JUNCTION
Junction v1.05 - Windows junction creator and reparse point viewer
Copyright © 2000-2007 Mark Russinovich
Systems Internals -
http://www.sysinternals.com
Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process.
Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.
..
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Brother\BrLog\BrDbgOut.INI: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINS32.log: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINST.log: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINSTL.log: Access is denied.
.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ae0ad2c781b2aade5b43efdb1141fe0_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b45f485ea512e4f973d981677635aa1_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43888a6dbef0e7d3039d36a821046067_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\764a32e0974b07e3b4f6ca4caa0a7f08_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\839355d28f5e88b34f48664baa866af3_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90d67098a88c40db0d8f76847abf6536_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fb3e2dd6349fef3d6db2a059384910d_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df10a096d31f0debf2010287546432c0_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed1a5d48be8e1e8b9bdb0111a2cdc464_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbc0b715526d4b9fcfb0d3c9ad077b42_2e2346a6-fbf3-43fc-92e3-187770e75c69: Access is denied.
Failed to open \\?\c:\\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp: Access is denied.
...
...
...
...
...
...
.
Failed to open \\?\c:\\Documents and Settings\asdf\Desktop\RootRepeal\RootRepeal.exe: Access is denied.
..
...
...
...
Failed to open \\?\c:\\Documents and Settings\user\Local Settings\Temp\iwgaxlhp.dat: Access is denied.
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
..
Failed to open \\?\c:\\Program Files\Malwarebytes' Anti-Malware\mbam.exe: Access is denied.
.
...
...
...
Failed to open \\?\c:\\Program Files\Trend Micro\HijackThis\HijackThis.exe: Access is denied.
...
...
...
.
Failed to open \\?\c:\\System Volume Information\MountPointManagerRemoteDatabase: Access is denied.
..
...
...
.\\?\c:\\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
Substitute Name: C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
\\?\c:\\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
Substitute Name: C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
..
...
...
...
...
...
...
...
.
Failed to open \\?\c:\\WINDOWS\system32\drivers\abkmzdfd.dat: Access is denied.
.
Failed to open \\?\c:\\WINDOWS\system32\drivers\iwgaxlhp.dat: Access is denied.
.
.
COMBOFIX
ComboFix 09-11-03.03 - asdf 04/11/2009 11:02.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.34 [GMT -5:00]
Running from: c:\documents and settings\asdf\Desktop\thcbytes.exe
Command switches used :: c:\documents and settings\asdf\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}"
"c:\windows\EReg072.dat"
"c:\windows\iun6002.exe"
"c:\windows\Psiwuxojapona.dat"
"c:\windows\Qxegunu.bin"
"c:\windows\system32\drivers\abkmzdfd.dat"
"c:\windows\system32\drivers\hqoicvtthemuwpsp.sys"
"c:\windows\system32\OpenAL32.dll"
"c:\windows\system32\wrap_oal.dll"
"c:\windows\win32k.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Local Settings\Application Data\{DF3E8DAC-9C22-43E6-9738-1D48AD39715E}
c:\documents and settings\Administrator\Local Settings\Application Data\{DF3E8DAC-9C22-43E6-9738-1D48AD39715E}\chrome.manifest
c:\documents and settings\Administrator\Local Settings\Application Data\{DF3E8DAC-9C22-43E6-9738-1D48AD39715E}\chrome\content\_cfg.js
c:\documents and settings\Administrator\Local Settings\Application Data\{DF3E8DAC-9C22-43E6-9738-1D48AD39715E}\chrome\content\overlay.xul
c:\documents and settings\Administrator\Local Settings\Application Data\{DF3E8DAC-9C22-43E6-9738-1D48AD39715E}\install.rdf
c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}
c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}\chrome.manifest
c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}\chrome\content\_cfg.js
c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}\chrome\content\overlay.xul
c:\documents and settings\asdf\Local Settings\Application Data\{E412279E-8375-4AFF-82DE-CAC81403D53D}\install.rdf
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Viewpoint\Common\VistaBoot.sdll
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VETScriptInterpreter.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMPVideo2.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
c:\windows\EReg072.dat
c:\windows\iun6002.exe
c:\windows\Psiwuxojapona.dat
c:\windows\Qxegunu.bin
c:\windows\system32\drivers\abkmzdfd.dat
c:\windows\system32\drivers\hqoicvtthemuwpsp.sys
c:\windows\system32\OpenAL32.dll
c:\windows\system32\wrap_oal.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\win32k.sys
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KRNNTWWO
-------\Service_krnntwwo
((((((((((((((((((((((((( Files Created from 2009-10-04 to 2009-11-04 )))))))))))))))))))))))))))))))
.
