Woah. It took more than an hour to scan.
OTL logfile created on: 3/5/2010 12:44:58 AM - Run 1
OTL by OldTimer - Version 3.1.33.0 Folder = F:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 71.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): F:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = F: | %SystemRoot% = F:\WINDOWS | %ProgramFiles% = F:\Program Files
Drive C: | 259.02 Gb Total Space | 63.08 Gb Free Space | 24.35% Space Free | Partition Type: NTFS
Drive D: | 37.10 Gb Total Space | 13.75 Gb Free Space | 37.06% Space Free | Partition Type: NTFS
Drive E: | 37.42 Gb Total Space | 0.44 Gb Free Space | 1.18% Space Free | Partition Type: NTFS
Drive F: | 39.06 Gb Total Space | 21.20 Gb Free Space | 54.28% Space Free | Partition Type: NTFS
Drive G: | 4.29 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-B0B73D7D31
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
[color=\"#E56717\"]========== Processes (SafeList) ==========[/color]
PRC - [2010/03/05 00:43:16 | 000,552,960 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Administrator\Desktop\OTL.exe
PRC - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/10/29 06:54:44 | 001,218,008 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2009/09/16 10:22:08 | 000,144,704 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2009/07/08 14:48:48 | 000,026,640 | ---- | M] (McAfee, Inc.) -- F:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) -- f:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) -- f:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2009/02/06 17:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- F:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/11/28 09:28:34 | 000,446,571 | ---- | M] (IDT, Inc.) -- F:\Program Files\IDT\WDM\sttray.exe
PRC - [2008/11/28 09:28:34 | 000,237,665 | ---- | M] (IDT, Inc.) -- f:\Program Files\IDT\5902XP_6033V_012208\WDM\stacsv.exe
PRC - [2008/09/10 13:01:28 | 000,611,664 | ---- | M] (Lavasoft) -- F:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
PRC - [2008/07/17 21:50:18 | 002,599,224 | ---- | M] (
www.BitComet.com) -- F:\Program Files\BitComet\BitComet.exe
PRC - [2006/09/28 22:13:20 | 000,204,800 | ---- | M] (Anti-Malware Development a.s.) -- F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
PRC - [2006/05/20 22:23:26 | 001,032,192 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\explorer.exe
PRC - [2006/02/04 20:16:34 | 000,062,464 | ---- | M] (Alexander Avdonin) -- F:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
PRC - [2006/01/24 11:38:56 | 000,147,456 | ---- | M] () -- F:\Program Files\Razer\Krait\razerhid.exe
PRC - [2005/12/08 12:42:28 | 000,155,648 | ---- | M] (Razer Inc.) -- F:\Program Files\Razer\Krait\razerofa.exe
[color=\"#E56717\"]========== Modules (SafeList) ==========[/color]
MOD - [2010/03/05 00:43:16 | 000,552,960 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Administrator\Desktop\OTL.exe
MOD - [2009/12/08 13:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- f:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2006/05/20 22:23:26 | 001,053,696 | ---- | M] (Microsoft Corporation) -- F:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\comctl32.dll
[color=\"#E56717\"]========== Win32 Services (SafeList) ==========[/color]
SRV - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- F:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/10/27 11:19:46 | 000,895,696 | ---- | M] (McAfee, Inc.) [Auto | Running] -- F:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2009/09/16 11:23:32 | 000,365,072 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- F:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2009/09/16 10:22:08 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- F:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2009/09/16 09:28:38 | 000,606,736 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- F:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2009/07/10 00:26:20 | 000,865,832 | ---- | M] (McAfee, Inc.) [Auto | Running] -- F:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2009/07/08 14:48:48 | 000,026,640 | ---- | M] (McAfee, Inc.) [Auto | Running] -- F:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2009/07/08 11:54:34 | 000,359,952 | ---- | M] (McAfee, Inc.) [Auto | Running] -- f:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2009/07/07 19:10:02 | 002,482,848 | ---- | M] (McAfee, Inc.) [Auto | Running] -- f:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2008/11/28 09:28:34 | 000,237,665 | ---- | M] (IDT, Inc.) [Auto | Running] -- f:\Program Files\IDT\5902XP_6033V_012208\WDM\stacsv.exe -- (STacSV)
