Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

WoW account hacked; probably keylogger; trying to ensure system is safe.


  • This topic is locked This topic is locked
6 replies to this topic

#1 avanduser

avanduser

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:57 AM

Posted 06 November 2009 - 10:30 PM

MOVING THIS POST OVER FROM INCORRECT FORUM (apologies)

(I followed the steps in the "Preparation Guide for use before posting about your potential Malware problem". I was unable to use 'RootRepeal' as it says it is not compatible with 64bit OS (Windows 7 RC). I also do not see anywhere to attach a file to my post, perhaps because I am new to the forum. I can post the 'Attach.txt' if needed. Logs are at the bottom of post, after my long-winded explanation).

Recently (Saturday) my World of Warcraft account was accessed by someone else and my characters devasted. Since I absolutely without exception do not share my account information with anyone else, I am left with the conclusion that this was most likely accomplished by a keylogger on my system. However, I am pretty zealous about computer security (within the bounds of my knowledge) and I am not sure how my system was compromised (I run Avast AV in full active mode, update and run Malwarebytes regularly; browse Internet using Firefox w/ NoScript and Adblock). Matters are further complicated by the fact that I have been unable to detect any malicious programs, etc. on my system since the hack. The only evidence I have is that my WoW account is in shambles. I was able to recover access to my account by using my laptop, but the damage is already done. However, I would very much like to ensure that my system is truly clean and would very much appreciate any advice/suggestions as to what steps to take and/or tools to use in the future to protect myself.

Steps I have followed so far upon discovering my account had been compromised:

1. Immediately checked Task Manager for unfamiliar processes. I have been in the habit of checking my running processes for years, so that when something new appears it usually jumps out at me. I noticed a process called 'wow.exe' running and immediately killed it (the game was not running at the time).

2. Deleted the last two things I downloaded for WoW (an addon called 'Jamba' and a program called 'Octopus' (similar to Synergy)). Even though I had scanned these after downloading and found them both free of anything, I deleted them out of precaution (read: panic).

2. Opened Malwarebytes and ran Full Scan. 0 infections.

3. Ran Avast full scan of all HDD's in 'thorough mode' with 'scan archives' ticked. 0 results.

4. Following a friend's suggestion I downloaded AVG, disabled Avast, then ran a full scan with AVG. 0 results.

5. Uninstalled AVG, and ran a scan using ESET Online Scanner. 0 results.

6. Rebooted in 'Safe Mode' and repeated steps 2 and 3. Also, installed Spybot S&D and ran full scan. All three programs returned 0 results.

At this point I was completely frazzled. Finding nothing was 10 times worse than if I had seen a bunch of trojans popping up. I didn't know if there was something especially clever still hiding on my system or if it stole my information and self-deleted, or what. In desperation, I resorted to 'old reliable': re-install Windows fresh. I booted from the CD (Windows 7 RC, btw) and deleted the partition on my C: drive, then proceeded through the process of installing Windows 7. After reading through this site, in hindsight I suppose it would have been better to submit my logs to this forum before wiping and reloading Windows, but I was at a loss.

Since re-installing Windows 7, I have done the following:

1. Installed ESET NOD32 Antivirus; updated.

2. Installed Comodo Firewall. This was suggested to me by a friend and seems like a great tool for security. However, I am finding the learning curve rather steep and hope that I am using it properly.

3. Installed Malwarebytes; updated.

4. Quick and Full scans with Malwarebytes. 1 Result was found:
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
I Googled this and found a post on the Malwarebytes forum saying this was a false positive so I clicked 'Ignore'.

5. Full and Smart scans with NOD32. 0 results.


However, I am still uneasy as to the status of my computer's security. I have never been infected, hacked (until now) so I always thought my security precautions were adequate.


Any help, advice, suggestions is greatly appreciated. Many thanks in advance for your help.

LOG:


DDS (Ver_09-10-26.01) - NTFSX64
Run by iamnotagun at 0:33:58.98 on Wed 11/04/2009
Internet Explorer: 8.0.7100.0
Microsoft Windows 7 Ultimate 6.1.7100.0.1252.1.1033.18.4094.1985 [GMT -5:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Windows\SysWOW64\Ctxfihlp.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
C:\Windows\system32\notepad.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Users\iamnotagun\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

mLocal Page = c:\windows\syswow64\blank.htm
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [Skype] "c:\program files (x86)\skype\phone\Skype.exe" /nosplash /minimized
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [AdobeCS4ServiceManager] "c:\program files (x86)\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe Acrobat Speed Launcher] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [<NO NAME>]
mRun: [Acrobat Assistant 8.0] "c:\program files (x86)\adobe\acrobat 9.0\acrobat\Acrotray.exe"
StartupFolder: c:\users\iamnot~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files (x86)\magicdisc\MagicDisc.exe
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\nostro~1.lnk - c:\windows\installer\{548c7b77-8b04-427e-acd0-d0e6e6e59bcf}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab
TCP: {7FAB77C7-D461-4597-83DA-E72D3EC7C1D1} = 156.154.70.22,156.154.71.22
TCP: {F8D3C2F1-AE8D-4671-A585-508961356589} = 156.154.70.22,156.154.71.22
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\syswow64\guard32.dll
mRun-x64: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun-x64: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun-x64: [RivaTunerStartupDaemon] "c:\program files (x86)\rivatuner\RivaTunerWrapper.exe" /S
mRun-x64: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun-x64: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
AppInit_DLLs-X64: c:\windows\system32\guard64.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\iamnot~1\appdata\roaming\mozilla\firefox\profiles\bljkk3zh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files (x86)\vlc\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-11-1 117064]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-11-1 33128]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\x86\ekrn.exe [2009-9-29 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-9-29 123200]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\nvidia corporation\3d vision\nvSCPAPISvr.exe [2009-9-27 240232]
R3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2009-11-3 35328]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 202776]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1417240]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 94744]
R3 RivaTuner64;RivaTuner64;c:\program files (x86)\rivatuner\RivaTuner64.sys [2009-8-22 19952]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt64win7.sys [2009-8-20 239616]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\common files\creative labs shared\service\CTAELicensing.exe [2009-11-1 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 202776]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1417240]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 94744]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\common files\macrovision shared\flexnet publisher\FNPLicensingService64.exe [2009-11-2 1038088]
S3 getPlusHelper;getPlusHelper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-4-21 27648]