2009-11-03 21:46 . 2009-11-03 22:24 -------- d-----w- C:\thcbytes
2009-10-26 16:01 . 2009-10-26 16:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-10-25 21:26 . 2009-10-25 21:26 -------- d-----w- c:\documents and settings\Administrator
2009-10-25 18:12 . 2009-10-25 18:12 -------- d-----w- c:\program files\Trend Micro
2009-10-25 02:05 . 2009-10-26 02:33 -------- d-----w- c:\documents and settings\asdf\Application Data\Malwarebytes
2009-10-25 02:05 . 2009-10-26 02:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-25 00:05 . 2008-10-16 18:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-25 00:05 . 2008-10-16 18:06 208744 ----a-w- c:\windows\system32\muweb.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-03 05:36 . 2009-06-18 01:12 -------- d-----w- c:\documents and settings\asdf\Application Data\U3
2009-11-03 05:27 . 2007-06-08 20:29 1051 ----a-w- c:\windows\eReg.dat
2009-11-03 01:51 . 2006-12-20 01:11 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-26 02:33 . 2009-10-26 02:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-25 04:48 . 2009-09-20 02:19 -------- d-----w- c:\documents and settings\asdf\Application Data\vlc
2009-10-16 20:17 . 2008-09-22 05:23 -------- d-----w- c:\program files\Image-Line
2009-10-16 20:16 . 2008-09-22 05:25 -------- d-----w- c:\program files\VstPlugins
2009-10-12 00:35 . 2006-12-23 21:52 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-10-08 10:52 . 2008-05-27 04:25 -------- d-----w- c:\documents and settings\asdf\Application Data\OpenOffice.org2
2009-09-24 00:37 . 2007-07-30 19:17 249856 ------w- c:\windows\Setup1.exe
2009-09-24 00:37 . 2007-07-30 19:17 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-09-20 02:17 . 2009-09-20 02:17 -------- d-----w- c:\program files\VideoLAN
2009-09-17 00:26 . 2009-09-17 00:26 -------- d-----w- c:\program files\SopCast
2009-09-15 22:15 . 2008-04-07 21:48 41816 ----a-w- c:\documents and settings\asdf\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 21:35 . 2009-09-15 21:35 -------- d-----w- c:\program files\Microsoft
2009-09-15 21:35 . 2009-09-15 21:33 -------- d-----w- c:\program files\Windows Live
2009-09-15 21:34 . 2009-09-15 21:34 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-15 21:28 . 2009-09-15 21:28 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-10 18:54 . 2009-10-26 02:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-10-26 02:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 02:34 . 2009-08-27 02:34 36734 ----a-w- c:\windows\system32\OggDSuninst.exe
2009-08-17 17:25 . 2009-08-17 17:25 0 ----a-r- C:\logwmemory.bin
2009-08-07 00:24 . 2006-11-27 23:10 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 00:24 . 2006-11-27 23:10 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 00:24 . 2006-12-23 19:44 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 00:24 . 2006-11-27 23:10 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 00:24 . 2006-11-27 23:09 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 00:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 00:23 . 2006-11-27 23:09 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 00:23 . 2006-11-27 23:10 1929952 ----a-w- c:\windows\system32\wuaueng.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-03_22.14.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-04 15:29 . 2009-08-07 00:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2009-11-04 15:29 . 2009-08-07 00:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2006-11-27 23:10 . 2009-08-07 00:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2006-11-27 23:09 . 2009-08-07 00:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-04 12:00 . 2009-08-07 00:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2004-08-04 12:00 . 2004-08-04 12:00 95360 c:\windows\system32\dllcache\atapi.sys
+ 2007-07-24 20:58 . 2007-07-24 20:58 95616 c:\windows\junction.exe
+ 2006-11-27 23:10 . 2009-08-07 00:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2006-11-27 23:10 . 2009-08-07 00:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2006-11-27 23:09 . 2009-08-07 00:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2006-11-27 23:10 . 2009-08-07 00:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B0078AE3-C5C6-4980-9E7C-6FD3F5FEDB1D}]
2004-08-04 12:00 108288 ----a-w- c:\windows\system32\docpro.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"WinampAgent"="c:\program files\Winamp\Winampa.exe" [2001-04-30 10752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= c:\documents and settings\user\Desktop\stm\103est WestHill.mht
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= c:\documents and settings\user\Desktop\stm\161est pinedale.mht
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-19 17:05 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk
backup=c:\windows\pss\Lotus Organizer EasyClip.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus QuickStart.lnk
backup=c:\windows\pss\Lotus QuickStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SmartCenter.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus SmartCenter.lnk
backup=c:\windows\pss\Lotus SmartCenter.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SuiteStart.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lotus SuiteStart.lnk
backup=c:\windows\pss\Lotus SuiteStart.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Status Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Status Monitor.lnk
backup=c:\windows\pss\Status Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^OpenOffice.org 2.2.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\OpenOffice.org 2.2.lnk
backup=c:\windows\pss\OpenOffice.org 2.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMP54Gv4SVC"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\stuff\\LimeWire\\LimeWire.exe"=
"c:\\stuff\\Shareaza\\Shareaza.exe"=
"c:\\games\\Starcraft\\StarCraft.exe"=
"c:\\games\\actua\\actuasoc3\\Soccer3.exe"=
"c:\\games\\zsnes142\\zsnesw.exe"=
"c:\\games\\zsnes136\\ZSNESW.EXE"=
"c:\\games\\zbattle.net\\zbattle.net.exe"=
"c:\\games\\NHL 2002\\nhl2002.exe"=
"c:\\games\\lfs\\LFS.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\games\\GameSpy Arcade\\Aphex.exe"=
"c:\\games\\counterstrike 1.5\\hl.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\asdf\\Desktop\\Dethkarz_By_www.guidobot.tk\\Dethkarz\\Dethkarz.exe"=
"c:\\games\\Sega Rally 2\\SEGA RALLY 2.exe"=
"c:\\games\\Future Cop L.A.P.D\\FCopLAPD.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\asdf\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\games\\SWAT3\\Swat.exe"=
"c:\\games\\Soldat\\Soldat.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\games\\Unrealtournament\\System\\UnrealTournament.exe"=
"c:\\games\\EA Sports\\NHL 98\\nhl98.exe"=
"c:\\games\\Unrealtournament\\System\\Infiltration.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/07/2009 12:05 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [19/07/2009 12:05 PM 108552]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14/01/2008 5:06 AM 21632]