SRV - [2008/09/10 13:01:28 | 000,611,664 | ---- | M] (Lavasoft) [Auto | Running] -- F:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice)
SRV - [2006/09/28 22:13:20 | 000,204,800 | ---- | M] (Anti-Malware Development a.s.) [Auto | Running] -- F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe -- (AVG Anti-Spyware Guard)
SRV - [2005/10/06 19:12:30 | 000,855,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- F:\Program Files\Windows Media Connect 2\wmccds.exe -- (WMConnectCDS)
[color=\"#E56717\"]========== Driver Services (SafeList) ==========[/color]
DRV - [2009/10/15 01:35:22 | 000,721,904 | ---- | M] () [Kernel | Boot | Running] -- F:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/09/16 10:22:48 | 000,214,664 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2009/07/16 12:32:26 | 000,120,136 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\Mpfp.sys -- (MPFP)
DRV - [2008/11/28 09:28:34 | 001,392,498 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2008/08/07 19:14:56 | 000,111,360 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007/10/12 09:40:12 | 000,009,096 | R--- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- F:\WINDOWS\system32\DRIVERS\amdide.sys -- (amdide)
DRV - [2007/05/11 06:03:00 | 006,738,432 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006/09/28 22:13:34 | 000,004,096 | ---- | M] () [Kernel | System | Running] -- F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys -- (AVG Anti-Spyware Driver)
DRV - [2006/09/06 16:04:12 | 004,377,600 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/09/06 00:03:16 | 000,003,968 | ---- | M] (GRISOFT, s.r.o.) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\AvgAsCln.sys -- (AvgAsCln)
DRV - [2006/07/01 22:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/05/20 22:23:26 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- F:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/05/20 22:23:26 | 000,012,160 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- F:\WINDOWS\system32\drivers\fsvga.sys -- (FsVga)
DRV - [2006/05/16 19:25:02 | 000,018,944 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006/05/16 19:25:00 | 000,052,736 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006/04/24 17:52:28 | 000,100,736 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- F:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2005/12/07 18:27:52 | 000,013,324 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\krait.sys -- (krait03)
DRV - [2005/02/01 23:30:00 | 000,141,246 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Stopped] -- F:\WINDOWS\system32\drivers\NVCAP.SYS -- (nvcap) nVidia WDM Video Capture (universal)
DRV - [2005/02/01 23:30:00 | 000,016,176 | ---- | M] (NVIDIA Corporation) [Kernel | Auto | Stopped] -- F:\WINDOWS\system32\drivers\NVXBAR.SYS -- (NVXBAR)
DRV - [2001/08/17 21:51:32 | 000,018,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- F:\WINDOWS\system32\drivers\irsir.sys -- (irsir)
[color=\"#E56717\"]========== Standard Registry (SafeList) ==========[/color]
[color=\"#E56717\"]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\AV, =
http://www.altavista.com/sites/search/web?q=%sIE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\FM, =
http://www.filemirrors.com/search.src?file=%sIE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\Ggl, =
http://www.google.com/search?q=%sIE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSKB, =
http://support.microsoft.com/?kbid=%sIE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\MSN, =