=============== Created Last 30 ================

2009-11-04 03:09:07 0 d-----w- c:\users\iamnot~1\appdata\roaming\Subversion
2009-11-03 21:12:21 0 d-----w- c:\program files\TortoiseSVN
2009-11-03 21:12:21 0 d-----w- c:\program files\common files\TortoiseOverlays
2009-11-03 20:44:07 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-11-03 20:42:58 0 d-----r- c:\program files (x86)\Skype
2009-11-03 20:42:44 0 d-----w- c:\programdata\Skype
2009-11-03 12:29:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2009-11-03 08:54:28 0 d-----w- c:\windows\WindowsMobile
2009-11-03 08:35:40 0 d-----w- c:\users\iamnot~1\appdata\roaming\Belkin
2009-11-03 08:34:57 35328 ----a-w- c:\windows\system32\drivers\bcgame.sys
2009-11-03 08:34:56 0 d-----w- c:\program files (x86)\Nostromo
2009-11-03 05:16:20 0 d-----w- c:\programdata\Blizzard Entertainment
2009-11-03 04:19:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2009-11-03 03:46:07 255552 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2009-11-03 03:46:05 0 d-----w- c:\program files (x86)\MagicDisc
2009-11-03 03:19:47 0 d-----w- c:\programdata\FLEXnet
2009-11-03 03:04:49 0 d-----w- c:\programdata\NOS
2009-11-03 02:30:08 0 d-----w- c:\program files (x86)\common files\Blizzard Entertainment
2009-11-03 02:29:16 0 d-----w- c:\programdata\Blizzard
2009-11-03 02:02:49 0 d-----w- c:\users\iamnot~1\appdata\roaming\EditPlus 3
2009-11-03 02:02:49 0 d-----w- c:\program files (x86)\EditPlus 3
2009-11-03 01:02:05 0 d-----w- c:\program files\Adobe
2009-11-03 01:00:11 0 d-----w- c:\programdata\ALM
2009-11-03 00:55:16 24416 ----a-r- c:\windows\system32\AdobePDFUI.dll
2009-11-03 00:29:43 0 d-----w- c:\windows\syswow64\spool
2009-11-03 00:28:59 0 d-----w- c:\programdata\Adobe
2009-11-03 00:27:40 0 d-----w- c:\program files\common files\Macrovision Shared
2009-11-03 00:27:39 0 d-----w- c:\program files\common files\Adobe
2009-11-03 00:25:38 0 d-----w- c:\program files (x86)\common files\Macrovision Shared
2009-11-02 23:26:53 0 d-----w- c:\program files\Zune
2009-11-02 23:26:29 0 d-----w- c:\windows\PCHEALTH
2009-11-02 21:49:41 0 d-----w- c:\program files (x86)\SyncBack
2009-11-02 21:45:18 0 d-----w- c:\program files (x86)\CCleaner
2009-11-02 21:11:53 5954560 ----a-w- c:\windows\syswow64\mshtml.dll
2009-11-02 20:49:03 0 d-----w- c:\program files (x86)\RivaTuner
2009-11-02 20:47:08 0 d-----w- c:\program files\7-Zip
2009-11-02 10:08:30 1080 ----a-w- c:\windows\system32\settingsbkup.sfm
2009-11-02 10:08:30 1080 ----a-w- c:\windows\system32\settings.sfm
2009-11-02 10:07:48 407040 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-11-02 10:07:44 231936 ----a-w- c:\windows\system32\ListSvc.dll
2009-11-02 10:07:35 358400 ----a-w- c:\windows\system32\wmpdxm.dll
2009-11-02 10:07:35 299520 ----a-w- c:\windows\syswow64\wmpdxm.dll
2009-11-02 10:07:19 10974208 ----a-w- c:\windows\syswow64\ieframe.dll
2009-11-02 10:04:11 716800 ----a-w- c:\windows\syswow64\jscript.dll
2009-11-02 10:04:04 2053120 ----a-w- c:\windows\syswow64\iertutil.dll
2009-11-02 09:59:23 0 d-----w- c:\programdata\ESET
2009-11-02 09:59:23 0 d-----w- c:\program files\ESET
2009-11-02 08:17:55 0 d-----w- c:\windows\Panther
2009-11-02 06:20:53 0 d-----w- c:\windows\syswow64\Macromed
2009-11-02 06:14:12 0 d-----w- c:\users\iamnot~1\appdata\roaming\Malwarebytes
2009-11-02 06:13:41 22104 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-02 06:13:41 0 d-----w- c:\programdata\Malwarebytes
2009-11-02 06:13:41 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2009-11-02 04:00:53 0 d-----w- c:\program files (x86)\VLC
2009-11-02 03:44:20 788 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
2009-11-02 03:44:20 61448 ----a-w- c:\windows\system32\BMXStateBkp-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
2009-11-02 03:44:20 61448 ----a-w- c:\windows\system32\BMXState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
2009-11-02 03:43:50 7062 ----a-w- c:\windows\syswow64\audiopid.vxd
2009-11-02 03:43:21 0 d-----w- c:\program files (x86)\common files\Creative
2009-11-02 03:43:20 0 d--h--w- c:\program files (x86)\Creative Installation Information
2009-11-02 03:43:08 0 d-----w- c:\program files (x86)\common files\Creative Labs Shared
2009-11-02 03:43:01 0 d-----w- c:\program files\Creative
2009-11-02 03:42:57 0 d-----w- c:\program files (x86)\Creative
2009-11-02 03:42:03 0 d-----w- c:\programdata\Creative
2009-11-02 03:42:00 107008 ----a-w- c:\windows\system32\cttele64.dll
2009-11-02 03:42:00 102400 ----a-w- c:\windows\syswow64\cttele32.dll
2009-11-02 03:40:21 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2009-11-02 03:40:21 444952 ----a-w- c:\windows\syswow64\wrap_oal.dll
2009-11-02 03:40:21 121880 ----a-w- c:\windows\system32\OpenAL32.dll
2009-11-02 03:40:21 0 d-----w- c:\program files (x86)\OpenAL
2009-11-02 03:40:19 89088 ----a-w- c:\windows\system32\CmdRtr64.DLL
2009-11-02 03:40:19 73728 ----a-w- c:\windows\syswow64\CmdRtr.DLL
2009-11-02 03:40:19 190976 ----a-w- c:\windows\system32\APOMgr64.DLL
2009-11-02 03:40:19 148480 ----a-w- c:\windows\syswow64\APOMngr.DLL
2009-11-02 03:40:19 109080 ----a-w- c:\windows\syswow64\OpenAL32.dll
2009-11-02 03:40:16 159 ---ha-r- c:\windows\ctfile.rfc
2009-11-02 03:38:47 12288 ----a-w- c:\windows\system32\INRES.DLL
2009-11-02 03:38:47 11776 ----a-w- c:\windows\syswow64\INRES.DLL
2009-11-02 03:38:47 0 d-----w- c:\windows\syswow64\Data
2009-11-02 03:38:47 0 d-----w- c:\windows\system32\Data
2009-11-02 03:38:11 22691984 ----a-w- c:\windows\syswow64\AppSetup.exe
2009-11-02 03:36:32 0 d-----w- c:\program files (x86)\NVIDIA Corporation
2009-11-02 03:36:06 0 d-----w- c:\programdata\NVIDIA
2009-11-02 03:35:45 0 d-----w- c:\windows\syswow64\AGEIA
2009-11-02 03:35:29 0 d-sh--w- c:\windows\Installer
2009-11-02 03:35:27 0 d-----w- c:\program files (x86)\common files\Wise Installation Wizard
2009-11-02 03:35:05 541800 ----a-w- c:\windows\system32\nvuninst.exe
2009-11-02 03:33:30 0 d-----w- C:\NVIDIA
2009-11-02 03:03:12 33128 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-02 03:03:12 241688 ----a-w- c:\windows\system32\guard64.dll
2009-11-02 03:03:12 179792 ----a-w- c:\windows\syswow64\guard32.dll
2009-11-02 03:03:12 117064 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-02 03:03:12 0 d-----w- c:\programdata\Comodo
2009-11-02 03:02:52 0 d-----w- c:\program files\COMODO
2009-11-02 02:42:31 238960 ------w- c:\windows\system32\MpSigStub.exe

==================== Find3M ====================

2009-09-29 18:06:16 123200 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2009-09-29 18:03:00 136584 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-09-29 17:56:36 144824 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-09-27 23:24:22 3778664 ----a-w- c:\windows\system32\nvcplui.exe
2009-09-27 23:23:00 4546152 ----a-w- c:\windows\system32\nvvitvs.dll
2009-09-27 23:23:00 3746920 ----a-w- c:\windows\system32\nvwss.dll
2009-09-27 23:23:00 289896 ----a-w- c:\windows\system32\nvmccss.dll
2009-09-27 23:23:00 1647720 ----a-w- c:\windows\system32\nvmobls.dll
2009-09-27 23:23:00 1646696 ----a-w- c:\windows\system32\nvsvs.dll
2009-09-27 23:22:00 991848 ----a-w- c:\windows\system32\nvsvc64.dll
2009-09-27 23:22:00 82536 ----a-w- c:\windows\system32\nvmctray.dll
2009-09-27 23:22:00 5426792 ----a-w- c:\windows\system32\nvdisps.dll
2009-09-27 23:22:00 5208168 ----a-w- c:\windows\system32\nvgames.dll
2009-09-27 23:22:00 383592 ----a-w- c:\windows\system32\nvvsvc.exe
2009-09-27 23:22:00 244840 ----a-w- c:\windows\system32\nvshext.dll
2009-09-27 23:22:00 16666728 ----a-w- c:\windows\system32\nvcpl.dll
2009-09-04 18:18:40 470256 ----a-w- c:\windows\system32\ZuneWlanCfgSvc.exe
2009-08-14 18:36:18 70936 ----a-w- c:\windows\syswow64\PhysXLoader.dll
2009-04-22 09:52:01 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-04-22 09:52:01 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-04-22 09:52:01 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-04-22 09:52:01 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-04-22 09:08:55 174 --sha-w- c:\program files\desktop.ini
2009-04-22 09:08:55 174 --sha-w- c:\program files (x86)\desktop.ini
2009-04-22 05:05:25 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-04-22 05:05:25 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-04-22 05:05:24 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-04-22 05:05:24 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-03-27 04:24:11 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-04-22 09:27:16 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-04-22 09:09:34 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-04-22 09:09:34 32768 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-04-22 09:09:34 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\index.dat
2009-04-22 05:38:46 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7100.0_none_be69c16d5d28757a\WinMail.exe
2009-04-22 05:19:40 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7100.0_none_624b25e9a4cb0444\WinMail.exe

============= FINISH: 0:35:24.70 ===============



Wind32kDiag.exe Log (as requested)

Running from: C:\Users\iamnotagun\Desktop\Win32kDiag.exe

Log file at : C:\Users\iamnotagun\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'...



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl

[1] 2009-11-06 01:30:19 72 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl

[1] 2009-11-06 01:30:13 72 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl

[1] 2009-11-06 01:30:13 72 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl

[1] 2009-11-06 01:30:13 72 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl

[1] 2009-11-06 01:32:35 0 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl ()



Cannot access: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl

[1] 2009-11-06 01:30:23 72 C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl ()





Finished!

BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,784 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:06:57 PM

Posted 11 November 2009 - 09:38 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
  • Please download OTL from following mirror:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized
In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. I suggest you do this and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 avanduser

avanduser
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:57 AM

Posted 11 November 2009 - 04:04 PM

Thank you for the response.

I'm afraid I have made changes to the computer since I first posted. I've installed several programs (Spybot, SUPERAntiSpyware, Threatfire). I hope that will not interfere with the process. I will not add/remove anything else until we finish here. Thank you for the help.

LOGS:

[OTL.txt]

OTL logfile created on: 11/11/2009 3:55:02 PM - Run 1
OTL by OldTimer - Version 3.1.5.0 Folder = C:\Users\iamnotagun\Desktop
64bit- Ultimate Edition (Version = 6.1.7100) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7100.0)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 39.67% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 94.27 Gb Free Space | 67.46% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 285.14 Gb Free Space | 95.65% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 185.97 Gb Free Space | 62.39% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 118.33 Gb Free Space | 39.70% Space Free | Partition Type: NTFS
Drive G: | 3.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DRAGON
Current User Name: iamnotagun
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/11/11 15:54:09 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\iamnotagun\Desktop\OTL.exe
PRC - [2009/11/06 02:06:00 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/11/02 19:25:38 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2009/11/02 19:25:38 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
PRC - [2009/10/09 13:11:12 | 25,623,336 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
PRC - [2009/10/09 13:11:12 | 25,623,336 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
PRC - [2009/10/09 13:11:12 | 25,623,336 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
PRC - [2009/10/09 13:11:12 | 00,078,008 | R--- | M] (Skype Technologies) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
PRC - [2009/10/09 13:11:12 | 00,078,008 | R--- | M] (Skype Technologies) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
PRC - [2009/10/09 13:11:12 | 00,078,008 | R--- | M] (Skype Technologies) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
PRC - [2009/10/02 23:32:51 | 00,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2009/09/29 13:03:46 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2009/09/29 13:03:46 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2009/09/27 16:48:00 | 00,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/09/23 08:07:38 | 00,382,224 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFTray.exe
PRC - [2009/09/23 08:07:38 | 00,382,224 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFTray.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe
PRC - [2009/08/12 16:11:01 | 08,318,056 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
PRC - [2009/08/03 20:05:02 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/08/03 20:05:02 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/08/03 20:05:02 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/08/03 20:05:02 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/08/03 20:05:02 | 00,238,888 | ---- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeNames.exe
PRC - [2009/06/04 00:55:16 | 00,025,600 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\Ctxfihlp.exe
PRC - [2009/06/04 00:49:56 | 01,213,440 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTxfispi.exe
PRC - [2009/06/04 00:49:56 | 01,213,440 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTxfispi.exe
PRC - [2009/02/23 19:43:12 | 00,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files (x86)\MagicDisc\MagicDisc.exe
PRC - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2007/08/16 12:02:06 | 00,562,416 | ---- | M] (Belkin Corporation) -- C:\Program Files (x86)\Nostromo\nost_LM.exe
PRC - [2007/05/31 09:20:54 | 00,050,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\WmdHost.exe
PRC - [2007/05/31 09:20:54 | 00,050,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\WmdHost.exe


========== Modules (SafeList) ==========

MOD - [2009/11/11 15:54:09 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\iamnotagun\Desktop\OTL.exe
MOD - [2009/11/01 22:03:11 | 00,179,792 | ---- | M] (COMODO) -- C:\Windows\SysWOW64\guard32.dll
MOD - [2009/09/23 08:07:42 | 00,455,952 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFWAH.dll
MOD - [2009/04/22 00:22:12 | 01,122,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll
MOD - [2009/04/22 00:22:12 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll
MOD - [2009/04/22 00:22:03 | 00,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll
MOD - [2009/04/22 00:22:02 | 00,170,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll
MOD - [2009/04/22 00:20:30 | 00,014,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\fltLib.dll
MOD - [2009/04/22 00:19:53 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll
MOD - [2009/04/22 00:00:58 | 01,679,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7100.0_none_d75e6751736615f2\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/11/02 19:27:40 | 01,038,088 | ---- | M] (Acresso Software Inc.) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009/11/01 22:03:11 | 01,079,048 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV:64bit: - [2009/09/29 13:11:14 | 00,023,296 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2009/09/29 13:03:46 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2009/09/04 13:18:40 | 00,470,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:64bit: - [2009/09/04 13:18:36 | 07,636,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV:64bit: - [2009/07/08 16:41:38 | 00,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
SRV:64bit: - [2009/04/22 00:41:48 | 00,228,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
SRV:64bit: - [2009/04/22 00:41:31 | 00,201,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
SRV:64bit: - [2009/04/22 00:41:29 | 00,195,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService)
SRV:64bit: - [2009/04/22 00:41:29 | 00,164,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\umpo.dll -- (Power)
SRV:64bit: - [2009/04/22 00:41:26 | 00,044,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2009/04/22 00:41:20 | 00,065,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
SRV:64bit: - [2009/04/22 00:41:01 | 00,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
SRV:64bit: - [2009/04/22 00:40:58 | 00,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
SRV:64bit: - [2009/04/22 00:40:56 | 00,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
SRV:64bit: - [2009/04/22 00:40:54 | 00,327,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
SRV:64bit: - [2009/04/22 00:40:54 | 00,327,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
SRV:64bit: - [2009/04/22 00:40:54 | 00,025,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
SRV:64bit: - [2009/04/22 00:40:52 | 01,361,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\PeerDistSvc.dll -- (PeerDistSvc)
SRV:64bit: - [2009/04/22 00:40:14 | 01,011,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/04/22 00:39:46 | 01,126,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
SRV:64bit: - [2009/04/22 00:39:30 | 00,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2009/04/22 00:39:29 | 00,291,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
SRV:64bit: - [2009/04/22 00:39:25 | 00,689,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cscsvc.dll -- (CscService)
SRV:64bit: - [2009/04/22 00:39:08 | 00,083,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
SRV:64bit: - [2009/04/22 00:39:06 | 00,100,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
SRV:64bit: - [2009/04/22 00:39:03 | 00,114,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
SRV:64bit: - [2009/04/22 00:38:59 | 00,193,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/04/22 00:38:59 | 00,032,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
SRV:64bit: - [2009/04/22 00:38:49 | 01,529,856 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV:64bit: - [2009/04/22 00:38:44 | 01,503,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:64bit: - [2009/04/22 00:38:39 | 00,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\svchost.exe -- (getPlusHelper)
SRV:64bit: - [2009/04/22 00:38:24 | 03,524,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
SRV:64bit: - [2009/04/22 00:38:06 | 00,689,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
SRV - [2009/11/02 19:25:38 | 00,655,624 | ---- | M] (Acresso Software Inc.) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/11/01 22:43:08 | 00,079,360 | ---- | M] (Creative Labs) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2009/09/27 16:48:00 | 00,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/09/23 08:07:34 | 00,070,928 | ---- | M] (PC Tools) -- C:\Program Files (x86)\ThreatFire\TFService.exe -- (ThreatFire)
SRV - [2009/04/22 02:16:44 | 00,000,000 | ---D | M] -- C:\Windows\Vss -- (VSS)
SRV - [2009/04/22 02:16:43 | 00,000,000 | ---D | M] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2009/04/22 00:38:04 | 00,696,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)
SRV - [2009/04/22 00:38:04 | 00,128,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched)
SRV - [2009/04/22 00:21:43 | 00,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/04/22 00:20:14 | 00,252,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV - [2009/04/21 19:32:06 | 00,061,056 | ---- | M] () -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2009/04/04 15:05:06 | 00,067,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/04/04 15:04:48 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
SRV - [2009/04/04 15:04:26 | 00,090,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2009/04/04 15:04:14 | 00,857,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2009/02/23 11:43:54 | 00,307,200 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2007/05/31 17:11:54 | 00,443,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 17:11:46 | 00,225,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2009/11/06 01:06:20 | 00,086,584 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2009/09/29 13:06:16 | 00,123,200 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2009/09/29 13:03:00 | 00,136,584 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2009/09/29 12:56:36 | 00,144,824 | ---- | M] (ESET) -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:64bit: - [2009/09/23 08:07:50 | 00,059,880 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\TfSysMon.sys -- (TfSysMon)
DRV:64bit: - [2009/09/23 08:07:50 | 00,041,888 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\TfNetMon.sys -- (TfNetMon)
DRV:64bit: - [2009/09/23 08:07:48 | 00,065,072 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\TfFsMon.sys -- (TfFsMon)
DRV:64bit: - [2009/08/20 01:05:06 | 00,239,616 | ---- | M] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/04 02:49:58 | 01,561,112 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)
DRV:64bit: - [2009/06/04 02:49:42 | 00,118,296 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:64bit: - [2009/06/04 02:49:34 | 00,213,016 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:64bit: - [2009/06/04 02:49:26 | 00,015,896 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:64bit: - [2009/06/04 02:49:18 | 00,179,224 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:64bit: - [2009/06/04 02:49:08 | 00,684,312 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k)
DRV:64bit: - [2009/06/04 02:49:00 | 00,580,632 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:64bit: - [2009/06/04 02:48:50 | 01,417,240 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)
DRV:64bit: - [2009/06/04 02:48:50 | 01,417,240 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:64bit: - [2009/06/04 02:48:38 | 00,094,744 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)
DRV:64bit: - [2009/06/04 02:48:38 | 00,094,744 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:64bit: - [2009/06/04 02:48:30 | 00,202,776 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)
DRV:64bit: - [2009/06/04 02:48:30 | 00,202,776 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)
DRV:64bit: - [2009/04/22 00:53:06 | 00,194,128 | ---- | M] (AMD Technologies Inc.) -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/04/22 00:53:04 | 00,105,040 | ---- | M] (AMD) -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/04/22 00:52:53 | 00,028,752 | ---- | M] (AMD) -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/04/22 00:48:23 | 00,153,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ksecpkg.sys -- (KSecPkg)
DRV:64bit: - [2009/04/22 00:48:16 | 00,077,904 | ---- | M] (Hewlett-Packard Company) -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/04/22 00:48:15 | 00,065,616 | ---- | M] (LSI Corporation) -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/04/22 00:48:14 | 00,054,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fsdepends.sys -- (FsDepends)
DRV:64bit: - [2009/04/22 00:48:11 | 00,050,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\pcw.sys -- (pcw)
DRV:64bit: - [2009/04/22 00:48:04 | 00,014,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hwpolicy.sys -- (hwpolicy)
DRV:64bit: - [2009/04/22 00:45:33 | 00,228,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vhdmp.sys -- (vhdmp)
DRV:64bit: - [2009/04/22 00:45:27 | 00,214,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdyboost.sys -- (rdyboost)
DRV:64bit: - [2009/04/22 00:45:27 | 00,203,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vmbus.sys -- (vmbus)
DRV:64bit: - [2009/04/22 00:45:25 | 00,047,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vmstorfl.sys -- (storflt)
DRV:64bit: - [2009/04/22 00:45:20 | 00,036,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storvsc.sys -- (storvsc)
DRV:64bit: - [2009/04/22 00:45:20 | 00,024,640 | ---- | M] (Promise Technology) -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/04/22 00:45:20 | 00,022,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wimmount.sys -- (WIMMount)
DRV:64bit: - [2009/04/22 00:45:19 | 00,036,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vdrvroot.sys -- (vdrvroot)
DRV:64bit: - [2009/04/22 00:45:10 | 00,458,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\cng.sys -- (CNG)
DRV:64bit: - [2009/04/22 00:44:54 | 00,222,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\fvevol.sys -- (fvevol)
DRV:64bit: - [2009/04/21 23:26:27 | 00,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpbus.sys -- (rdpbus)
DRV:64bit: - [2009/04/21 23:25:20 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV:64bit: - [2009/04/21 23:19:00 | 00,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\agilevpn.sys -- (RasAgileVpn)
DRV:64bit: - [2009/04/21 23:18:29 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/04/21 23:18:10 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\wfplwf.sys -- (WfpLwf)
DRV:64bit: - [2009/04/21 23:16:55 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ndiscap.sys -- (NdisCap)
DRV:64bit: - [2009/04/21 23:15:56 | 00,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vwifibus.sys -- (vwifibus)
DRV:64bit: - [2009/04/21 23:15:43 | 00,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\1394ohci.sys -- (1394ohci)
DRV:64bit: - [2009/04/21 23:15:37 | 00,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService)
DRV:64bit: - [2009/04/21 23:15:28 | 00,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\umpass.sys -- (UmPass)
DRV:64bit: - [2009/04/21 23:15:08 | 00,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\winusb.sys -- (WinUSB)
DRV:64bit: - [2009/04/21 23:15:05 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV:64bit: - [2009/04/21 23:14:25 | 00,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WUDFPf.sys -- (WudfPf)
DRV:64bit: - [2009/04/21 23:10:55 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\MTConfig.sys -- (MTConfig)
DRV:64bit: - [2009/04/21 23:09:18 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\CompositeBus.sys -- (CompositeBus)
DRV:64bit: - [2009/04/21 23:08:57 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\beep.sys -- (Beep)
DRV:64bit: - [2009/04/21 22:59:57 | 00,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\appid.sys -- (AppID)
DRV:64bit: - [2009/04/21 22:57:24 | 00,029,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\scfilter.sys -- (scfilter)
DRV:64bit: - [2009/04/21 22:49:33 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\vms3cap.sys -- (s3cap)
DRV:64bit: - [2009/04/21 22:49:14 | 00,021,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\VMBusHID.sys -- (VMBusHID)
DRV:64bit: - [2009/04/21 22:43:33 | 00,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\discache.sys -- (discache)
DRV:64bit: - [2009/04/21 22:34:55 | 00,026,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\hidbatt.sys -- (HidBatt)
DRV:64bit: - [2009/04/21 22:34:53 | 00,017,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\CmBatt.sys -- (CmBatt)
DRV:64bit: - [2009/04/21 22:29:34 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\acpipmi.sys -- (AcpiPmi)
DRV:64bit: - [2009/04/21 22:27:28 | 00,514,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\csc.sys -- (CSC)
DRV:64bit: - [2009/04/21 22:23:12 | 00,060,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\amdppm.sys -- (AmdPPM)
DRV:64bit: - [2009/03/16 23:35:14 | 00,468,480 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/03/06 02:43:48 | 00,270,848 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/02/24 18:35:44 | 00,255,552 | ---- | M] (MagicISO, Inc.) -- C:\Windows\SysNative\drivers\mcdbus.sys -- (mcdbus)
DRV:64bit: - [2009/02/05 22:41:49 | 03,286,016 | ---- | M] (Broadcom Corporation) -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/01/23 23:08:24 | 00,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/08/14 10:36:58 | 00,035,328 | ---- | M] (Belkin Corporation) -- C:\Windows\SysNative\drivers\bcgame.sys -- (bcgame)
DRV - [2009/11/06 01:06:20 | 00,086,584 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\drivers\adfs.sys -- (adfs)
DRV - [2009/11/02 15:49:51 | 00,019,952 | ---- | M] () -- C:\Program Files (x86)\RivaTuner\RivaTuner64.sys -- (RivaTuner64)
DRV - [2009/11/02 03:19:15 | 00,000,000 | ---D | M] -- C:\Windows\CSC -- (CSC)
DRV - [2009/10/12 21:24:56 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/10/12 21:24:54 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/10/12 21:24:52 | 00,074,480 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2009/04/22 00:23:43 | 00,019,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/04/22 00:22:17 | 00,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winusb.dll -- (WinUSB)
DRV - [2009/04/22 00:21:17 | 00,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netbios.dll -- (NetBIOS)
DRV - [2009/03/20 10:27:01 | 00,001,088 | ---- | M] () -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)
DRV - [2009/03/20 10:21:33 | 00,003,066 | ---- | M] () -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
DRV - [2009/02/24 18:35:44 | 00,255,552 | ---- | M] (MagicISO, Inc.) -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-287412798-2220196098-1387617092-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-287412798-2220196098-1387617092-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-287412798-2220196098-1387617092-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKU\S-1-5-21-287412798-2220196098-1387617092-1001\S-1-5-21-287412798-2220196098-1387617092-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.7
FF - prefs.js..extensions.enabledItems: anticontainer@downthemall.net:0.6
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {4BBDD651-70CF-4821-84F8-2B918CF89CA3}:6.3
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.4.5
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.11.2
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.14
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.3.1
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.2
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.5

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/04/22 04:45:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/11/06 02:06:01 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/11/06 17:04:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2009/11/07 16:03:31 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2009/11/02 04:59:24 | 00,000,000 | ---D | M]

[2009/11/01 21:32:10 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Extensions
[2009/11/01 21:32:10 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/11/09 23:13:51 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/01 21:57:07 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/11/04 23:37:17 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2009/11/01 21:45:57 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/01 21:45:57 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/11/01 21:45:56 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/11/01 21:45:56 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\anticontainer@downthemall.net
[2009/11/07 15:44:34 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\firebug@software.joehewitt.com
[2009/11/01 21:45:55 | 00,000,000 | ---D | M] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\extensions\personas@christopher.beard
[2009/10/22 16:03:04 | 00,002,067 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\searchplugins\thottbot.xml
[2009/09/29 11:44:52 | 00,001,554 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\searchplugins\wowhead.xml
[2009/09/29 11:44:40 | 00,001,914 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\searchplugins\wowwiki-en.xml
[2009/08/16 16:07:12 | 00,004,140 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Mozilla\Firefox\Profiles\bljkk3zh.default\searchplugins\youtube.xml
[2009/11/03 15:43:13 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/11/06 02:06:01 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/11/03 15:43:13 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/11/06 02:06:00 | 00,023,512 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browserdirprovider.dll
[2009/11/06 02:06:00 | 00,137,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\brwsrcmp.dll
[2009/11/06 02:06:00 | 00,064,984 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
[2008/06/11 22:45:28 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
[2009/10/16 12:58:44 | 00,001,394 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazondotcom.xml
[2009/10/16 12:58:44 | 00,002,193 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\answers.xml
[2009/10/16 12:58:44 | 00,001,534 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\creativecommons.xml
[2009/10/16 12:58:44 | 00,002,344 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay.xml
[2009/10/16 12:58:44 | 00,002,371 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\google.xml
[2009/10/16 12:58:44 | 00,001,178 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia.xml
[2009/10/16 12:58:44 | 00,000,792 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: (1262 bytes) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RivaTunerStartupDaemon] C:\Program Files (x86)\RivaTuner\RivaTunerWrapper.exe ()
O4:64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [ThreatFire] C:\Program Files (x86)\ThreatFire\TFTray.exe (PC Tools)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-287412798-2220196098-1387617092-1001..\Run: [Skype] C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\SysWow64\mctadmin.exe File not found
O4 - Startup: C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup...15109/CTPID.cab (Creative Software AutoUpdate Support Package)
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/22 09:28:23 | 00,000,122 | R--- | M] () - G:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{51f9d22a-c788-11de-be44-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{51f9d22a-c788-11de-be44-806e6f6e6963}\Shell\AutoRun\command - "" = G:\setup.exe -- [2009/04/22 09:28:23 | 00,106,776 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/11/11 15:53:53 | 00,529,408 | ---- | C] (OldTimer Tools) -- C:\Users\iamnotagun\Desktop\OTL.exe
[2009/11/11 00:59:09 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Deployment
[2009/11/11 00:59:09 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Apps
[2009/11/10 21:40:08 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Ventrilo
[2009/11/10 21:39:10 | 00,000,000 | ---D | C] -- C:\Program Files\Ventrilo
[2009/11/10 01:25:04 | 00,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2009/11/10 01:25:04 | 00,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2009/11/10 01:25:04 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2009/11/10 00:30:19 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2009/11/10 00:30:19 | 00,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2009/11/10 00:30:06 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\SUPERAntiSpyware.com
[2009/11/10 00:30:06 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\SUPERAntiSpyware
[2009/11/07 16:03:41 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Talkback
[2009/11/07 16:03:30 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Thunderbird
[2009/11/07 16:03:30 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Thunderbird
[2009/11/07 16:03:11 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2009/11/06 22:39:16 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2009/11/06 21:59:14 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\PRGrep
[2009/11/06 21:48:31 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Denis_Stankovski
[2009/11/06 21:29:08 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\FileSeek
[2009/11/06 20:40:37 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Blizzard Entertainment
[2009/11/06 17:41:15 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2009/11/06 17:04:49 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2009/11/06 17:04:37 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2009/11/06 17:04:37 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2009/11/06 17:04:23 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2009/11/06 17:03:05 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2009/11/06 17:02:40 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Microsoft Help
[2009/11/06 17:02:38 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2009/11/06 17:02:38 | 00,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2009/11/06 17:02:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2009/11/06 17:02:14 | 00,000,000 | RH-D | C] -- C:\MSOCache
[2009/11/06 16:30:18 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\GetRightToGo
[2009/11/06 00:47:33 | 00,024,416 | R--- | C] (Adobe Systems Inc.) -- C:\Windows\SysNative\AdobePDFUI.dll
[2009/11/06 00:47:29 | 00,052,568 | R--- | C] (Adobe Systems Inc) -- C:\Windows\SysNative\AdobePDF.dll
[2009/11/06 00:34:51 | 00,000,000 | R-SD | C] -- C:\Users\iamnotagun\Documents\My Stationery
[2009/11/06 00:31:49 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2009/11/06 00:31:38 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2009/11/06 00:31:30 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live SkyDrive
[2009/11/06 00:31:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2009/11/06 00:22:23 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2009/11/05 21:40:41 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\FileZilla
[2009/11/05 21:40:18 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2009/11/04 17:50:49 | 00,065,072 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfFsMon.sys
[2009/11/04 17:50:49 | 00,059,880 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfSysMon.sys
[2009/11/04 17:50:49 | 00,041,888 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfNetMon.sys
[2009/11/04 17:50:40 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2009/11/04 17:50:40 | 00,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2009/11/04 17:50:40 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ThreatFire
[2009/11/04 00:28:07 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\TSVNCache
[2009/11/03 22:09:07 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Subversion
[2009/11/03 16:12:21 | 00,000,000 | ---D | C] -- C:\Program Files\TortoiseSVN
[2009/11/03 16:12:21 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\TortoiseOverlays
[2009/11/03 16:05:04 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\Documents\ProcessExplorer
[2009/11/03 16:03:19 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\HijackThis
[2009/11/03 15:44:00 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\skypePM
[2009/11/03 15:43:21 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Skype
[2009/11/03 15:43:00 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2009/11/03 15:42:58 | 00,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2009/11/03 15:42:44 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2009/11/03 15:42:44 | 00,000,000 | ---D | C] -- C:\ProgramData\Skype
[2009/11/03 03:54:28 | 00,000,000 | ---D | C] -- C:\Windows\WindowsMobile
[2009/11/03 03:35:40 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Belkin
[2009/11/03 03:34:57 | 00,035,328 | ---- | C] (Belkin Corporation) -- C:\Windows\SysNative\drivers\bcgame.sys
[2009/11/03 03:34:56 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Nostromo
[2009/11/03 03:33:37 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Downloaded Installations
[2009/11/03 00:16:20 | 00,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2009/11/03 00:16:20 | 00,000,000 | ---D | C] -- C:\ProgramData\Blizzard Entertainment
[2009/11/02 22:46:07 | 00,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysWow64\drivers\mcdbus.sys
[2009/11/02 22:46:07 | 00,255,552 | ---- | C] (MagicISO, Inc.) -- C:\Windows\SysNative\drivers\mcdbus.sys
[2009/11/02 22:46:05 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\MagicDisc
[2009/11/02 22:19:47 | 00,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2009/11/02 22:19:47 | 00,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2009/11/02 22:04:49 | 00,000,000 | ---D | C] -- C:\ProgramData\NOS
[2009/11/02 22:04:49 | 00,000,000 | ---D | C] -- C:\ProgramData\NOS
[2009/11/02 21:54:31 | 00,000,000 | ---D | C] -- C:\Users\Public\Documents\Blizzard Entertainment
[2009/11/02 21:30:08 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Blizzard Entertainment
[2009/11/02 21:29:16 | 00,000,000 | ---D | C] -- C:\ProgramData\Blizzard
[2009/11/02 21:29:16 | 00,000,000 | ---D | C] -- C:\ProgramData\Blizzard
[2009/11/02 21:02:49 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\EditPlus 3
[2009/11/02 21:02:49 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\EditPlus 3
[2009/11/02 20:02:05 | 00,000,000 | ---D | C] -- C:\Program Files\Adobe
[2009/11/02 20:00:11 | 00,000,000 | ---D | C] -- C:\ProgramData\ALM
[2009/11/02 20:00:11 | 00,000,000 | ---D | C] -- C:\ProgramData\ALM
[2009/11/02 19:29:43 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2009/11/02 19:29:39 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Media Player
[2009/11/02 19:28:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2009/11/02 19:28:59 | 00,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2009/11/02 19:28:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2009/11/02 19:27:40 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2009/11/02 19:27:39 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2009/11/02 19:26:55 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2009/11/02 19:25:57 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Adobe
[2009/11/02 19:25:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2009/11/02 19:19:50 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2009/11/02 18:26:53 | 00,000,000 | ---D | C] -- C:\Program Files\Zune
[2009/11/02 18:26:29 | 00,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2009/11/02 16:49:41 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\SyncBack
[2009/11/02 16:45:18 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\CCleaner
[2009/11/02 16:11:53 | 05,954,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtml.dll
[2009/11/02 16:11:52 | 09,275,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtml.dll
[2009/11/02 16:01:14 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\ElevatedDiagnostics
[2009/11/02 15:49:03 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\RivaTuner
[2009/11/02 15:47:08 | 00,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2009/11/02 05:07:48 | 00,407,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\srv2.sys
[2009/11/02 05:07:44 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ListSvc.dll
[2009/11/02 05:07:35 | 00,358,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmpdxm.dll
[2009/11/02 05:07:35 | 00,299,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmpdxm.dll
[2009/11/02 05:07:19 | 10,974,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieframe.dll
[2009/11/02 05:07:18 | 12,343,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieframe.dll
[2009/11/02 05:04:11 | 00,855,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2009/11/02 05:04:11 | 00,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2009/11/02 05:04:04 | 02,434,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iertutil.dll
[2009/11/02 05:04:04 | 02,053,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iertutil.dll
[2009/11/02 04:59:23 | 00,000,000 | ---D | C] -- C:\ProgramData\ESET
[2009/11/02 04:59:23 | 00,000,000 | ---D | C] -- C:\ProgramData\ESET
[2009/11/02 04:59:23 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009/11/02 03:21:23 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2009/11/02 03:19:18 | 00,000,000 | ---D | C] -- C:\Windows\Prefetch
[2009/11/02 03:18:43 | 00,000,000 | -HSD | C] -- C:\System Volume Information
[2009/11/02 03:17:55 | 00,000,000 | ---D | C] -- C:\Windows\Panther
[2009/11/02 01:21:01 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Macromedia
[2009/11/02 01:21:01 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Adobe
[2009/11/02 01:20:53 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\Macromed
[2009/11/02 01:14:12 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Malwarebytes
[2009/11/02 01:13:42 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/11/02 01:13:41 | 00,022,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2009/11/02 01:13:41 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/11/02 01:13:41 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/11/02 01:13:41 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/11/01 23:01:25 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\dvdcss
[2009/11/01 23:01:11 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\vlc
[2009/11/01 23:00:53 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\VLC
[2009/11/01 22:43:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative
[2009/11/01 22:43:20 | 00,000,000 | -H-D | C] -- C:\Program Files (x86)\Creative Installation Information
[2009/11/01 22:43:08 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Creative Labs Shared
[2009/11/01 22:43:01 | 00,000,000 | ---D | C] -- C:\Program Files\Creative
[2009/11/01 22:42:57 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Creative
[2009/11/01 22:42:03 | 00,000,000 | ---D | C] -- C:\ProgramData\Creative
[2009/11/01 22:42:03 | 00,000,000 | ---D | C] -- C:\ProgramData\Creative
[2009/11/01 22:42:00 | 00,107,008 | ---- | C] (Creative Technology Ltd) -- C:\Windows\SysNative\cttele64.dll
[2009/11/01 22:42:00 | 00,102,400 | ---- | C] (Creative Technology Ltd) -- C:\Windows\SysWow64\cttele32.dll
[2009/11/01 22:40:21 | 00,466,456 | ---- | C] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2009/11/01 22:40:21 | 00,444,952 | ---- | C] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2009/11/01 22:40:21 | 00,121,880 | ---- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2009/11/01 22:40:21 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\OpenAL
[2009/11/01 22:40:19 | 00,109,080 | ---- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2009/11/01 22:38:47 | 00,012,288 | ---- | C] (Creative Technology Limited) -- C:\Windows\SysNative\INRES.DLL
[2009/11/01 22:38:47 | 00,011,776 | ---- | C] (Creative Technology Limited) -- C:\Windows\SysWow64\INRES.DLL
[2009/11/01 22:38:47 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\Data
[2009/11/01 22:38:47 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\Data
[2009/11/01 22:38:11 | 22,691,984 | ---- | C] (Creative Technology Ltd) -- C:\Windows\SysWow64\AppSetup.exe
[2009/11/01 22:38:10 | 00,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
[2009/11/01 22:38:03 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2009/11/01 22:36:32 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2009/11/01 22:36:06 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2009/11/01 22:36:06 | 00,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2009/11/01 22:35:45 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\AGEIA
[2009/11/01 22:35:45 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
[2009/11/01 22:35:29 | 00,000,000 | -HSD | C] -- C:\Windows\Installer
[2009/11/01 22:35:27 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2009/11/01 22:35:05 | 00,541,800 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvuninst.exe
[2009/11/01 22:33:30 | 00,000,000 | ---D | C] -- C:\NVIDIA
[2009/11/01 22:03:12 | 00,241,688 | ---- | C] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2009/11/01 22:03:12 | 00,179,792 | ---- | C] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2009/11/01 22:03:12 | 00,117,064 | ---- | C] (COMODO) -- C:\Windows\SysNative\drivers\cmdguard.sys
[2009/11/01 22:03:12 | 00,084,104 | ---- | C] (COMODO) -- C:\Windows\SysNative\drivers\inspect.sys
[2009/11/01 22:03:12 | 00,033,128 | ---- | C] (COMODO) -- C:\Windows\SysNative\drivers\cmdhlp.sys
[2009/11/01 22:03:12 | 00,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2009/11/01 22:03:12 | 00,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2009/11/01 22:02:52 | 00,000,000 | ---D | C] -- C:\Program Files\COMODO
[2009/11/01 21:42:31 | 00,226,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe
[2009/11/01 21:32:06 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Mozilla
[2009/11/01 21:32:06 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Mozilla
[2009/11/01 21:32:01 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2009/11/01 21:27:30 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Searches
[2009/11/01 21:27:23 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Identities
[2009/11/01 21:27:21 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Contacts
[2009/11/01 21:27:19 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\VirtualStore
[2009/11/01 21:27:16 | 00,000,000 | --SD | C] -- C:\Users\iamnotagun\AppData\Roaming\Microsoft
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Videos
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Saved Games
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Pictures
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Music
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Links
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Favorites
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Downloads
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Documents
[2009/11/01 21:27:16 | 00,000,000 | R--D | C] -- C:\Users\iamnotagun\Desktop
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Templates
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Start Menu
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\SendTo
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Recent
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\PrintHood
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\NetHood
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Documents\My Videos
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Documents\My Pictures
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Documents\My Music
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\My Documents
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Local Settings
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Cookies
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\Application Data
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\AppData\Local\Temporary Internet Files
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\AppData\Local\History
[2009/11/01 21:27:16 | 00,000,000 | -HSD | C] -- C:\Users\iamnotagun\AppData\Local\Application Data
[2009/11/01 21:27:16 | 00,000,000 | -H-D | C] -- C:\Users\iamnotagun\AppData
[2009/11/01 21:27:16 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Roaming\Media Center Programs
[2009/11/01 21:27:16 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Temp
[2009/11/01 21:27:16 | 00,000,000 | ---D | C] -- C:\Users\iamnotagun\AppData\Local\Microsoft
[2009/11/01 21:27:05 | 00,000,000 | -HSD | C] -- C:\Recovery
[2009/06/04 00:57:38 | 00,060,928 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll

========== Files - Modified Within 30 Days ==========

[2009/11/11 15:57:20 | 01,310,720 | -HS- | M] () -- C:\Users\iamnotagun\NTUSER.DAT
[2009/11/11 15:54:09 | 00,529,408 | ---- | M] (OldTimer Tools) -- C:\Users\iamnotagun\Desktop\OTL.exe
[2009/11/11 15:26:50 | 00,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2009/11/11 15:26:50 | 00,615,122 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2009/11/11 15:26:50 | 00,103,496 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2009/11/11 08:00:30 | 00,000,396 | ---- | M] () -- C:\Windows\tasks\SyncBack Work.job
[2009/11/11 07:30:07 | 00,000,402 | ---- | M] () -- C:\Windows\tasks\SyncBack Written.job
[2009/11/11 07:10:02 | 00,000,408 | ---- | M] () -- C:\Windows\tasks\SyncBack Orig_Music.job
[2009/11/11 07:00:01 | 00,000,398 | ---- | M] () -- C:\Windows\tasks\SyncBack Fonts.job
[2009/11/11 06:55:09 | 00,000,402 | ---- | M] () -- C:\Windows\tasks\SyncBack Brushes.job
[2009/11/11 01:24:55 | 00,000,312 | ---- | M] () -- C:\Users\iamnotagun\Desktop\Curse Client.appref-ms
[2009/11/11 01:01:59 | 00,000,000 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2009/11/10 21:39:11 | 00,000,913 | ---- | M] () -- C:\Users\iamnotagun\Desktop\Ventrilo.lnk
[2009/11/10 21:39:11 | 00,000,262 | ---- | M] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2009/11/10 15:43:34 | 00,006,033 | ---- | M] () -- C:\Users\iamnotagun\Documents\contacts.csv
[2009/11/10 02:04:12 | 00,001,885 | ---- | M] () -- C:\Users\iamnotagun\Desktop\CCleaner.lnk
[2009/11/10 01:25:13 | 00,001,258 | ---- | M] () -- C:\Users\iamnotagun\Desktop\Spybot - Search & Destroy.lnk
[2009/11/10 00:34:00 | 00,001,255 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2009/11/10 00:30:08 | 00,001,033 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/11/07 16:03:32 | 00,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2009/11/07 16:03:21 | 00,002,005 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2009/11/07 15:00:42 | 00,086,936 | ---- | M] () -- C:\Users\iamnotagun\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/11/07 03:25:35 | 00,013,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2009/11/07 03:25:35 | 00,013,216 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2009/11/07 03:18:25 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/11/07 03:18:19 | 02,952,072 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2009/11/07 03:18:13 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/11/07 03:18:03 | 32,200,37632 | -HS- | M] () -- C:\hiberfil.sys
[2009/11/07 03:17:28 | 00,061,448 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/07 03:17:28 | 00,061,448 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/07 03:17:28 | 00,000,788 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/07 03:17:16 | 02,771,604 | -H-- | M] () -- C:\Users\iamnotagun\AppData\Local\IconCache.db
[2009/11/07 03:00:37 | 00,000,478 | ---- | M] () -- C:\Windows\win.ini
[2009/11/06 01:38:01 | 00,001,262 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.bak
[2009/11/06 01:38:01 | 00,001,262 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2009/11/06 01:06:20 | 00,086,584 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWow64\drivers\adfs.sys
[2009/11/06 01:06:20 | 00,086,584 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysNative\drivers\adfs.sys
[2009/11/06 00:48:56 | 00,001,080 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2009/11/06 00:48:56 | 00,001,080 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2009/11/05 21:40:29 | 00,002,000 | ---- | M] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2009/11/05 15:06:05 | 00,004,608 | ---- | M] () -- C:\Users\iamnotagun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/05 04:34:22 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2009/11/05 04:34:22 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2009/11/04 20:40:38 | 00,001,027 | ---- | M] () -- C:\Users\iamnotagun\Desktop\Malwarebytes Anti-Malware.lnk
[2009/11/04 17:50:51 | 00,000,934 | ---- | M] () -- C:\Users\Public\Desktop\ThreatFire.lnk
[2009/11/03 16:11:16 | 00,001,416 | ---- | M] () -- C:\Users\iamnotagun\Desktop\Process Explorer.lnk
[2009/11/03 16:03:29 | 00,001,917 | ---- | M] () -- C:\Users\iamnotagun\Desktop\HijackThis.lnk
[2009/11/03 15:44:07 | 00,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2009/11/03 15:44:07 | 00,000,056 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2009/11/03 15:43:00 | 00,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/11/03 07:29:35 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2009/11/03 03:34:56 | 00,002,663 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk
[2009/11/02 23:19:19 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2009/11/02 22:48:07 | 00,000,989 | ---- | M] () -- C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2009/11/02 20:42:06 | 00,226,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MpSigStub.exe
[2009/11/02 18:26:54 | 00,000,927 | ---- | M] () -- C:\Users\Public\Desktop\Zune.lnk
[2009/11/02 00:22:43 | 00,028,965 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2009/11/02 00:22:43 | 00,028,965 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2009/11/01 22:40:21 | 00,466,456 | ---- | M] (Creative Labs) -- C:\Windows\SysNative\wrap_oal.dll
[2009/11/01 22:40:21 | 00,444,952 | ---- | M] (Creative Labs) -- C:\Windows\SysWow64\wrap_oal.dll
[2009/11/01 22:40:21 | 00,121,880 | ---- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysNative\OpenAL32.dll
[2009/11/01 22:40:19 | 00,109,080 | ---- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) -- C:\Windows\SysWow64\OpenAL32.dll
[2009/11/01 22:40:19 | 00,000,159 | RH-- | M] () -- C:\Windows\ctfile.rfc
[2009/11/01 22:03:11 | 00,241,688 | ---- | M] (COMODO) -- C:\Windows\SysNative\guard64.dll
[2009/11/01 22:03:11 | 00,179,792 | ---- | M] (COMODO) -- C:\Windows\SysWow64\guard32.dll
[2009/11/01 22:03:11 | 00,117,064 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmdguard.sys
[2009/11/01 22:03:11 | 00,084,104 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\inspect.sys
[2009/11/01 22:03:11 | 00,033,128 | ---- | M] (COMODO) -- C:\Windows\SysNative\drivers\cmdhlp.sys
[2009/11/01 21:51:22 | 00,524,288 | -HS- | M] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2009/11/01 21:51:22 | 00,524,288 | -HS- | M] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2009/11/01 21:51:22 | 00,065,536 | -HS- | M] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TM.blf
[2009/11/01 21:27:16 | 00,000,020 | -HS- | M] () -- C:\Users\iamnotagun\ntuser.ini

========== Files Created - No Company Name ==========

[2009/11/11 01:24:55 | 00,000,312 | ---- | C] () -- C:\Users\iamnotagun\Desktop\Curse Client.appref-ms
[2009/11/11 01:01:59 | 00,000,000 | ---- | C] () -- C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
[2009/11/10 21:39:11 | 00,000,913 | ---- | C] () -- C:\Users\iamnotagun\Desktop\Ventrilo.lnk
[2009/11/10 21:39:09 | 00,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2009/11/10 15:43:34 | 00,006,033 | ---- | C] () -- C:\Users\iamnotagun\Documents\contacts.csv
[2009/11/10 02:04:12 | 00,001,885 | ---- | C] () -- C:\Users\iamnotagun\Desktop\CCleaner.lnk
[2009/11/10 01:25:13 | 00,001,258 | ---- | C] () -- C:\Users\iamnotagun\Desktop\Spybot - Search & Destroy.lnk
[2009/11/10 00:30:08 | 00,001,033 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/11/07 16:03:32 | 00,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2009/11/07 16:03:21 | 00,002,005 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2009/11/05 21:40:29 | 00,002,000 | ---- | C] () -- C:\Users\Public\Desktop\FileZilla Client.lnk
[2009/11/05 15:05:17 | 00,004,608 | ---- | C] () -- C:\Users\iamnotagun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/05 04:34:22 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
[2009/11/05 04:34:22 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUSB_01009.Wdf
[2009/11/04 20:40:38 | 00,001,027 | ---- | C] () -- C:\Users\iamnotagun\Desktop\Malwarebytes Anti-Malware.lnk
[2009/11/04 17:50:51 | 00,000,934 | ---- | C] () -- C:\Users\Public\Desktop\ThreatFire.lnk
[2009/11/03 16:11:16 | 00,001,416 | ---- | C] () -- C:\Users\iamnotagun\Desktop\Process Explorer.lnk
[2009/11/03 16:03:29 | 00,001,917 | ---- | C] () -- C:\Users\iamnotagun\Desktop\HijackThis.lnk
[2009/11/03 15:44:07 | 00,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/11/03 15:43:00 | 00,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2009/11/03 07:29:35 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
[2009/11/03 03:34:56 | 00,002,663 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk
[2009/11/02 23:19:19 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2009/11/02 22:48:07 | 00,000,989 | ---- | C] () -- C:\Users\iamnotagun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
[2009/11/02 21:30:08 | 00,001,255 | ---- | C] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2009/11/02 18:26:54 | 00,000,927 | ---- | C] () -- C:\Users\Public\Desktop\Zune.lnk
[2009/11/02 16:54:01 | 00,000,402 | ---- | C] () -- C:\Windows\tasks\SyncBack Written.job
[2009/11/02 16:53:33 | 00,000,396 | ---- | C] () -- C:\Windows\tasks\SyncBack Work.job
[2009/11/02 16:52:59 | 00,000,408 | ---- | C] () -- C:\Windows\tasks\SyncBack Orig_Music.job
[2009/11/02 16:51:42 | 00,000,398 | ---- | C] () -- C:\Windows\tasks\SyncBack Fonts.job
[2009/11/02 16:50:55 | 00,000,402 | ---- | C] () -- C:\Windows\tasks\SyncBack Brushes.job
[2009/11/02 05:08:30 | 00,001,080 | ---- | C] () -- C:\Windows\SysNative\settingsbkup.sfm
[2009/11/02 05:08:30 | 00,001,080 | ---- | C] () -- C:\Windows\SysNative\settings.sfm
[2009/11/02 03:18:43 | 32,200,37632 | -HS- | C] () -- C:\hiberfil.sys
[2009/11/01 22:49:37 | 00,086,936 | ---- | C] () -- C:\Users\iamnotagun\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/11/01 22:44:20 | 00,061,448 | ---- | C] () -- C:\Windows\SysNative\BMXStateBkp-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/01 22:44:20 | 00,061,448 | ---- | C] () -- C:\Windows\SysNative\BMXState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/01 22:44:20 | 00,000,788 | ---- | C] () -- C:\Windows\SysNative\DVCState-{00000004-00000000-00000004-00001102-00000005-00311102}.rfx
[2009/11/01 22:43:50 | 00,007,062 | ---- | C] () -- C:\Windows\SysWow64\audiopid.vxd
[2009/11/01 22:40:19 | 00,190,976 | ---- | C] () -- C:\Windows\SysNative\APOMgr64.DLL
[2009/11/01 22:40:19 | 00,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2009/11/01 22:40:19 | 00,089,088 | ---- | C] () -- C:\Windows\SysNative\CmdRtr64.DLL
[2009/11/01 22:40:19 | 00,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2009/11/01 22:40:16 | 00,000,159 | RH-- | C] () -- C:\Windows\ctfile.rfc
[2009/11/01 21:51:20 | 02,771,604 | -H-- | C] () -- C:\Users\iamnotagun\AppData\Local\IconCache.db
[2009/11/01 21:27:16 | 01,310,720 | -HS- | C] () -- C:\Users\iamnotagun\NTUSER.DAT
[2009/11/01 21:27:16 | 00,524,288 | -HS- | C] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
[2009/11/01 21:27:16 | 00,524,288 | -HS- | C] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
[2009/11/01 21:27:16 | 00,065,536 | -HS- | C] () -- C:\Users\iamnotagun\NTUSER.DAT{87b498e0-2d68-11de-80f1-001e0bcde3ec}.TM.blf
[2009/11/01 21:27:16 | 00,000,020 | -HS- | C] () -- C:\Users\iamnotagun\ntuser.ini
[2009/08/03 00:21:54 | 00,197,912 | ---- | C] () -- C:\Windows\SysWow64\physxcudart_20.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 00,058,648 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2009/06/04 01:37:08 | 00,021,093 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2009/06/04 01:37:06 | 00,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2009/06/04 00:55:20 | 00,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL
[2009/05/27 09:49:00 | 00,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2009/04/22 04:45:18 | 00,037,665 | ---- | C] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
[2009/04/22 04:45:18 | 00,029,779 | ---- | C] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/04/22 04:45:18 | 00,026,489 | ---- | C] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/04/22 04:45:18 | 00,026,040 | ---- | C] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/04/22 04:08:55 | 00,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini
[2009/04/22 01:37:02 | 00,000,478 | ---- | C] () -- C:\Windows\win.ini
[2009/04/22 01:37:02 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
[2009/04/21 22:40:32 | 00,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/04/21 20:04:20 | 00,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007/08/12 12:24:02 | 00,081,920 | ---- | C] () -- C:\Windows\SysWow64\TkTool.dll
[2005/09/24 01:53:20 | 00,135,168 | ---- | C] () -- C:\Windows\SysWow64\detfile.dll
[2005/08/31 10:43:10 | 00,522,752 | ---- | C] () -- C:\Windows\SysWow64\p2xdll.dll
< End of report >


[Extras.txt]

OTL Extras logfile created on: 11/11/2009 3:55:02 PM - Run 1
OTL by OldTimer - Version 3.1.5.0 Folder = C:\Users\iamnotagun\Desktop
64bit- Ultimate Edition (Version = 6.1.7100) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7100.0)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.59 Gb Available Physical Memory | 39.67% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 139.73 Gb Total Space | 94.27 Gb Free Space | 67.46% Space Free | Partition Type: NTFS
Drive D: | 298.09 Gb Total Space | 285.14 Gb Free Space | 95.65% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 185.97 Gb Free Space | 62.39% Space Free | Partition Type: NTFS
Drive F: | 298.09 Gb Total Space | 118.33 Gb Free Space | 39.70% Space Free | Partition Type: NTFS
Drive G: | 3.05 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DRAGON
Current User Name: iamnotagun
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-287412798-2220196098-1387617092-1001\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %* File not found
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = E7 3D 5E 41 2C C3 C9 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{4183655A-5FC6-4A23-A804-7764145EC57C}" = ESET NOD32 Antivirus
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{AC2512D4-ED8A-4015-BF87-92478483C171}" = TortoiseSVN 1.6.6.17493 (64 bit)
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"COMODO Internet Security" = COMODO Internet Security
"NVIDIA Drivers" = NVIDIA Drivers
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3A6829EF-0791-4FDD-9382-C690DD0821B9}" = Adobe Flash Player 10 ActiveX
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}" = Nostromo
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_PROR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_920" = Adobe Acrobat 9.2.0 - CPSID_50026
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"AudioCS" = Creative Audio Control Panel
"CCleaner" = CCleaner
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"EditPlus 3" = EditPlus 3
"FileZilla Client" = FileZilla Client 3.2.8.1
"HijackThis" = HijackThis 2.0.2
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PROR" = Microsoft Office Professional 2007 Trial
"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
"SyncBack_is1" = SyncBack
"VLC media player" = VLC media player 1.0.3
"WinLiveSuite_Wave3" = Windows Live Essentials
"World of Warcraft" = World of Warcraft

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-287412798-2220196098-1387617092-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"090215de958f1060" = Curse Client

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/8/2009 4:17:37 PM | Computer Name = Dragon | Source = Application Error | ID = 1000
Description = Faulting application name: Skype.exe, version: 4.1.0.179, time stamp:
0x4acf0be1 Faulting module name: RPCRT4.dll, version: 6.1.7100.0, time stamp: 0x49eea707
Exception
code: 0xc0020043 Fault offset: 0x0005cd59 Faulting process id: 0xa20 Faulting application
start time: 0x01ca5f89129a522b Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
Faulting
module path: C:\Windows\syswow64\RPCRT4.dll Report Id: c18ca8de-cca3-11de-9070-00508db613d8

Error - 11/8/2009 4:34:27 PM | Computer Name = Dragon | Source = RapiMgr | ID = 8
Description = Windows Mobile-based device failed to connect due to communication
(0x80072745) failure (see data for failure code).

Error - 11/8/2009 5:12:32 PM | Computer Name = Dragon | Source = RapiMgr | ID = 8
Description = Windows Mobile-based device failed to connect due to communication
(0x80072745) failure (see data for failure code).

Error - 11/10/2009 7:06:51 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 11/10/2009 7:07:17 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 11/10/2009 7:07:19 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7100.0_none_8fb1307a5ee9ecec.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7100.0_none_d75e6751736615f2.manifest.

Error - 11/10/2009 7:07:34 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Spybot
- Search & Destroy\DelZip179.dll".Error in manifest or policy file "C:\Program
Files (x86)\Spybot - Search & Destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 11/11/2009 7:19:04 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 11/11/2009 7:19:39 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 11/11/2009 7:19:42 AM | Computer Name = Dragon | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7100.0_none_8fb1307a5ee9ecec.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7100.0_none_d75e6751736615f2.manifest.

[ System Events ]
Error - 11/6/2009 5:08:01 PM | Computer Name = Dragon | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 11/6/2009 5:10:05 PM | Computer Name = Dragon | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 11/7/2009 4:17:20 AM | Computer Name = Dragon | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 11/7/2009 4:25:06 PM | Computer Name = Dragon | Source = Schannel | ID = 36888
Description = The following fatal alert was generated: 10. The internal error state
is 10.

Error - 11/10/2009 1:30:14 AM | Computer Name = Dragon | Source = Application Popup | ID = 1060
Description = \??\C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.sys has been
blocked from loading due to incompatibility with this system. Please contact your
software vendor for a compatible version of the driver.

Error - 11/10/2009 1:30:14 AM | Computer Name = Dragon | Source = Service Control Manager | ID = 7000
Description = The SASKUTIL service failed to start due to the following error: %%1275

Error - 11/10/2009 1:30:14 AM | Computer Name = Dragon | Source = Application Popup | ID = 1060
Description = \??\C:\Program Files (x86)\SUPERAntiSpyware\SASDIFSV.SYS has been
blocked from loading due to incompatibility with this system. Please contact your
software vendor for a compatible version of the driver.

Error - 11/10/2009 1:30:14 AM | Computer Name = Dragon | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%1275

Error - 11/10/2009 1:30:22 AM | Computer Name = Dragon | Source = Application Popup | ID = 1060
Description = \??\C:\Program Files (x86)\SUPERAntiSpyware\SASENUM.SYS has been blocked
from loading due to incompatibility with this system. Please contact your software
vendor for a compatible version of the driver.

Error - 11/10/2009 1:30:22 AM | Computer Name = Dragon | Source = Service Control Manager | ID = 7000
Description = The SASENUM service failed to start due to the following error: %%1275


< End of report >

#4 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,784 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:06:57 PM

Posted 11 November 2009 - 06:53 PM

Hi,

Those logs look pretty clean, if you disaccount the blocked activations. :(

Please run Malwarebytes:
Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
If you have a previous version of MBAM, remove it via Add/Remove Programs and download a fresh copy.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself.
  • Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install. Alternatively, you can update through MBAM's interface from a clean computer, copy the definitions (rules.ref) located in C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you after scanning with MBAM. Please temporarily disable such programs or permit them to allow the changes.

And Kaspersky:
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#5 avanduser

avanduser
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:57 AM

Posted 13 November 2009 - 03:34 PM

Those logs look pretty clean, if you disaccount the blocked activations. :(

This has been resolved. The items have been removed. =)


I am having a little trouble with Kapersky. I think it is due to Comodo's defense settings. When I do manage to get it to start scanning, it runs for several hours and is only about 45% complete. I will keep trying and post the logs as soon as I am successful.

Thanks for your help and patience.

#6 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,784 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:06:57 PM

Posted 15 November 2009 - 05:54 PM

Hi,

then please try running the Eset onlinescanner instead:
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#7 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,784 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:06:57 PM

Posted 20 November 2009 - 06:12 AM

Due to lack of feedback, this topic is now Closed

If you need this topic reopened, please send me a PM.
Please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users