S3 alcan5ln;Alcatel SpeedTouch USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [06/04/2007 5:58 PM 36960]
S4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [19/07/2009 12:04 PM 907032]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [19/07/2009 12:04 PM 298776]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext =
https://login.live.com/ppsecure/sha1auth.srf?lc=4105
IE: E&xport to Microsoft Excel - c:\stuff\MICROS~1\Office10\EXCEL.EXE/3000
Trusted Zone: motive.com\pbctbc.bc
Trusted Zone: motive.com\pbctbcivr.bc
Trusted Zone: sympatico.ca\assistance
Trusted Zone: sympatico.ca\fix
Trusted Zone: sympatico.ca\rc
Trusted Zone: sympatico.ca\rcfr
Trusted Zone: sympatico.ca\service
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\asdf\Application Data\Mozilla\Firefox\Profiles\zfdt1tyr.default\
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\stuff\Adobe\Acrobat 5.0\Reader\browser\nppdf32.dll
FF - plugin: c:\stuff\divX\DivX Content Uploader\npUpload.dll
FF - plugin: c:\stuff\divX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: c:\stuff\divX\DivX Web Player\npdivx32.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin2.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin3.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin4.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin5.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin6.dll
FF - plugin: c:\stuff\quicktime\Plugins\npqtplugin7.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Infiltration_2.9 - c:\windows\iun6002.exe
AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-04 11:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8130D1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8130d1f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1460)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng-us.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\Brmfrmps.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-11-04 11:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-04 16:29
ComboFix2.txt 2009-11-03 22:24
Pre-Run: 2,445,549,568 bytes free
Post-Run: 2,404,790,272 bytes free
ESETSCan
C:\Documents and Settings\user\Local Settings\Temp\iwgaxlhp.sys Win32/Rootkit.Agent.NDA trojan cleaned by deleting - quarantined
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\HBGC7M1X\gnida[1].swf probably a variant of Win32/Agent trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\net.net.vir a variant of Win32/TrojanClicker.Punad.AA trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Win32/Small.NEB trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\hqoicvtthemuwpsp.sys.vir Win32/Olmarik.MJ trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_abkmzdfd_.dat.zip Win32/Agent.NOU trojan deleted - quarantined
C:\stuff\Image-Line\FL Studio 8\Fruity Loops Studio Producer Edition XXL v8.0.0 Crack.exe a variant of Win32/Injector.EH trojan cleaned by deleting - quarantined
C:\stuff\Shareaza\Downloads\Fruity Loops Studio 8 XXL Producer Edition\FL.Studio.8.0.0.XXL.Producer.Edition\Crack\Fruity Loops Studio Producer Edition XXL v8.0.0 Crack.exe a variant of Win32/Injector.EH trojan cleaned by deleting - quarantined
C:\stuff\Shareaza\Downloads\Fruity Loops Studio 8 XXL Producer Edition\FL.Studio.8.0.0.XXL.Producer.Edition\setup\flstudio_8.0_install.exe probably a variant of Win32/Delf trojan deleted - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000052.exe Win32/Small.NEB trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000314.sys Win32/Olmarik.MJ trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000461.sys Win32/Rootkit.Agent.NDA trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000462.exe a variant of Win32/Injector.EH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000463.exe a variant of Win32/Injector.EH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{9BC14C3F-2553-4173-B8F4-1D6849AB7A60}\RP1\A0000464.exe probably a variant of Win32/Delf trojan deleted - quarantined
C:\WINDOWS\update2.html Win32/Spy.BZub.IK trojan cleaned by deleting - quarantined
C:\WINDOWS\system32\docpro.2 a variant of Win32/Adware.BHO.NBI application cleaned by deleting - quarantined
C:\WINDOWS\system32\docpro.3 a variant of Win32/Adware.BHO.NBI application cleaned by deleting - quarantined
C:\WINDOWS\system32\docpro.4 a variant of Win32/Adware.BHO.NBI application cleaned by deleting - quarantined
C:\WINDOWS\system32\docpro.dll probably a variant of Win32/Genetik trojan cleaned by deleting - quarantined
C:\WINDOWS\system32\drivers\abkmzdfd.sys Win32/Rootkit.Agent.KT trojan cleaned by deleting - quarantined
C:\WINDOWS\system32\drivers\iwgaxlhp.dat Win32/Agent.NMY trojan cleaned by deleting - quarantined
OTL
OTL logfile created on: 04/11/2009 2:09:29 PM - Run 1
OTL by OldTimer - Version 3.1.3.3 Folder = C:\Documents and Settings\asdf\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
254.73 Mb Total Physical Memory | 61.89 Mb Available Physical Memory | 24.30% Memory free
624.82 Mb Paging File | 293.55 Mb Available in Paging File | 46.98% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 2.18 Gb Free Space | 5.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-1053E8CAB5
Current User Name: asdf
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009/11/04 14:08:13 | 00,528,384 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\asdf\Desktop\OTL.exe
PRC - [2009/10/28 16:57:30 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/07/19 12:05:02 | 00,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2008/08/14 16:11:48 | 00,565,008 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/07/26 07:23:42 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2008/07/26 07:23:42 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
PRC - [2008/01/31 12:23:03 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciCMService.exe
PRC - [2007/06/13 05:23:07 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2004/08/04 07:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2003/05/05 18:30:22 | 00,065,536 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\system32\Brmfrmps.exe
PRC - [2001/12/12 23:01:00 | 00,045,056 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brss01a.exe
PRC - [2001/02/23 09:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
========== Modules (SafeList) ==========
MOD - [2009/11/04 14:08:13 | 00,528,384 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\asdf\Desktop\OTL.exe
MOD - [2006/08/25 10:45:55 | 01,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
MOD - [2004/08/04 07:00:00 | 00,185,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll
MOD - [2004/08/04 07:00:00 | 00,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mslbui.dll
========== Win32 Services (SafeList) ==========
SRV - File not found -- -- (WMP54Gv4SVC)
SRV - File not found -- -- (Viewpoint Manager Service)
SRV - [2009/07/24 10:28:17 | 00,907,032 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgemc.exe -- (avg8emc)
SRV - [2009/07/19 12:04:51 | 00,298,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2008/07/26 07:25:36 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008/07/26 07:23:42 | 00,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2008/07/25 10:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/07/25 10:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state)
SRV - [2008/01/31 12:23:03 | 00,303,104 | ---- | M] (Motive Communications, Inc.) -- C:\Program Files\Common Files\Motive\McciCMService.exe -- (McciCMService)
SRV - [2007/06/15 16:55:00 | 00,300,544 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc)
SRV - [2004/08/04 07:00:00 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll -- (helpsvc)
SRV - [2003/05/05 18:30:22 | 00,065,536 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\Brmfrmps.exe -- (brmfrmps)
SRV - [2002/04/11 23:00:00 | 00,057,344 | ---- | M] (brother Industries Ltd) -- C:\WINDOWS\system32\brsvc01a.exe -- (Brother XP spl Service)
SRV - [2001/02/23 09:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe -- (MDM)
========== Driver Services (SafeList) ==========
DRV - File not found -- -- (catchme)
DRV - [2009/07/24 10:29:05 | 00,335,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2009/07/19 12:05:33 | 00,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2009/07/19 12:05:32 | 00,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2009/01/10 02:02:34 | 00,717,296 | ---- | M] () -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/01/10 01:36:48 | 00,094,208 | ---- | M] (VSO Software) -- C:\WINDOWS\system32\drivers\ezplay.sys -- (ezplay)
DRV - [2009/01/10 01:36:28 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\system32\drivers\pcouffin.sys -- (pcouffin)
DRV - [2008/07/26 10:26:22 | 00,041,752 | R--- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2008/07/26 10:25:48 | 00,627,864 | R--- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2008/07/26 10:22:34 | 02,570,520 | R--- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI)
DRV - [2008/07/26 10:22:22 | 00,013,848 | R--- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2008/07/26 07:25:02 | 00,025,624 | ---- | M] () -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008/01/31 12:21:54 | 00,018,304 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2008/01/31 12:20:50 | 00,019,712 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2008/01/14 05:06:32 | 00,021,632 | ---- | M] (ManyCam LLC.) -- C:\WINDOWS\system32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2007/11/13 05:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv)
DRV - [2007/07/02 14:41:10 | 00,036,624 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20)
DRV - [2007/06/30 13:46:36 | 00,020,747 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP)
DRV - [2007/02/22 11:15:56 | 00,137,216 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcd.sys -- (nmwcd)
DRV - [2007/02/22 11:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdcm.sys -- (nmwcdcm)
DRV - [2007/02/22 11:15:14 | 00,012,288 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdcj.sys -- (nmwcdcj)
DRV - [2007/02/22 11:15:14 | 00,008,320 | ---- | M] (Nokia) -- C:\WINDOWS\system32\drivers\nmwcdc.sys -- (nmwcdc)
DRV - [2006/10/31 14:15:16 | 00,165,752 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B)
DRV - [2006/06/29 16:11:08 | 00,011,712 | ---- | M] (IBM Corporation) -- C:\WINDOWS\system32\EGATHDRV.SYS -- (EGATHDRV)
DRV - [2005/10/27 14:06:30 | 00,356,096 | ---- | M] (Ralink Technology Inc.) -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2004/08/04 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)
DRV - [2004/08/03 22:07:56 | 00,059,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio)
DRV - [2004/08/03 17:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2004/06/12 04:27:18 | 00,051,712 | ---- | M] (Brother Industries Ltd.) -- C:\WINDOWS\system32\drivers\BrSerIf.sys -- (BrSerIf)
DRV - [2004/04/30 08:37:02 | 00,160,640 | ---- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\a347bus.sys -- (a347bus)
DRV - [2004/04/30 08:33:00 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\System32\Drivers\a347scsi.sys -- (a347scsi)
DRV - [2004/01/10 03:28:18 | 00,011,648 | ---- | M] (Brother Industries Ltd.) -- C:\WINDOWS\system32\drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2003/12/19 20:15:50 | 00,015,263 | ---- | M] (Brother Industries Ltd.) -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2002/05/03 09:41:22 | 00,036,960 | ---- | M] (Alcatel Bell) -- C:\WINDOWS\system32\drivers\alcan5ln.sys -- (alcan5ln)
DRV - [2002/05/03 09:41:04 | 00,735,568 | ---- | M] (Alcatel Bell) -- C:\WINDOWS\system32\drivers\alcaudsl.sys -- (alcaudsl)
DRV - [2001/08/17 12:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1)
DRV - [2001/08/17 07:20:04 | 00,096,256 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-1715567821-606747145-725345543-1009\S-1-5-21-1715567821-606747145-725345543-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.15
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/07/19 12:04:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/28 16:57:30 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/28 16:57:32 | 00,000,000 | ---D | M]
[2009/06/27 00:26:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Mozilla\Extensions
[2009/06/27 00:26:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/16 18:13:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Mozilla\Firefox\Profiles\yu0u3pv2.new\extensions
[2009/07/24 11:10:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Mozilla\Firefox\Profiles\zfdt1tyr.default\extensions
[2009/07/16 18:05:54 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/10/28 16:57:30 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/10/28 16:57:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2009/10/28 16:57:30 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2008/08/06 15:22:02 | 00,114,688 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
[2009/10/28 16:57:32 | 00,065,528 | ---- | M] (mozilla.org) -- C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/01/02 21:19:39 | 00,131,072 | ---- | M] (Apple Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2009/06/27 00:25:25 | 00,001,394 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/06/27 00:25:25 | 00,002,193 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2009/06/27 00:25:25 | 00,001,534 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/06/27 00:25:25 | 00,002,343 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2009/06/27 00:25:25 | 00,001,706 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2009/06/27 00:25:25 | 00,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\stuff\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\stuff\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\Winampa.exe ()
O4 - HKU\.DEFAULT..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-18..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe (Time Information Services Ltd.)
O4 - HKU\S-1-5-21-1715567821-606747145-725345543-1009..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1715567821-606747145-725345543-1009\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1715567821-606747145-725345543-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1715567821-606747145-725345543-1009_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\stuff\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://a1540.g.akamai.net/7/1540/52/200705...ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/3/9...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://dev.srtest.com/srl_bin/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518}
http://www.easports.com/downloads/games/common/ieell.cab (ell Class)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/...b?1166902988953 (WUWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE}
http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084}
http://www-307.ibm.com/pc/support/IbmEgath.cab (IBM Access Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/flash...ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
http://download.mcafee.com/molbin/iss-loc/...109/mcfscan.cab (McFreeScan Class)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong
http://download2.games.yahoo.com/games/clients/y/ot0_x.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop Components:1 () - C:\Documents and Settings\user\Desktop\stm\103est WestHill.mht
O24 - Desktop Components:2 () - C:\Documents and Settings\user\Desktop\stm\161est pinedale.mht
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/11/27 18:13:07 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/11/04 14:08:11 | 00,528,384 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\asdf\Desktop\OTL.exe
[2009/11/04 11:33:46 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009/11/04 11:29:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/11/04 10:54:49 | 00,000,000 | ---D | C] -- C:\thcbytes23883t
[2009/11/03 16:50:38 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/11/03 16:46:21 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/11/03 16:46:18 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/11/03 16:46:18 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/11/03 16:46:18 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/11/03 16:46:03 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/11/03 16:46:00 | 00,000,000 | ---D | C] -- C:\thcbytes
[2009/11/03 16:45:10 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/11/03 16:35:58 | 00,000,000 | ---D | C] -- C:\Avenger
[2009/11/03 16:33:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\asdf\Desktop\avenger
[2009/10/26 10:56:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\asdf\Desktop\RootRepeal
[2009/10/25 21:33:10 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/25 21:33:07 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/10/25 21:33:06 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/10/25 21:31:23 | 04,045,528 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\asdf\Desktop\mbam-setup.exe
[2009/10/25 13:12:13 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/10/25 13:11:55 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\asdf\Desktop\HJTInstall.exe
[2009/10/25 13:03:15 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/10/24 21:05:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\asdf\Application Data\Malwarebytes
[2009/10/24 21:05:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/24 19:05:36 | 00,268,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2009/10/24 19:05:36 | 00,208,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\muweb.dll
[2009/10/24 19:05:36 | 00,027,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2009/01/10 01:36:48 | 00,094,208 | ---- | C] (VSO Software) -- C:\Documents and Settings\asdf\Application Data\ezplay.sys
[2009/01/10 01:36:28 | 00,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\asdf\Application Data\pcouffin.sys
[2007/06/12 22:26:54 | 00,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2007/06/12 22:26:54 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2009/11/04 14:08:13 | 00,528,384 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\asdf\Desktop\OTL.exe
[2009/11/04 11:33:28 | 02,664,072 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\esetsmartinstaller_enu.exe
[2009/11/04 11:32:16 | 05,505,024 | -H-- | M] () -- C:\Documents and Settings\asdf\NTUSER.DAT
[2009/11/04 11:31:26 | 00,001,432 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\DelDomains.inf
[2009/11/04 11:21:16 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/11/04 11:20:57 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/11/04 11:20:46 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/11/04 11:20:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/11/04 11:20:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/11/04 11:20:15 | 26,717,7984 | -HS- | M] () -- C:\hiberfil.sys
[2009/11/04 11:19:01 | 00,000,278 | -HS- | M] () -- C:\Documents and Settings\asdf\ntuser.ini
[2009/11/04 10:52:26 | 03,533,737 | R--- | M] () -- C:\Documents and Settings\asdf\Desktop\thcbytes.exe
[2009/11/04 10:30:12 | 00,046,375 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\Junction.zip
[2009/11/03 16:50:48 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/11/03 16:06:46 | 00,047,616 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\Win32kDiag.exe
[2009/11/03 12:49:45 | 00,001,065 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2009/11/03 02:42:36 | 01,383,376 | -H-- | M] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\IconCache.db
[2009/11/03 00:48:15 | 00,523,776 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\dds.pif
[2009/11/03 00:27:23 | 00,001,051 | ---- | M] () -- C:\WINDOWS\eReg.dat
[2009/11/02 20:51:56 | 00,001,744 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/11/02 20:51:49 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/11/02 20:49:22 | 10,043,1872 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\NHL_2003.part1.rar
[2009/11/01 01:49:18 | 00,495,816 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/11/01 01:49:17 | 00,590,966 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/11/01 01:49:17 | 00,086,098 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/27 23:28:02 | 00,004,930 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\1256702311701.png
[2009/10/26 10:52:55 | 00,465,298 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\RootRepeal.rar
[2009/10/25 22:57:50 | 06,051,840 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\00440.mp3
[2009/10/25 21:33:15 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/25 21:31:42 | 04,045,528 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\asdf\Desktop\mbam-setup.exe
[2009/10/25 21:23:13 | 00,059,664 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\mbam-clean.exe
[2009/10/25 21:11:02 | 00,262,144 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\rkill.com
[2009/10/25 18:40:18 | 00,029,184 | ---- | M] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/25 16:21:33 | 00,000,748 | ---- | M] () -- C:\Documents and Settings\asdf\My Documents\adminkey.reg
[2009/10/25 13:12:56 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\HijackThis.lnk
[2009/10/25 13:11:58 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\asdf\Desktop\HJTInstall.exe
[2009/10/25 12:28:58 | 00,524,288 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\dds.scr
[2009/10/25 06:11:34 | 00,077,312 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2009/10/22 23:06:36 | 00,000,000 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\watch.wtc
[2009/10/16 15:37:06 | 00,001,648 | ---- | M] () -- C:\Documents and Settings\asdf\Desktop\Play Infiltration.lnk
[2009/10/11 19:35:49 | 00,001,632 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2009/10/11 08:10:09 | 00,236,544 | ---- | M] () -- C:\WINDOWS\PEV.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2009/11/04 11:33:12 | 02,664,072 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\esetsmartinstaller_enu.exe
[2009/11/04 11:31:24 | 00,001,432 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\DelDomains.inf
[2009/11/04 10:30:08 | 00,046,375 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\Junction.zip
[2009/11/03 16:50:48 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/11/03 16:50:42 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/11/03 16:46:21 | 00,236,544 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2009/11/03 16:46:21 | 00,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2009/11/03 16:46:18 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/11/03 16:46:18 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/11/03 16:46:18 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/11/03 16:42:51 | 03,533,737 | R--- | C] () -- C:\Documents and Settings\asdf\Desktop\thcbytes.exe
[2009/11/03 00:48:14 | 00,523,776 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\dds.pif
[2009/11/02 20:36:27 | 10,043,1872 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\NHL_2003.part1.rar
[2009/10/27 23:27:50 | 00,004,930 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\1256702311701.png
[2009/10/26 14:14:23 | 00,047,616 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\Win32kDiag.exe
[2009/10/26 10:52:50 | 00,465,298 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\RootRepeal.rar
[2009/10/25 22:56:57 | 06,051,840 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\00440.mp3
[2009/10/25 21:33:15 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/25 21:23:09 | 00,059,664 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\mbam-clean.exe
[2009/10/25 21:10:57 | 00,262,144 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\rkill.com
[2009/10/25 16:31:12 | 26,717,7984 | -HS- | C] () -- C:\hiberfil.sys
[2009/10/25 16:21:33 | 00,000,748 | ---- | C] () -- C:\Documents and Settings\asdf\My Documents\adminkey.reg
[2009/10/25 13:12:13 | 00,001,734 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\HijackThis.lnk
[2009/10/25 12:26:32 | 00,524,288 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\dds.scr
[2009/10/22 23:06:36 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\watch.wtc
[2009/10/16 15:37:06 | 00,001,648 | ---- | C] () -- C:\Documents and Settings\asdf\Desktop\Play Infiltration.lnk
[2009/08/20 16:58:17 | 00,001,065 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2009/08/10 21:16:24 | 00,000,000 | ---- | C] () -- C:\WINDOWS\EAREMOVE.INI
[2009/07/10 20:10:19 | 00,066,482 | R--- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/06/08 20:32:43 | 00,217,088 | ---- | C] () -- C:\WINDOWS\System32\libmySQL.dll
[2009/06/08 20:32:43 | 00,102,400 | ---- | C] () -- C:\WINDOWS\System32\TrackerNET.dll
[2009/06/08 19:58:11 | 00,000,522 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2009/06/08 16:18:55 | 00,000,056 | ---- | C] () -- C:\WINDOWS\FinalSun.ini
[2009/01/13 16:34:09 | 00,000,127 | ---- | C] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\fusioncache.dat
[2009/01/10 02:02:34 | 00,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/01/10 01:37:10 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\ezplay.log
[2009/01/10 01:36:48 | 00,007,861 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\ezplay.cat
[2009/01/10 01:36:48 | 00,001,103 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\ezplay.inf
[2009/01/10 01:36:48 | 00,000,125 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\ezplay.ini
[2009/01/10 01:36:47 | 00,000,034 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\pcouffin.log
[2009/01/10 01:36:28 | 00,007,887 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\pcouffin.cat
[2009/01/10 01:36:28 | 00,001,144 | ---- | C] () -- C:\Documents and Settings\asdf\Application Data\pcouffin.inf
[2008/09/07 15:15:33 | 00,004,883 | ---- | C] () -- C:\WINDOWS\FRED2.INI
[2008/07/26 07:25:02 | 00,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/07/20 10:40:27 | 00,000,295 | ---- | C] () -- C:\WINDOWS\ACTIVEJP.INI
[2008/07/17 15:52:27 | 00,029,184 | ---- | C] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/16 12:55:50 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/05/16 19:08:32 | 00,000,051 | ---- | C] () -- C:\WINDOWS\brmx2001.ini
[2008/04/07 16:48:59 | 00,041,816 | ---- | C] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/04/01 18:04:12 | 00,000,028 | ---- | C] () -- C:\WINDOWS\pdf995.ini
[2008/03/29 02:59:53 | 01,383,376 | -H-- | C] () -- C:\Documents and Settings\asdf\Local Settings\Application Data\IconCache.db
[2008/03/26 21:21:46 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\asdf\Application Data\desktop.ini
[2007/11/23 14:24:32 | 00,000,056 | ---- | C] () -- C:\WINDOWS\WDIRECT.INI
[2007/10/22 17:47:48 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2007/08/17 00:37:13 | 00,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/08/15 01:17:02 | 00,000,206 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2007/08/01 08:53:54 | 00,008,498 | ---- | C] () -- C:\WINDOWS\System32\cnf.ini
[2007/07/02 14:41:13 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/07/02 14:36:50 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/30 13:46:32 | 00,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2007/06/30 13:46:08 | 00,000,890 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2007/06/18 20:22:08 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2007/06/12 23:08:52 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2007/04/27 23:57:53 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\impborl.dll
[2007/04/18 07:47:44 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\pdfmona.dll
[2007/04/18 07:47:44 | 00,051,716 | ---- | C] () -- C:\WINDOWS\System32\pdf995mon.dll
[2007/04/18 07:47:44 | 00,000,060 | ---- | C] () -- C:\WINDOWS\wpd99.drv
[2007/04/17 17:28:18 | 00,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2007/04/09 15:18:03 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Brownie.ini
[2007/04/09 14:57:22 | 00,000,030 | ---- | C] () -- C:\WINDOWS\System32\brss01a.ini
[2007/04/09 14:54:52 | 00,000,236 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2007/04/09 14:54:52 | 00,000,092 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2007/04/09 14:54:51 | 00,000,463 | ---- | C] () -- C:\WINDOWS\brwmark.ini
[2007/04/09 14:54:51 | 00,000,079 | ---- | C] () -- C:\WINDOWS\BRPP2KA.INI
[2007/04/09 14:51:40 | 00,027,019 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2007/04/09 14:42:35 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Net-It Now! SE.INI
[2007/04/09 14:41:55 | 00,000,038 | ---- | C] () -- C:\WINDOWS\Approach.ini
[2007/04/06 17:59:00 | 00,005,605 | ---- | C] () -- C:\WINDOWS\System32\stci.dll
[2007/03/29 23:00:40 | 00,203,264 | R--- | C] () -- C:\WINDOWS\System32\CddbCdda.dll
[2006/11/27 12:40:53 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/04 07:00:00 | 00,000,654 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 07:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2002/10/06 13:42:57 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002/10/04 18:04:25 | 00,921,600 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 18:04:24 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2002/10/04 18:04:17 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2002/03/04 09:16:34 | 00,110,592 | R--- | C] () -- C:\WINDOWS\System32\Jpeg32.dll
[2000/07/05 11:53:06 | 00,088,064 | ---- | C] () -- C:\WINDOWS\System32\AudioExCtl.dll
[1999/03/10 20:23:00 | 00,222,928 | ---- | C] () -- C:\WINDOWS\System32\lobas09.dll
[1998/03/18 20:23:00 | 00,096,256 | ---- | C] () -- C:\WINDOWS\System32\nsqlc32.dll
[1998/01/13 20:23:00 | 00,047,104 | ---- | C] () -- C:\WINDOWS\System32\lotrn13.dll
[1997/11/14 20:23:00 | 00,031,008 | ---- | C] () -- C:\WINDOWS\System32\ivtrn09.dll
[1997/05/13 20:23:00 | 00,000,153 | ---- | C] () -- C:\WINDOWS\acroread.ini
[1994/07/25 20:23:00 | 00,014,928 | ---- | C] () -- C:\WINDOWS\System32\wingen.drv
[1994/04/07 20:23:00 | 00,000,462 | ---- | C] () -- C:\WINDOWS\lodbf13.ini
========== LOP Check ==========
[2009/05/20 13:45:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2009/01/10 02:08:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2007/11/19 17:29:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2007/11/19 17:40:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/03/08 21:10:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2007/04/09 14:51:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/07/24 11:35:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2009/08/28 15:09:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/05/20 13:45:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/05/20 13:49:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\acccore
[2009/01/10 02:10:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\DAEMON Tools
[2009/01/10 02:10:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\DAEMON Tools Lite
[2009/01/10 02:10:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\DAEMON Tools Pro
[2009/07/26 14:48:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\GeoVid
[2009/07/01 14:10:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Key Metric Software
[2009/07/10 20:07:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Leadertech
[2009/01/10 01:53:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\log
[2009/07/20 19:43:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\ManyCam
[2008/08/29 15:28:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Nokia Multimedia Player
[2009/07/15 20:25:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\NotMyIp
[2008/08/29 15:27:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\PC Suite
[2008/04/01 18:04:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\pdf995
[2008/12/10 18:17:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Personal Composer DEMO
[2009/08/17 12:23:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Soldat
[2009/07/26 14:46:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\VisiFly
[2009/01/10 01:37:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\asdf\Application Data\Vso
[2006/12/19 20:11:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Atari
[2008/03/21 02:16:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\AVG7
[2007/04/06 18:13:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\InterTrust
[2006/12/19 20:06:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Leadertech
[2007/11/19 17:49:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Nokia
[2007/11/19 17:33:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\PC Suite
[2007/04/10 16:41:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\Shareaza
[2004/08/04 07:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/11/04 11:20:26 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\asdf\Desktop\dds.scr:SummaryInformation
@Alternate Data Stream - 487 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
< End of report >
EXTRAS
OTL Extras logfile created on: 04/11/2009 2:09:29 PM - Run 1
OTL by OldTimer - Version 3.1.3.3 Folder = C:\Documents and Settings\asdf\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
254.73 Mb Total Physical Memory | 61.89 Mb Available Physical Memory | 24.30% Memory free
624.82 Mb Paging File | 293.55 Mb Available in Paging File | 46.98% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 2.18 Gb Free Space | 5.85% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: USER-1053E8CAB5
Current User Name: asdf
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- "%SYSTEMROOT%\hh.exe" %1
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SYSTEMROOT%\hh.exe" %1 File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "C:\stuff\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" File not found
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) -- File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\StubInstaller.exe" = C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer -- (LimeWire)
"C:\stuff\LimeWire\LimeWire.exe" = C:\stuff\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- (Lime Wire, LLC)
"C:\stuff\Shareaza\Shareaza.exe" = C:\stuff\Shareaza\Shareaza.exe:*:Enabled:Shareaza -- (Shareaza Development Team)
"C:\games\Starcraft\StarCraft.exe" = C:\games\Starcraft\StarCraft.exe:*:Enabled:Starcraft -- (Blizzard Entertainment)
"C:\games\actua\actuasoc3\Soccer3.exe" = C:\games\actua\actuasoc3\Soccer3.exe:*:Enabled:actua99 -- (Gremlin)
"C:\games\zsnes142\zsnesw.exe" = C:\games\zsnes142\zsnesw.exe:*:Enabled:zsnesw -- ()
"C:\games\zsnes136\ZSNESW.EXE" = C:\games\zsnes136\ZSNESW.EXE:*:Enabled:ZSNESW -- ()
"C:\games\zbattle.net\zbattle.net.exe" = C:\games\zbattle.net\zbattle.net.exe:*:Enabled:zbattle.net -- ()
"C:\games\NHL 2002\nhl2002.exe" = C:\games\NHL 2002\nhl2002.exe:*:Enabled:nhl2002 -- ()
"C:\games\lfs\LFS.exe" = C:\games\lfs\LFS.exe:*:Enabled:LFS -- ( )
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader -- (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM -- (AOL LLC)
"C:\games\GameSpy Arcade\Aphex.exe" = C:\games\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade -- (IGN Entertainment, Inc.)
"C:\games\counterstrike 1.5\hl.exe" = C:\games\counterstrike 1.5\hl.exe:*:Enabled:Half-Life Launcher -- (Valve, L.L.C.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\Documents and Settings\asdf\Desktop\Dethkarz_By_www.guidobot.tk\Dethkarz\Dethkarz.exe" = C:\Documents and Settings\asdf\Desktop\Dethkarz_By_www.guidobot.tk\Dethkarz\Dethkarz.exe:*:Enabled:Dethkarz -- (Beam Software)
"C:\games\Sega Rally 2\SEGA RALLY 2.exe" = C:\games\Sega Rally 2\SEGA RALLY 2.exe:*:Enabled:Sega Rally 2 PC RALLY.EXE [i586] -- (Sega Enterprises, Ltd.)
"C:\games\Future Cop L.A.P.D\FCopLAPD.exe" = C:\games\Future Cop L.A.P.D\FCopLAPD.exe:*:Enabled:FCopLAPD -- ()
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)
"C:\Documents and Settings\asdf\Local Settings\Application Data\Dyyno Receiver\DPPM.exe" = C:\Documents and Settings\asdf\Local Settings\Application Data\Dyyno Receiver\DPPM.exe:*:Enabled:Dyyno Plugin Receiver -- ()
"C:\games\SWAT3\Swat.exe" = C:\games\SWAT3\Swat.exe:*:Enabled:Swat 3 : Close Quarters Battle -- (Sierra On-Line, Inc.)
"C:\games\Soldat\Soldat.exe" = C:\games\Soldat\Soldat.exe:*:Enabled:http://soldat.pl -- (Michal Marcinkowski)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\SopCast\SopCast.exe" = C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application -- (www.sopcast.com)
"C:\Program Files\SopCast\adv\SopAdver.exe" = C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver -- (www.sopcast.com)
"C:\games\Unrealtournament\System\UnrealTournament.exe" = C:\games\Unrealtournament\System\UnrealTournament.exe:*:Enabled:UnrealTournament -- ()
"C:\games\EA Sports\NHL 98\nhl98.exe" = C:\games\EA Sports\NHL 98\nhl98.exe:*:Enabled:nhl98 -- ()
"C:\games\Unrealtournament\System\Infiltration.exe" = C:\games\Unrealtournament\System\Infiltration.exe:*:Enabled:Infiltration -- ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{005E738B-5A0A-4483-A900-877D183A8F45}_is1" = BlindWrite 6
"{11964613-805F-432D-A12B-169554B793E7}" = Nokia Connectivity Cable Driver
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java SE Runtime Environment 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4DDC3BED-CC68-44AA-B435-D727B620CA5B}" = Linksys Wireless-G PCI Adapter
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{99A40651-0BC2-4095-8F9A-A40FAB224FEF}" = PC Connectivity Solution
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A1C8D94A-4303-4489-B585-4B6E6CD408CB}" = OpenOffice.org 2.2
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}" = Nokia PC Suite
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = Alcatel SpeedTouch USB Software
"{E9F81423-211E-46B6-9AE0-38568BC5CF6F}" =
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1362843-0E0E-4F74-8662-724CF101ADCE}" = Skype web features
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.5
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"4077F884D1BB007055BDB83B621D87220A73F30F" = Windows Driver Package - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AIM_6" = AIM 6
"AVG8Uninstall" = AVG Free 8.5
"B726756F5B5A5AA9D798B399386FC6205A45F19E" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"Battle.net" = Battle.net
"BellCanada.MCCInstall" = Sympatico NetAssistant
"CD8424B9400BFF7D34AA18F816C71322AC4BDAA7" = Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1)
"Citrus Alarm Clock_is1" = Citrus Alarm Clock 1.0.5
"ESET Online Scanner" = ESET Online Scanner v3
"Flv Audio Extractor_is1" = Flv Audio Extractor 1.04
"FLV Player_is1" = Free FLV Player V0.05
"Future Cop L.A.P.D." = Future Cop L.A.P.D.
"GameSpy Arcade" = GameSpy Arcade
"GCFScape_is1" = GCFScape 1.3.1
"GLSetup" = GLSetup
"Half-Life" = Half-Life
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"IL Download Manager" = IL Download Manager
"Internet Check-Up" = Internet Check-Up
"IrfanView" = IrfanView (remove only)
"LFSTweak S1 .3G" = LFSTweak S1 .3G
"LimeWire" = LimeWire 4.12.11
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"ManyCam" = ManyCam 2.4 (remove only)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MjuiceWinamp" = Mjuice Components
"Mozilla Firefox (3.0.14)" = Mozilla Firefox (3.0.14)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NetworkActiv PIAFCTM 1.5" = NetworkActiv PIAFCTM 1.5
"NHL 98" = NHL 98
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"OggDS" = Direct Show Ogg Vorbis Filter (remove only)
"PdfEdit995" = PdfEdit995
"pepakura_viewer3_crobo_en" = Pepakura Viewer 3 for CraftROBO
"Personal Composer DEMO" = Personal Composer DEMO
"POD-Bot 2.5" = POD-Bot 2.5
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer
"Red Alert: A Path Beyond FDS" = Red Alert: A Path Beyond FDS 0.9935
"Security Task Manager" = Security Task Manager 1.7h
"Shareaza_is1" = Shareaza version 2.2.5.0
"Sierra Utilities" = Sierra Utilities
"Signature995" = Signature995
"SmartSuite V99.0" = Lotus SmartSuite Release 9.5
"Soldat_is1" = Soldat 1.5.0
"SopCast" = SopCast 3.0.3
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"ST6UNST #1" = StarForge
"ST6UNST #2" = Hero Editor V0.96
"Starcraft" = Starcraft
"StealthBot v2.6 Revision 3" = StealthBot v2.6 Revision 3 (remove only)
"SWAT3 Elite Edition" = SWAT3 Elite Edition
"SystemRequirementsLab" = System Requirements Lab
"Valve Hammer Editor" = Valve Hammer Editor
"VIV Wizard v0.9.0.299_is1" = VIV Wizard v0.9.0.299
"VLC media player" = VLC media player 1.0.1
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinUHA_is1" = WinUHA 2.0 RC1 (2005.02.27)
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WOLAPI" = Westwood Shared Internet Components
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5
"zbattle.net_is1" = zbattle.net 1.09 SR-1 beta
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 16/10/2009 4:38:37 PM | Computer Name = USER-1053E8CAB5 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.2180, fault address 0x0001295d.
Error - 25/10/2009 7:14:07 PM | Computer Name = USER-1053E8CAB5 | Source = Application Error | ID = 1000
Description = Faulting application nhl2002.exe, version 0.0.0.0, faulting module
ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2.
Error - 25/10/2009 7:14:22 PM | Computer Name = USER-1053E8CAB5 | Source = Application Error | ID = 1000
Description = Faulting application nhl2002.exe, version 0.0.0.0, faulting module
ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2.
Error - 02/11/2009 1:10:53 PM | Computer Name = USER-1053E8CAB5 | Source = Application Error | ID = 1000
Description = Faulting application nhl2002.exe, version 0.0.0.0, faulting module
nhl2002.exe, version 0.0.0.0, fault address 0x001e7a30.
Error - 03/11/2009 5:55:01 PM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 03/11/2009 5:55:01 PM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 04/11/2009 11:57:11 AM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 04/11/2009 11:57:12 AM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 04/11/2009 12:01:16 PM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: A connection with the server could not be established
Error - 04/11/2009 12:01:17 PM | Computer Name = USER-1053E8CAB5 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
[ System Events ]
Error - 04/11/2009 12:01:24 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.
Error - 04/11/2009 12:16:56 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.
Error - 04/11/2009 12:16:56 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).
Error - 04/11/2009 12:18:06 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.
Error - 04/11/2009 12:18:33 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the PEVSystemStart service
to connect.
Error - 04/11/2009 12:18:33 PM | Computer Name = USER-1053E8CAB5 | Source = PlugPlayManager | ID = 11
Description = The device Root\LEGACY_KRNNTWWO\0000 disappeared from the system without
first being prepared for removal.
Error - 04/11/2009 12:20:39 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7000
Description = The Viewpoint Manager Service service failed to start due to the following
error: %%3
Error - 04/11/2009 12:20:39 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
krnntwwo
Error - 04/11/2009 12:20:55 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).
Error - 04/11/2009 12:26:46 PM | Computer Name = USER-1053E8CAB5 | Source = Service Control Manager | ID = 7016
Description = The BrSplService service has reported an invalid current state 0.
< End of report >