http://search.msn.com/results.asp?q=%sIE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - f:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=\"#E56717\"]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "
http://www.facebook.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.03
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: F:\Program Files\McAfee\SiteAdvisor [2010/02/18 14:50:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Components: F:\Program Files\Mozilla Firefox\components [2010/01/07 19:42:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.17\extensions\\Plugins: F:\Program Files\Mozilla Firefox\plugins [2010/01/07 19:42:32 | 000,000,000 | ---D | M]
[2009/07/09 23:57:32 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/02/28 00:23:07 | 000,000,000 | ---D | M] -- F:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fugtnys0.default\extensions
[2009/01/28 01:08:00 | 000,000,000 | ---D | M] (BitComet Download Helper) -- F:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fugtnys0.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2009/07/09 23:58:33 | 000,000,000 | ---D | M] (Adblock Plus) -- F:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fugtnys0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/10/18 23:53:50 | 000,002,386 | ---- | M] () -- F:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\fugtnys0.default\searchplugins\siteadvisor.xml
[2010/02/28 00:23:06 | 000,000,000 | ---D | M] -- F:\Program Files\Mozilla Firefox\extensions
[2007/01/06 15:57:53 | 000,000,000 | ---D | M] (No name found) -- F:\Program Files\Mozilla Firefox\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2007/01/06 15:57:53 | 000,000,000 | ---D | M] -- F:\Program Files\Mozilla Firefox\extensions\filtersetg@updater
[2008/01/23 14:20:30 | 000,491,520 | ---- | M] (BitComet) -- F:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2006/03/06 11:23:02 | 000,000,232 | ---- | M] () -- F:\Program Files\Mozilla Firefox\searchplugins\wikipedia.png
[2006/04/14 17:48:08 | 000,001,081 | ---- | M] () -- F:\Program Files\Mozilla Firefox\searchplugins\wikipedia.src
[2006/03/19 09:50:02 | 000,001,019 | ---- | M] () -- F:\Program Files\Mozilla Firefox\searchplugins\Wiktionary.png
[2006/03/19 10:15:46 | 000,000,717 | ---- | M] () -- F:\Program Files\Mozilla Firefox\searchplugins\wiktionary.src
O1 HOSTS File: ([2008/11/25 00:19:55 | 000,288,033 | R--- | M]) - F:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1
www.007guard.comO1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.comO1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.comO1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.comO1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.comO1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.comO1 - Hosts: 127.0.0.1
www.1001namen.comO1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.comO1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1
www.100sexlinks.comO1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.comO1 - Hosts: 127.0.0.1
www.123haustiereundmehr.comO1 - Hosts: 127.0.0.1 123haustiereundmehr.com
O1 - Hosts: 9926 more lines...
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - f:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - F:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll (BitComet)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - F:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - f:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - f:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] F:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] F:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Krait] F:\Program Files\Razer\Krait\razerhid.exe ()
O4 - HKLM..\Run: [mcagent_exe] F:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [McENUI] F:\Program Files\McAfee\MHN\McENUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] F:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] F:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] F:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [RemoteControl] F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SysTrayApp] F:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [TaskSwitchXP] F:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (Alexander Avdonin)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O8 - Extra context menu item: &D&ownload &with BitComet - F:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all video with BitComet - F:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O8 - Extra context menu item: &D&ownload all with BitComet - F:\Program Files\BitComet\BitComet.exe (
www.BitComet.com)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - F:\Program Files\BitComet\tools\BitCometBHO_1.2.6.26.dll (BitComet)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - f:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - F:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - f:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - F:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: F:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: F:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (Anti-Malware Development a.s.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/16 14:44:35 | 000,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/01/06 16:01:17 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2007/09/03 14:28:17 | 000,000,046 | R--- | M] () - G:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe -- [2007/09/03 11:46:41 | 000,253,952 | R--- | M] (2K Games )
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - F:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
[color=\"#E56717\"]========== Files/Folders - Created Within 30 Days ==========[/color]
[2010/03/05 00:43:45 | 000,552,960 | ---- | C] (OldTimer Tools) -- F:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/02/18 01:22:56 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Administrator\My Documents\Bioshock
[2010/02/18 01:22:56 | 000,000,000 | ---D | C] -- F:\Documents and Settings\Administrator\Application Data\Bioshock
[2010/02/18 01:22:51 | 000,000,000 | RH-D | C] -- F:\Documents and Settings\Administrator\Application Data\SecuROM
[2010/02/18 00:19:14 | 000,000,000 | ---D | C] -- F:\Program Files\Trend Micro
[2009/11/03 20:57:13 | 000,000,000 | ---D | M] -- F:\Documents and Settings\LocalService\Application Data\McAfee
[2009/10/18 20:34:09 | 000,000,000 | ---D | M] -- F:\Documents and Settings\LocalService\Application Data\SACore
[2007/01/06 16:03:00 | 000,000,000 | ---D | M] -- F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/01/06 16:02:57 | 000,000,000 | ---D | M] -- F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/01/06 16:01:15 | 000,000,000 | --SD | M] -- F:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/01/06 16:01:15 | 000,000,000 | --SD | M] -- F:\Documents and Settings\LocalService\Application Data\Microsoft
[5 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[color=\"#E56717\"]========== Files - Modified Within 30 Days ==========[/color]
[2010/03/05 00:43:16 | 000,552,960 | ---- | M] (OldTimer Tools) -- F:\Documents and Settings\Administrator\Desktop\OTL.exe
[2010/03/05 00:38:36 | 000,016,347 | ---- | M] () -- F:\WINDOWS\System32\Config.MPF
[2010/03/05 00:35:16 | 000,000,006 | -H-- | M] () -- F:\WINDOWS\tasks\SA.DAT
[2010/03/05 00:35:07 | 000,002,206 | ---- | M] () -- F:\WINDOWS\System32\wpa.dbl
[2010/03/05 00:35:04 | 000,002,048 | --S- | M] () -- F:\WINDOWS\bootstat.dat
[2010/03/04 19:05:39 | 010,747,904 | -H-- | M] () -- F:\Documents and Settings\Administrator\NTUSER.DAT
[2010/03/01 00:36:12 | 002,110,928 | -H-- | M] () -- F:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db
[2010/03/01 00:36:03 | 000,000,162 | ---- | M] () -- F:\WINDOWS\igsmj2002.no
[2010/02/20 21:59:08 | 000,112,128 | ---- | M] () -- F:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/18 01:22:50 | 000,107,888 | ---- | M] (Sony DADC Austria AG.) -- F:\WINDOWS\System32\CmdLineExt.dll
[2010/02/18 01:20:51 | 000,001,719 | ---- | M] () -- F:\Documents and Settings\All Users\Desktop\BioShock.lnk
[2010/02/18 00:19:14 | 000,001,734 | ---- | M] () -- F:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2010/02/17 04:44:31 | 000,000,116 | ---- | M] () -- F:\WINDOWS\NeroDigital.ini
[2010/02/15 01:03:25 | 000,000,356 | ---- | M] () -- F:\WINDOWS\tasks\McDefragTask.job
[5 F:\WINDOWS\*.tmp files -> F:\WINDOWS\*.tmp -> ]
[1 F:\WINDOWS\System32\*.tmp files -> F:\WINDOWS\System32\*.tmp -> ]
[color=\"#E56717\"]========== Files Created - No Company Name ==========[/color]
[2010/02/18 01:20:51 | 000,001,719 | ---- | C] () -- F:\Documents and Settings\All Users\Desktop\BioShock.lnk
[2010/02/18 00:19:14 | 000,001,734 | ---- | C] () -- F:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2009/10/15 01:35:22 | 000,721,904 | ---- | C] () -- F:\WINDOWS\System32\drivers\sptd.sys
[2009/09/04 20:37:44 | 000,000,013 | ---- | C] () -- F:\WINDOWS\msgtn.ini
[2009/09/04 20:33:00 | 000,000,113 | ---- | C] () -- F:\WINDOWS\PPSMediaList.ini
[2009/09/04 20:32:59 | 000,000,063 | ---- | C] () -- F:\WINDOWS\powerlist.ini
[2009/09/04 20:32:55 | 000,001,451 | ---- | C] () -- F:\WINDOWS\powerplayer.ini
[2009/09/04 20:32:55 | 000,000,886 | ---- | C] () -- F:\WINDOWS\psnetwork.ini
[2008/04/23 21:19:15 | 000,032,768 | ---- | C] () -- F:\WINDOWS\System32\mf.dll
[2008/02/14 03:35:57 | 000,000,023 | ---- | C] () -- F:\WINDOWS\BlendSettings.ini
[2008/02/10 14:31:39 | 000,000,300 | ---- | C] () -- F:\WINDOWS\game.ini
[2007/09/22 18:34:30 | 000,000,025 | ---- | C] () -- F:\WINDOWS\cdplayer.ini
[2007/04/17 15:34:40 | 000,135,716 | ---- | C] () -- F:\WINDOWS\System32\xlive.dll.cat
[2007/04/14 15:57:06 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2007/04/14 15:57:06 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelSwedish.dll
[2007/04/14 15:57:06 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelSpanish.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelPortugese.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelKorean.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelJapanese.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelGerman.dll
[2007/04/14 15:57:04 | 000,053,248 | ---- | C] () -- F:\WINDOWS\System32\AgCPanelFrench.dll
[2007/02/21 16:37:13 | 000,000,056 | ---- | C] () -- F:\WINDOWS\kgt2k.INI
[2007/01/15 21:59:11 | 000,000,376 | ---- | C] () -- F:\WINDOWS\ODBC.INI
[2007/01/06 17:35:57 | 000,112,128 | ---- | C] () -- F:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/01/06 17:24:32 | 000,000,116 | ---- | C] () -- F:\WINDOWS\NeroDigital.ini
[2007/01/06 17:15:50 | 000,000,000 | ---- | C] () -- F:\WINDOWS\muveeapp.INI
[2007/01/06 16:49:37 | 000,147,456 | ---- | C] () -- F:\WINDOWS\System32\RtlCPAPI.dll
[2006/12/13 00:30:26 | 003,596,288 | ---- | C] () -- F:\WINDOWS\System32\qt-dx331.dll
[2006/12/13 00:24:42 | 000,012,288 | ---- | C] () -- F:\WINDOWS\System32\DivXWMPExtType.dll
[2006/06/01 17:22:00 | 001,703,936 | ---- | C] () -- F:\WINDOWS\System32\nvwdmcpl.dll
[2006/06/01 17:22:00 | 001,474,560 | ---- | C] () -- F:\WINDOWS\System32\nview.dll
[2006/06/01 17:22:00 | 001,019,904 | ---- | C] () -- F:\WINDOWS\System32\nvwimg.dll
[2006/06/01 17:22:00 | 000,581,632 | ---- | C] () -- F:\WINDOWS\System32\nvhwvid.dll
[2006/06/01 17:22:00 | 000,466,944 | ---- | C] () -- F:\WINDOWS\System32\nvshell.dll
[2006/06/01 17:22:00 | 000,286,720 | ---- | C] () -- F:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/20 22:23:26 | 000,394,240 | ---- | C] () -- F:\WINDOWS\System32\HMTCD.dll
[2006/05/20 22:23:26 | 000,081,920 | ---- | C] () -- F:\WINDOWS\System32\ieencode.dll
[2006/05/20 22:23:26 | 000,061,440 | ---- | C] () -- F:\WINDOWS\System32\CopyToSendTo.dll
[2005/04/28 12:22:34 | 000,831,488 | ---- | C] () -- F:\WINDOWS\System32\libeay32.dll
[2005/04/28 12:22:34 | 000,159,744 | ---- | C] () -- F:\WINDOWS\System32\ssleay32.dll
[2003/01/08 03:05:08 | 000,002,695 | ---- | C] () -- F:\WINDOWS\System32\OUTLPERF.INI
[color=\"#E56717\"]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 120 bytes -> F:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >