39 | 000,239,432 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2008/10/22 00:36:52 | 000,001,231 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Client] C:\Windows\System32\Client.exe File not found
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Winsys32sys] C:\Windows\System32\Client.exe File not found
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe ()
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - HKCU..\Run: [Video Library] C:\Users\JAg\AppData\Local\Temp\Rpcqt.DLL (Safer Networking Limited )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} [You must be registered and logged in to see this link.] (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\JAg\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\JAg\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/08 13:14:52 | 000,000,000 | ---D | M] - C:\autodesk -- [ NTFS ]
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2000/05/11 06:13:12 | 000,000,046 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{83a8ea48-7ee1-11de-bf50-001fe1dc1585}\Shell - "" = AutoRun
O33 - MountPoints2\{83a8ea48-7ee1-11de-bf50-001fe1dc1585}\Shell\AutoRun\command - "" = F:\SETUP.EXE -- [2000/05/20 22:36:50 | 000,032,768 | R--- | M] ()
O33 - MountPoints2\{87e70dfa-2587-11de-a1ec-001fe1dc1585}\Shell\AutoRun\command - "" = Autorun.exe /run
O33 - MountPoints2\{87e70dfa-2587-11de-a1ec-001fe1dc1585}\Shell\Shell00\Command - "" = Autorun.exe /run
O33 - MountPoints2\{87e70dfa-2587-11de-a1ec-001fe1dc1585}\Shell\Shell01\Command - "" = Autorun.exe /action
O33 - MountPoints2\{87e70dfa-2587-11de-a1ec-001fe1dc1585}\Shell\Shell02\Command - "" = Autorun.exe /uninstall
O33 - MountPoints2\{c7fcf18f-73bf-11de-8209-001fe1dc1585}\Shell - "" = AutoRun
O33 - MountPoints2\{c7fcf18f-73bf-11de-8209-001fe1dc1585}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found


SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {1C8B5F0A-4EDE-D808-8904-C2356E5E3223} - Microsoft Windows Media Player
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {26C6F5DD-8B95-CB98-CCBE-19CDD2694BC4} - Java (Sun)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2FEE7374-62BB-3C64-C54A-D38252274737} - Microsoft Windows Media Player 11.0
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4B4A5348-3DF7-A010-8B29-F20AF53646C7} - Java (Sun)
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5245C883-6CCE-6C96-BB48-905553E6DF5A} - Offline Browsing Pack
ActiveX: {5B436709-90AA-5EA6-2F59-0C56CD090F0A} - Microsoft Windows Media Player 11.0
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7092AF14-F518-8AE0-F720-90ED52756A48} - Internet Explorer
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {7D24AFE3-0CDD-F190-83E6-7C01E11312CB} - Microsoft Windows Media Player
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {9C450606-ED24-4958-92BA-B8940C99D441} - C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
ActiveX: {AAC3F1F0-5649-4670-A698-F1523729F015} - Microsoft .NET Framework 1.1 Hotfix (KB929729)
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: {EF7CDA6F-CAFE-225B-585D-9EFF9FC7650C} - Themes Setup
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2010/07/27 23:10:13 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\JAg\Desktop\OTL.com
[2010/07/27 23:04:07 | 002,421,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2010/07/27 23:04:07 | 000,044,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2010/07/27 23:03:44 | 000,171,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2010/07/27 23:03:44 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2010/07/27 22:46:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/07/27 22:44:38 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/07/27 22:44:38 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/07/27 22:44:38 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/07/27 22:43:32 | 016,062,240 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\JAg\Desktop\jre-6u21-windows-i586.exe
[2010/07/27 22:42:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/07/27 22:41:44 | 000,423,656 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010/07/27 15:29:25 | 000,000,000 | ---D | C] -- C:\Users\JAg\Documents\StarCraft II
[2010/07/27 15:29:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2010/07/27 15:29:25 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Blizzard Entertainment
[2010/07/27 13:38:13 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2010/07/27 13:38:10 | 000,000,000 | ---D | C] -- C:\Users\JAg\AppData\Roaming\SystemRequirementsLab
[2010/07/23 20:25:37 | 000,094,208 | ---- | C] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010/07/23 20:23:55 | 000,000,000 | ---D | C] -- C:\Program Files\Diablo II
[2010/07/22 21:02:36 | 000,000,000 | ---D | C] -- C:\Program Files\Starcraft
[2010/07/21 16:34:49 | 000,000,000 | ---D | C] -- C:\Users\JAg\AppData\Local\Deployment
[2010/07/21 16:34:49 | 000,000,000 | ---D | C] -- C:\Users\JAg\AppData\Local\Apps
[2010/07/16 23:00:41 | 000,000,000 | ---D | C] -- C:\Users\JAg\AppData\Roaming\Malwarebytes
[2010/07/16 23:00:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/16 23:00:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/07/16 23:00:33 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/07/16 23:00:33 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/16 21:58:18 | 000,000,000 | ---D | C] -- C:\Users\JAg\Desktop\Somaliland
[2010/07/12 08:42:25 | 000,000,000 | ---D | C] -- C:\Program Files\Veoh Networks
[2010/07/06 13:33:28 | 000,139,264 | ---- | C] (Blizzard Entertainment) -- C:\Windows\War3Unin.exe

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2010/07/27 23:15:08 | 004,980,736 | -HS- | M] () -- C:\Users\JAg\ntuser.dat
[2010/07/27 23:09:35 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\JAg\Desktop\OTL.com
[2010/07/27 23:02:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/07/27 23:02:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/07/27 23:01:30 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/27 22:52:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4177002003-3084292159-914443694-1000UA.job
[2010/07/27 22:44:32 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/07/27 22:44:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/07/27 22:44:32 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/07/27 22:44:31 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2010/07/27 22:39:48 | 016,062,240 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\JAg\Desktop\jre-6u21-windows-i586.exe
[2010/07/27 22:24:28 | 000,708,438 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/07/27 22:24:28 | 000,607,356 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/07/27 22:24:28 | 000,106,220 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/07/27 22:20:46 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/07/27 22:19:53 | 000,879,082 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/07/27 22:18:46 | 000,879,082 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/07/27 22:18:34 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/27 22:18:34 | 000,003,664 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/27 22:18:30 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/07/27 22:18:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/07/27 22:18:20 | 3756,064,768 | -HS- | M] () -- C:\hiberfil.sys
[2010/07/27 22:17:19 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/07/27 22:17:13 | 000,524,288 | -HS- | M] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TMContainer00000000000000000001.regtrans-ms
[2010/07/27 22:17:13 | 000,065,536 | -HS- | M] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TM.blf
[2010/07/27 22:17:10 | 002,751,697 | -H-- | M] () -- C:\Users\JAg\AppData\Local\IconCache.db
[2010/07/27 16:36:37 | 062,646,716 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2010/07/27 15:52:00 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4177002003-3084292159-914443694-1000Core.job
[2010/07/27 15:51:24 | 000,000,720 | ---- | M] () -- C:\Users\Public\Desktop\StarCraft II.lnk
[2010/07/27 15:28:41 | 000,216,576 | ---- | M] () -- C:\Users\JAg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/26 21:04:53 | 000,165,339 | ---- | M] () -- C:\Users\JAg\Desktop\LooseChange.jpg
[2010/07/26 10:28:30 | 000,002,255 | ---- | M] () -- C:\Users\JAg\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/23 20:38:24 | 000,043,520 | ---- | M] () -- C:\Windows\System32\CmdLineExt03.dll
[2010/07/23 20:38:21 | 000,019,036 | ---- | M] () -- C:\Windows\DIIUnin.dat
[2010/07/23 20:33:25 | 000,021,840 | ---- | M] () -- C:\Windows\System32\SIntfNT.dll
[2010/07/23 20:33:25 | 000,017,212 | ---- | M] () -- C:\Windows\System32\SIntf32.dll
[2010/07/23 20:33:25 | 000,012,067 | ---- | M] () -- C:\Windows\System32\SIntf16.dll
[2010/07/23 20:25:38 | 000,001,686 | ---- | M] () -- C:\Users\JAg\Desktop\Diablo II.lnk
[2010/07/23 20:25:37 | 000,094,208 | ---- | M] (Blizzard Entertainment) -- C:\Windows\DIIUnin.exe
[2010/07/23 20:25:37 | 000,002,829 | ---- | M] () -- C:\Windows\DIIUnin.pif
[2010/07/22 21:04:06 | 000,000,816 | ---- | M] () -- C:\Users\JAg\Desktop\StarCraft.lnk
[2010/07/19 12:23:19 | 000,018,314 | ---- | M] () -- C:\Users\JAg\Desktop\image001.gif
[2010/07/19 11:13:45 | 000,067,074 | ---- | M] () -- C:\Users\JAg\Desktop\36378682.nairobiaerials014.jpg
[2010/07/19 11:13:31 | 000,117,198 | ---- | M] () -- C:\Users\JAg\Desktop\36378684.nairobiaerials026.JPG
[2010/07/18 21:35:43 | 000,133,170 | ---- | M] () -- C:\Users\JAg\Desktop\1279506735173.jpg
[2010/07/16 23:00:37 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/16 20:40:41 | 000,524,288 | -HS- | M] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TMContainer00000000000000000002.regtrans-ms
[2010/07/16 20:36:34 | 000,524,288 | -HS- | M] () -- C:\Users\JAg\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/07/16 20:36:34 | 000,065,536 | -HS- | M] () -- C:\Users\JAg\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/07/13 22:10:55 | 000,019,816 | ---- | M] () -- C:\Users\JAg\Desktop\1279075000502.jpg
[2010/07/08 22:55:46 | 000,014,953 | ---- | M] () -- C:\Users\JAg\Desktop\1278641823792s.jpg
[2010/07/06 14:36:55 | 000,077,054 | ---- | M] () -- C:\Windows\War3Unin.dat
[2010/07/06 14:02:55 | 000,139,264 | ---- | M] (Blizzard Entertainment) -- C:\Windows\War3Unin.exe
[2010/07/06 14:02:55 | 000,002,829 | ---- | M] () -- C:\Windows\War3Unin.pif
[2010/07/05 16:30:34 | 000,002,255 | ---- | M] () -- C:\Users\JAg\Desktop\iTunes.lnk
[2010/06/30 19:37:02 | 000,000,680 | ---- | M] () -- C:\Users\JAg\AppData\Local\d3d9caps.dat

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2010/07/27 23:01:30 | 000,001,887 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/07/27 15:29:25 | 000,000,720 | ---- | C] () -- C:\Users\Public\Desktop\StarCraft II.lnk
[2010/07/26 21:04:53 | 000,165,339 | ---- | C] () -- C:\Users\JAg\Desktop\LooseChange.jpg
[2010/07/23 20:38:24 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2010/07/23 20:26:32 | 000,021,840 | ---- | C] () -- C:\Windows\System32\SIntfNT.dll
[2010/07/23 20:26:32 | 000,017,212 | ---- | C] () -- C:\Windows\System32\SIntf32.dll
[2010/07/23 20:26:32 | 000,012,067 | ---- | C] () -- C:\Windows\System32\SIntf16.dll
[2010/07/23 20:25:38 | 000,019,036 | ---- | C] () -- C:\Windows\DIIUnin.dat
[2010/07/23 20:25:38 | 000,001,686 | ---- | C] () -- C:\Users\JAg\Desktop\Diablo II.lnk
[2010/07/23 20:25:37 | 000,002,829 | ---- | C] () -- C:\Windows\DIIUnin.pif
[2010/07/22 21:04:06 | 000,000,816 | ---- | C] () -- C:\Users\JAg\Desktop\StarCraft.lnk
[2010/07/19 12:23:19 | 000,018,314 | ---- | C] () -- C:\Users\JAg\Desktop\image001.gif
[2010/07/19 11:13:45 | 000,067,074 | ---- | C] () -- C:\Users\JAg\Desktop\36378682.nairobiaerials014.jpg
[2010/07/19 11:13:31 | 000,117,198 | ---- | C] () -- C:\Users\JAg\Desktop\36378684.nairobiaerials026.JPG
[2010/07/18 21:35:43 | 000,133,170 | ---- | C] () -- C:\Users\JAg\Desktop\1279506735173.jpg
[2010/07/16 23:00:37 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/16 20:40:40 | 000,524,288 | -HS- | C] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TMContainer00000000000000000002.regtrans-ms
[2010/07/16 20:40:40 | 000,524,288 | -HS- | C] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TMContainer00000000000000000001.regtrans-ms
[2010/07/16 20:40:40 | 000,065,536 | -HS- | C] () -- C:\Users\JAg\ntuser.dat{0ceb8ec0-9143-11df-b704-9c79222ffa67}.TM.blf
[2010/07/16 20:39:09 | 3756,064,768 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/06 19:42:58 | 000,002,255 | ---- | C] () -- C:\Users\JAg\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/06 13:33:29 | 000,077,054 | ---- | C] () -- C:\Windows\War3Unin.dat
[2010/07/06 13:33:28 | 000,002,829 | ---- | C] () -- C:\Windows\War3Unin.pif
[2010/01/28 10:51:19 | 000,190,976 | R--- | C] () -- C:\Windows\System32\Wgalogon.dll
[2009/08/02 20:13:31 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/08/01 16:22:11 | 000,716,272 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2009/03/23 11:00:02 | 000,667,136 | R--- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/03/02 11:33:32 | 000,067,584 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2009/03/02 11:33:32 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2007/07/25 16:40:02 | 000,999,424 | ---- | C] () -- C:\Windows\System32\WLIHVUI.dll
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini

[color=#E56717]========== Custom Scans ==========[/color]


[color=#A23BEC]< %systemroot%\*. /mp /s >[/color]

[color=#A23BEC]< %systemroot%\system32\*.dll /lockedfiles >[/color]
[2009/08/24 09:19:57 | 000,011,952 | ---- | M] (AVG Technologies CZ, s.r.o.)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\avgrsstx.dll
[2008/01/18 23:35:12 | 000,156,160 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\msls31.dll
[2008/01/18 23:36:16 | 000,286,720 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\rasapi32.dll
[2008/01/18 23:36:16 | 000,071,168 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\rasman.dll
[2008/01/18 23:38:04 | 000,242,744 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\rsaenh.dll
[2006/11/02 04:46:12 | 000,036,352 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\rtutils.dll
[2006/11/02 04:46:12 | 000,008,704 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\SensApi.dll
[2008/01/18 23:36:12 | 000,225,792 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\SLC.dll
[2008/01/18 23:36:38 | 000,376,832 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\sxs.dll
[2006/11/02 04:46:13 | 000,191,488 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5[/b] -- C:\Windows\System32\tapi32.dll

[color=#A23BEC]< %systemroot%\system32\*.exe /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\Tasks\*.job /lockedfiles >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.sys /lockedfiles >[/color]
[2009/08/01 16:22:11 | 000,716,272 | ---- | M] ()[b] Unable to obtain MD5[/b] -- C:\Windows\System32\drivers\sptd.sys

[color=#A23BEC]< %systemroot%\System32\config\*.sav >[/color]
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

[color=#A23BEC]< %systemroot%\system32\*.sys >[/color]
[2006/11/02 02:09:42 | 000,009,029 | ---- | M] () -- C:\Windows\System32\ANSI.SYS
[2008/01/18 23:43:00 | 000,247,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clfs.sys
[2006/11/02 02:09:45 | 000,027,097 | ---- | M] () -- C:\Windows\System32\country.sys
[2006/11/02 02:09:41 | 000,004,768 | ---- | M] () -- C:\Windows\System32\HIMEM.SYS
[2006/11/02 02:09:44 | 000,042,809 | ---- | M] () -- C:\Windows\System32\KEY01.SYS
[2006/11/02 02:09:44 | 000,042,537 | ---- | M] () -- C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 02:09:29 | 000,027,866 | ---- | M] () -- C:\Windows\System32\NTDOS.SYS
[2006/11/02 02:09:35 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS404.SYS
[2006/11/02 02:09:38 | 000,029,370 | ---- | M] () -- C:\Windows\System32\NTDOS411.SYS
[2006/11/02 02:09:40 | 000,029,274 | ---- | M] () -- C:\Windows\System32\NTDOS412.SYS
[2006/11/02 02:09:31 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS804.SYS
[2006/11/02 02:09:20 | 000,033,952 | ---- | M] () -- C:\Windows\System32\NTIO.SYS
[2006/11/02 02:09:23 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO404.SYS
[2006/11/02 02:09:24 | 000,035,776 | ---- | M] () -- C:\Windows\System32\NTIO411.SYS
[2006/11/02 02:09:26 | 000,035,536 | ---- | M] () -- C:\Windows\System32\NTIO412.SYS
[2006/11/02 02:09:22 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO804.SYS
[2009/04/21 06:55:06 | 002,033,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys

[color=#A23BEC]< %systemroot%\system32\drivers\*.dll >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.ini >[/color]

[color=#A23BEC]< %systemroot%\system32\drivers\*.exe >[/color]

[color=#A23BEC]< %SYSTEMDRIVE%\*.* >[/color]
[2006/09/18 16:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2008/01/18 23:45:46 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2009/04/06 19:28:17 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/07/27 22:18:20 | 3756,064,768 | -HS- | M] () -- C:\hiberfil.sys
[2009/08/01 15:53:14 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/07/27 22:50:16 | 000,014,039 | ---- | M] () -- C:\JavaRa.log
[2009/08/01 15:53:14 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/07/27 22:18:18 | 4069,675,008 | -HS- | M] () -- C:\pagefile.sys
[2009/05/11 23:08:08 | 000,000,137 | ---- | M] () -- C:\VundoFix.txt

[color=#A23BEC]< %PROGRAMFILES%\*. >[/color]
[2010/07/27 23:01:05 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/08/01 16:25:14 | 000,000,000 | ---D | M] -- C:\Program Files\Alcohol Soft
[2009/07/28 16:55:46 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/02/06 17:05:25 | 000,000,000 | ---D | M] -- C:\Program Files\AutoCAD 2010
[2010/01/28 11:21:35 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk
[2010/01/28 11:27:07 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk Revit Architecture 2010
[2009/04/08 13:25:07 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk Student Community Download Tool
[2009/06/03 16:16:01 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2010/01/09 12:52:02 | 000,000,000 | ---D | M] -- C:\Program Files\BFG
[2009/07/28 16:56:27 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/07/27 15:24:28 | 000,000,000 | ---D | M] -- C:\Program Files\Catan
[2009/05/02 11:46:52 | 000,000,000 | ---D | M] -- C:\Program Files\CDisplay
[2010/07/27 22:46:34 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/04/06 17:59:20 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
[2010/07/26 01:54:36 | 000,000,000 | ---D | M] -- C:\Program Files\Diablo II
[2009/10/14 00:57:03 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2009/09/09 15:54:49 | 000,000,000 | ---D | M] -- C:\Program Files\FLAC
[2009/10/19 11:25:05 | 000,000,000 | ---D | M] -- C:\Program Files\GIMP-2.0
[2010/05/13 15:55:25 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2009/08/20 18:57:36 | 000,000,000 | ---D | M] -- C:\Program Files\Grandpas Candy Factory
[2009/08/06 14:29:33 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2009/08/06 13:23:06 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2009/05/12 10:54:54 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/04/13 00:06:53 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/07/30 03:06:39 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/12/28 12:10:50 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/12/28 12:11:23 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/05/04 10:14:40 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/07/16 23:00:37 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/06 18:00:28 | 000,000,000 | ---D | M] -- C:\Program Files\Marvell
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2010/01/28 11:08:20 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/01/28 11:22:22 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SDKs
[2009/10/20 12:39:31 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2010/01/28 11:08:15 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2010/01/28 11:05:43 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8
[2010/01/28 11:22:40 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 9.0
[2010/01/28 11:08:52 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2010/01/28 11:07:42 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/07/27 15:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/01/28 11:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/01/04 21:28:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2009/05/13 03:00:40 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/04/08 22:49:11 | 000,000,000 | ---D | M] -- C:\Program Files\Netflix
[2009/08/04 00:11:29 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2009/05/03 00:24:29 | 000,000,000 | ---D | M] -- C:\Program Files\Pando Networks
[2009/10/21 13:17:46 | 000,000,000 | ---D | M] -- C:\Program Files\PixiePack Codec Pack
[2010/07/27 15:24:00 | 000,000,000 | ---D | M] -- C:\Program Files\PopCap Games
[2009/12/28 12:09:25 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/10/21 13:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\RapidSolution
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/02/05 10:15:08 | 000,000,000 | ---D | M] -- C:\Program Files\Rhinoceros 4.0
[2009/04/06 22:17:25 | 000,000,000 | ---D | M] -- C:\Program Files\SecureW2
[2009/04/06 17:58:05 | 000,000,000 | ---D | M] -- C:\Program Files\SigmaTel
[2010/06/11 21:01:51 | 000,000,000 | R--D | M] -- C:\Program Files\Skype
[2010/01/02 22:23:40 | 000,000,000 | ---D | M] -- C:\Program Files\SopCast
[2010/07/23 00:07:47 | 000,000,000 | ---D | M] -- C:\Program Files\Starcraft
[2010/07/27 22:19:55 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/07/27 13:38:13 | 000,000,000 | ---D | M] -- C:\Program Files\SystemRequirementsLab
[2010/03/01 21:07:52 | 000,000,000 | ---D | M] -- C:\Program Files\TryMedia
[2009/10/24 20:52:29 | 000,000,000 | ---D | M] -- C:\Program Files\TVUPlayer
[2006/11/02 08:01:55 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/03/13 21:43:11 | 000,000,000 | ---D | M] -- C:\Program Files\Veetle
[2010/07/12 08:42:25 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2009/04/06 21:44:51 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2010/07/26 19:45:04 | 000,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Calendar
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Collaboration
[2009/04/15 14:34:48 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2009/07/18 03:01:31 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar

MBvash

Newbie Surfer
Newbie Surfer

Posts : 15
Joined : 2010-07-28
Operating System : Vista

View user profile

Back to top Go down


Re: Random adverts playing in background with no windows open

Post by MBvash on Thu 29 Jul 2010, 7:02 pm

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/18 23:38:04 | 000,242,744 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2008/01/18 23:36:12 | 000,225,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll

< %systemroot%\system32\*.exe /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %systemroot%\system32\*.sys >
[2006/11/02 02:09:42 | 000,009,029 | ---- | M] () -- C:\Windows\System32\ANSI.SYS
[2008/01/18 23:43:00 | 000,247,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\clfs.sys
[2006/11/02 02:09:45 | 000,027,097 | ---- | M] () -- C:\Windows\System32\country.sys
[2006/11/02 02:09:41 | 000,004,768 | ---- | M] () -- C:\Windows\System32\HIMEM.SYS
[2006/11/02 02:09:44 | 000,042,809 | ---- | M] () -- C:\Windows\System32\KEY01.SYS
[2006/11/02 02:09:44 | 000,042,537 | ---- | M] () -- C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 02:09:29 | 000,027,866 | ---- | M] () -- C:\Windows\System32\NTDOS.SYS
[2006/11/02 02:09:35 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS404.SYS
[2006/11/02 02:09:38 | 000,029,370 | ---- | M] () -- C:\Windows\System32\NTDOS411.SYS
[2006/11/02 02:09:40 | 000,029,274 | ---- | M] () -- C:\Windows\System32\NTDOS412.SYS
[2006/11/02 02:09:31 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS804.SYS
[2006/11/02 02:09:20 | 000,033,952 | ---- | M] () -- C:\Windows\System32\NTIO.SYS
[2006/11/02 02:09:23 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO404.SYS
[2006/11/02 02:09:24 | 000,035,776 | ---- | M] () -- C:\Windows\System32\NTIO411.SYS
[2006/11/02 02:09:26 | 000,035,536 | ---- | M] () -- C:\Windows\System32\NTIO412.SYS
[2006/11/02 02:09:22 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO804.SYS
[2010/05/01 08:53:49 | 002,036,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys

< %systemroot%\system32\drivers\*.dll >

< %systemroot%\system32\drivers\*.ini >

< %systemroot%\system32\drivers\*.exe >

< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2008/01/18 23:45:46 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2009/04/06 19:28:17 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2010/07/29 02:46:13 | 000,020,990 | ---- | M] () -- C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/07/29 02:33:16 | 3756,064,768 | -HS- | M] () -- C:\hiberfil.sys
[2009/08/01 15:53:14 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/07/27 22:50:16 | 000,014,039 | ---- | M] () -- C:\JavaRa.log
[2009/08/01 15:53:14 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/07/29 02:33:14 | 4069,675,008 | -HS- | M] () -- C:\pagefile.sys

< %PROGRAMFILES%\*. >
[2010/07/27 23:01:05 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/08/01 16:25:14 | 000,000,000 | ---D | M] -- C:\Program Files\Alcohol Soft
[2009/07/28 16:55:46 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010/02/06 17:05:25 | 000,000,000 | ---D | M] -- C:\Program Files\AutoCAD 2010
[2010/01/28 11:21:35 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk
[2010/01/28 11:27:07 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk Revit Architecture 2010
[2009/04/08 13:25:07 | 000,000,000 | ---D | M] -- C:\Program Files\Autodesk Student Community Download Tool
[2009/06/03 16:16:01 | 000,000,000 | ---D | M] -- C:\Program Files\AVG
[2010/01/09 12:52:02 | 000,000,000 | ---D | M] -- C:\Program Files\BFG
[2009/07/28 16:56:27 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/07/27 15:24:28 | 000,000,000 | ---D | M] -- C:\Program Files\Catan
[2009/05/02 11:46:52 | 000,000,000 | ---D | M] -- C:\Program Files\CDisplay
[2010/07/29 02:41:19 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/04/06 17:59:20 | 000,000,000 | ---D | M] -- C:\Program Files\Dell Support Center
[2010/07/26 01:54:36 | 000,000,000 | ---D | M] -- C:\Program Files\Diablo II
[2009/10/14 00:57:03 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2009/09/09 15:54:49 | 000,000,000 | ---D | M] -- C:\Program Files\FLAC
[2009/10/19 11:25:05 | 000,000,000 | ---D | M] -- C:\Program Files\GIMP-2.0
[2010/05/13 15:55:25 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2009/08/20 18:57:36 | 000,000,000 | ---D | M] -- C:\Program Files\Grandpas Candy Factory
[2009/08/06 14:29:33 | 000,000,000 | ---D | M] -- C:\Program Files\Hewlett-Packard
[2009/08/06 13:23:06 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2009/05/12 10:54:54 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/04/13 00:06:53 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/07/30 03:06:39 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/12/28 12:10:50 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2009/12/28 12:11:23 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2009/05/04 10:14:40 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010/07/16 23:00:37 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/06 18:00:28 | 000,000,000 | ---D | M] -- C:\Program Files\Marvell
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Games
[2010/01/28 11:08:20 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Office
[2010/01/28 11:22:22 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft SDKs
[2009/10/20 12:39:31 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Silverlight
[2010/01/28 11:08:15 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio
[2010/01/28 11:05:43 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 8
[2010/01/28 11:22:40 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Visual Studio 9.0
[2010/01/28 11:08:52 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft Works
[2010/01/28 11:07:42 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft.NET
[2010/07/27 23:55:00 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/07/27 15:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010/01/28 11:08:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010/01/04 21:28:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSECache
[2009/05/13 03:00:40 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/04/08 22:49:11 | 000,000,000 | ---D | M] -- C:\Program Files\Netflix
[2009/08/04 00:11:29 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2009/05/03 00:24:29 | 000,000,000 | ---D | M] -- C:\Program Files\Pando Networks
[2010/07/23 20:09:32 | 000,000,000 | ---D | M] -- C:\Program Files\PeerBlock
[2010/02/04 10:46:10 | 000,000,000 | ---D | M] -- C:\Program Files\PeerGuardian2
[2009/10/21 13:17:46 | 000,000,000 | ---D | M] -- C:\Program Files\PixiePack Codec Pack
[2010/07/27 15:24:00 | 000,000,000 | ---D | M] -- C:\Program Files\PopCap Games
[2009/12/28 12:09:25 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2009/10/21 13:12:50 | 000,000,000 | ---D | M] -- C:\Program Files\RapidSolution
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/02/05 10:15:08 | 000,000,000 | ---D | M] -- C:\Program Files\Rhinoceros 4.0
[2009/04/06 22:17:25 | 000,000,000 | ---D | M] -- C:\Program Files\SecureW2
[2009/04/06 17:58:05 | 000,000,000 | ---D | M] -- C:\Program Files\SigmaTel
[2010/06/11 21:01:51 | 000,000,000 | R--D | M] -- C:\Program Files\Skype
[2010/01/02 22:23:40 | 000,000,000 | ---D | M] -- C:\Program Files\SopCast
[2010/07/23 00:07:47 | 000,000,000 | ---D | M] -- C:\Program Files\Starcraft
[2010/07/29 00:31:24 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/07/27 13:38:13 | 000,000,000 | ---D | M] -- C:\Program Files\SystemRequirementsLab
[2010/03/01 21:07:52 | 000,000,000 | ---D | M] -- C:\Program Files\TryMedia
[2009/10/24 20:52:29 | 000,000,000 | ---D | M] -- C:\Program Files\TVUPlayer
[2006/11/02 08:01:55 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010/07/27 22:46:18 | 000,000,000 | ---D | M] -- C:\Program Files\uTorrent
[2010/03/13 21:43:11 | 000,000,000 | ---D | M] -- C:\Program Files\Veetle
[2010/07/28 21:10:37 | 000,000,000 | ---D | M] -- C:\Program Files\Ventrilo
[2010/07/12 08:42:25 | 000,000,000 | ---D | M] -- C:\Program Files\Veoh Networks
[2009/04/06 21:44:51 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2010/07/26 19:45:04 | 000,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Calendar
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Collaboration
[2009/04/15 14:34:48 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Defender
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Journal
[2010/07/27 23:55:07 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Mail
[2010/07/27 23:54:33 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2006/11/02 07:37:34 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/04/15 14:34:49 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Photo Gallery
[2009/04/15 14:34:50 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Sidebar

< %appdata%\*.* >
[2009/08/02 20:13:31 | 000,022,328 | ---- | M] () -- C:\Users\JAg\AppData\Roaming\PnkBstrK.sys


< MD5 for: AGP440.SYS >
[2008/01/18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2008/01/18 23:42:26 | 000,056,376 | ---- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 -- C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_bbfe6647bbd2a4c6\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\ERDNT\cache\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 04:49:52 | 000,053,864 | ---- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 -- C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\ERDNT\cache\atapi.sys
[2008/01/18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\drivers\atapi.sys
[2008/01/18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/18 23:41:32 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 04:49:36 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2007/02/21 14:49:48 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=5653737BAD8C6C10136451C195C19881 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20485_none_db8a029f3dbd443b\atapi.sys
[2007/02/21 14:49:48 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_82339ef2\atapi.sys
[2007/02/21 14:49:48 | 000,019,048 | ---- | M] (Microsoft Corporation) MD5=A779CA2C76DA4FCB595E692C05E8E4EB -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16391_none_daf194c024ab5b06\atapi.sys
[2009/04/07 00:03:38 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
[2009/04/07 00:03:38 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=B35CFCEF838382AB6490B321C87EDF17 -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
[2009/04/07 00:03:38 | 000,021,560 | ---- | M] (Microsoft Corporation) MD5=E03E8C99D15D0381E02743C36AFC7C6F -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\ERDNT\cache\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\System32\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | ---- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D -- C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: DISK.SYS >
[2008/01/18 23:42:22 | 000,055,352 | ---- | M] (Microsoft Corporation) MD5=64109E623ABD6955C8FB110B592E68B7 -- C:\Windows\System32\drivers\disk.sys
[2008/01/18 23:42:22 | 000,055,352 | ---- | M] (Microsoft Corporation) MD5=64109E623ABD6955C8FB110B592E68B7 -- C:\Windows\System32\DriverStore\FileRepository\disk.inf_90722180\disk.sys
[2008/01/18 23:42:22 | 000,055,352 | ---- | M] (Microsoft Corporation) MD5=64109E623ABD6955C8FB110B592E68B7 -- C:\Windows\winsxs\x86_disk.inf_31bf3856ad364e35_6.0.6001.18000_none_f9c681e4742c835a\disk.sys
[2006/11/02 04:49:51 | 000,052,840 | ---- | M] (Microsoft Corporation) MD5=841AF4C4D41D3E3B2F244E976B0F7963 -- C:\Windows\System32\DriverStore\FileRepository\disk.inf_e0b0b355\disk.sys

< MD5 for: IASTORV.SYS >
[2008/01/18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/18 23:42:52 | 000,235,064 | ---- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 -- C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 04:51:25 | 000,232,040 | ---- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 -- C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2006/11/02 04:46:11 | 000,559,616 | ---- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008/01/18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\ERDNT\cache\netlogon.dll
[2008/01/18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\System32\netlogon.dll
[2008/01/18 23:35:38 | 000,592,384 | ---- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F -- C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2007/01/06 00:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\drivers\nvstor.sys
[2007/01/06 00:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_45f67928\nvstor.sys
[2007/01/06 00:59:42 | 000,035,920 | ---- | M] (NVIDIA Corporation) MD5=4A5FCAB82D9BF6AF8A023A66802FE9E9 -- C:\Windows\System32\DriverStore\FileRepository\nvstor.inf_f48b8337\nvstor.sys
[2006/11/02 04:50:13 | 000,040,040 | ---- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/18 23:42:10 | 000,045,112 | ---- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 -- C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\ERDNT\cache\scecli.dll
[2008/01/18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\System32\scecli.dll
[2008/01/18 23:36:20 | 000,177,152 | ---- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 04:46:12 | 000,176,640 | ---- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll

< MD5 for: USBSTOR.SYS >
[2009/04/07 00:21:48 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=7887CE56934E7F104E98C975F47353C5 -- C:\Windows\System32\DriverStore\FileRepository\usbstor.inf_8416e98e\USBSTOR.SYS
[2009/04/07 00:21:48 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=7887CE56934E7F104E98C975F47353C5 -- C:\Windows\winsxs\x86_usbstor.inf_31bf3856ad364e35_6.0.6000.16478_none_465c5f209ade1e53\USBSTOR.SYS
[2009/04/07 00:21:49 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=7DA1833F2B2500C755AB6C81C5ABFC88 -- C:\Windows\winsxs\x86_usbstor.inf_31bf3856ad364e35_6.0.6000.20588_none_46db2bffb403da0e\USBSTOR.SYS
[2008/01/18 21:53:24 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=87BA6B83C5D19B69160968D07D6E2982 -- C:\Windows\System32\drivers\USBSTOR.SYS
[2008/01/18 21:53:24 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=87BA6B83C5D19B69160968D07D6E2982 -- C:\Windows\System32\DriverStore\FileRepository\usbstor.inf_b9f18584\USBSTOR.SYS
[2008/01/18 21:53:24 | 000,055,296 | ---- | M] (Microsoft Corporation) MD5=87BA6B83C5D19B69160968D07D6E2982 -- C:\Windows\winsxs\x86_usbstor.inf_31bf3856ad364e35_6.0.6001.18000_none_48864eb697d31b43\USBSTOR.SYS
[2006/11/02 03:55:05 | 000,054,784 | ---- | M] (Microsoft Corporation) MD5=FDBAABF07244C60B0F4E0A6E71A107C6 -- C:\Windows\System32\DriverStore\FileRepository\usbstor.inf_bb2778a0\USBSTOR.SYS

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-28 04:46:42

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:1DEE6B65
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:517B507A
< End of report >

MBvash

Newbie Surfer
Newbie Surfer

Posts : 15
Joined : 2010-07-28
Operating System : Vista

View user profile

Back to top Go down

Re: Random adverts playing in background with no windows open

Post by Crush on Fri 30 Jul 2010, 4:07 am

Hi,

All that looks good. How are things running now?

TFC(Temp File Cleaner):


  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.


Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

Crush

Tech Officer
Tech Officer

Posts : 3889
Joined : 2010-01-28

View user profile

Back to top Go down

Re: Random adverts playing in background with no windows open

Post by Sponsored content Today at 1:11 am


Sponsored content


Back to top Go down

Page 2 of 2 Previous  1, 2

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum