Hey EB,
Whan I was in Iraq last year I contracted the nar.vbs virus. A short history is this. I have three Computers:this Satellite with Vista, a Gateway laptop with XP and and a desk top with XP. My Gateway laptop was infected. In turn all of my external storage became infected with the NAR.VBS. I followed a post on the whatthetech website that had similar issues. I want to insure that Ive cleaned my computer properly and that I have no other infections. Hopfully I can make my security a little stronger and learn a little in the process.
Also, My Trend keeps poping up with an access to the internet that I cant figure out. I think it may be that stupid Google updater but Im not sure.
I will be heading to Iraq on the 28feb09. It may be dificult to respond but I think I may be able to handle a 5 day window. Thanks for the support EB. Im glad you can make since of all this.
Y Lee
OTview.TXT
OTViewIt logfile created on: 2/18/2009 2:39:55 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Users\Dwight\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 59.08 Gb Free Space | 25.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 4.18 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DWIGHT-PC
Current User Name: Dwight
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2008/01/19 02:33:37 | 00,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wininit.exe
[2008/01/19 02:33:14 | 00,229,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\lsm.exe
[2008/06/19 20:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe
[2008/01/19 02:33:22 | 02,623,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe
[2006/10/05 16:10:12 | 00,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe
[2006/11/14 23:33:10 | 00,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
[2009/02/11 10:19:38 | 00,179,856 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
[2000/08/06 01:50:20 | 07,442,493 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe
[2008/07/29 14:24:36 | 00,698,888 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
[2007/10/23 19:27:16 | 00,066,928 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe
[2007/06/28 19:25:30 | 00,077,824 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
[2006/05/25 21:30:16 | 00,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe
[2007/03/29 13:39:20 | 00,427,576 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
[2007/02/26 00:55:18 | 00,125,048 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
[2006/08/23 19:39:48 | 00,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
[2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
[2008/05/27 00:18:43 | 00,439,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe
[2008/02/15 23:39:30 | 00,333,064 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe
[2008/01/19 02:33:32 | 00,169,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2008/01/19 02:33:08 | 00,081,920 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dwm.exe
[2007/04/10 19:40:28 | 00,413,696 | —- | M] (Chicony) – C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
[2007/06/01 13:52:10 | 00,049,152 | —- | M] (Advanced Micro Devices Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
[2007/06/13 16:11:30 | 04,489,216 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
[2006/11/15 01:02:36 | 01,372,160 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
[2006/11/06 20:14:44 | 00,034,352 | —- | M] () – C:\Program Files\Toshiba\Utilities\KeNotify.exe
[2007/03/29 13:39:18 | 00,411,192 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
[2007/06/16 00:01:58 | 00,448,080 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\SmoothView\SmoothView.exe
[2008/10/15 01:04:34 | 00,039,792 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[2008/07/29 14:24:38 | 01,398,024 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
[2007/05/17 19:03:24 | 04,813,312 | —- | M] () – C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
[2008/06/20 07:37:00 | 01,316,136 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[2009/02/11 10:19:38 | 00,399,504 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
[2008/06/20 07:14:00 | 00,200,704 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynToshiba.exe
[2008/12/29 19:00:56 | 00,133,104 | —- | M] (Google Inc.) – C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe
[2008/01/19 02:33:39 | 00,202,240 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnscfg.exe
[2008/01/19 02:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe
[2008/01/19 02:33:39 | 00,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wbem\WmiPrvSE.exe
[2008/01/19 02:33:15 | 00,095,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mobsync.exe
[2008/02/16 00:58:10 | 00,488,768 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
[2006/11/15 00:19:42 | 00,405,504 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
[2008/02/16 00:58:10 | 00,648,456 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
[2007/06/01 13:52:34 | 00,049,152 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
[2008/01/19 02:33:32 | 00,169,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2008/05/27 00:18:16 | 00,184,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchProtocolHost.exe
[2008/05/27 00:17:55 | 00,087,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchFilterHost.exe
[2008/06/20 07:37:00 | 00,103,720 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
[2009/02/18 14:34:57 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2006/10/05 16:10:12 | 00,009,216 | —- | M] (Agere Systems) – C:\Windows\System32\agrsmsvc.exe – (AgereModemAudio [Auto | Running])
[2007/07/14 01:50:18 | 00,606,208 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\Ati2evxx.exe – (Ati External Event Utility [Auto | Running])
File not found – – (CertPropSvc [Unknown | Stopped])
[2006/11/14 23:33:10 | 00,040,960 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe – (CFSvcs [Auto | Running])
[2008/07/27 13:03:13 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
File not found – – (DcomLaunch [Unknown | Running])
[2008/01/19 02:33:06 | 02,091,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dfsr.exe – (DFSR [On_Demand | Stopped])
[2008/01/19 02:34:06 | 00,134,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dps.dll – (DPS [Unknown | Running])
[2008/01/19 02:33:09 | 00,292,352 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehrecvr.exe – (ehRecvr [On_Demand | Stopped])
[2006/11/02 07:35:29 | 00,131,072 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
[2008/06/19 20:14:44 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [Auto | Running])
[2008/01/19 02:34:25 | 00,574,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\gpsvc.dll – (gpsvc [Unknown | Running])
[2007/11/21 02:14:22 | 00,138,168 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
[2005/11/14 04:06:04 | 00,069,632 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
[2009/02/11 10:19:38 | 00,179,856 | —- | M] (Malwarebytes Corporation) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService [Auto | Running])
[2006/11/02 08:04:14 | 00,000,000 | —D | M] – C:\Windows\System32\Msdtc – (MSDTC [Unknown | Stopped])
[2000/08/06 01:50:20 | 07,442,493 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe – (MSSQLSERVER [Auto | Running])
[2000/08/06 01:50:18 | 00,065,602 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper [On_Demand | Stopped])
[2008/06/19 20:14:31 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\Toshiba\IVP\ISM\pinger.exe – (pinger [Auto | Running])
[2008/01/19 02:36:19 | 00,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll – (SCardSvr [Unknown | Stopped])
File not found – – (Schedule [Unknown | Running])
File not found – – (SCPolicySvc [Unknown | Stopped])
[2008/07/29 14:24:36 | 00,698,888 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe – (SfCtlCom [Auto | Running])
[2008/01/19 02:33:22 | 02,623,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe – (slsvc [Auto | Running])
[2006/11/02 04:45:46 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\snmptrap.exe – (SNMPTRAP [On_Demand | Stopped])
[2000/08/06 01:50:18 | 00,303,170 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE – (SQLSERVERAGENT [On_Demand | Stopped])
[2007/10/23 19:27:16 | 00,066,928 | —- | M] () – c:\Toshiba\IVP\swupdate\swupdtmr.exe – (Swupdtmr [Auto | Running])
[2008/02/15 23:39:30 | 00,333,064 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe – (TMBMServer [Auto | Running])
[2008/02/16 00:58:10 | 00,488,768 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe – (TmPfw [On_Demand | Running])
[2008/02/16 00:58:10 | 00,648,456 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe – (tmproxy [On_Demand | Running])
[2007/06/28 19:25:30 | 00,077,824 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe – (TNaviSrv [Auto | Running])
[2006/05/25 21:30:16 | 00,114,688 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe – (TODDSrv [Auto | Running])
[2007/03/29 13:39:20 | 00,427,576 | —- | M] (TOSHIBA Corporation) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe – (TosCoSrv [Auto | Running])
[2007/02/26 00:55:18 | 00,125,048 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe – (TOSHIBA Bluetooth Service [Auto | Running])
[2008/01/19 02:33:33 | 00,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UI0Detect.exe – (UI0Detect [On_Demand | Stopped])
[2006/08/23 19:39:48 | 00,049,152 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe – (UleadBurningHelper [Auto | Running])
[2008/01/19 02:33:33 | 00,382,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vds.exe – (vds [On_Demand | Stopped])
[2007/01/04 16:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
File not found – – (WdiServiceHost [Unknown | Stopped])
File not found – – (WdiSystemHost [Unknown | Running])
[2008/01/19 02:33:39 | 00,896,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Running])
[2008/05/27 00:18:43 | 00,439,808 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe – (WSearch [Auto | Running])
========== Driver Services ==========
[2006/11/02 04:51:38 | 00,420,968 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped])
[2006/11/02 04:51:32 | 00,297,576 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpahci.sys – (adpahci [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,098,408 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped])
[2006/11/02 04:51:00 | 00,147,048 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped])
[2006/11/28 19:11:00 | 01,161,888 | —- | M] (Agere Systems) – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem [On_Demand | Running])
[2006/11/02 04:50:11 | 00,071,272 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped])
[2006/11/02 04:49:20 | 00,014,952 | —- | M] (Acer Laboratories Inc.) – C:\Windows\System32\drivers\aliide.sys – (aliide [Disabled | Stopped])
[2006/11/02 04:49:59 | 00,054,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\AMDAGP.SYS – (amdagp [On_Demand | Stopped])
[2006/11/02 04:49:26 | 00,015,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdide.sys – (amdide [Disabled | Stopped])
[2006/11/02 03:30:18 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdk7.sys – (AmdK7 [Disabled | Stopped])
[2008/01/19 00:27:20 | 00,044,032 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\amdk8.sys – (AmdK8 [On_Demand | Running])
[2006/08/30 12:35:58 | 00,140,800 | —- | M] (Alps Electric Co., Ltd.) – C:\Windows\System32\drivers\Apfiltr.sys – (ApfiltrService [On_Demand | Stopped])
[2006/11/02 04:50:09 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\arc.sys – (arc [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\System32\drivers\arcsas.sys – (arcsas [Disabled | Stopped])
[2008/07/29 05:05:04 | 00,919,552 | —- | M] (Atheros Communications, Inc.) – C:\Windows\System32\drivers\athr.sys – (athr [On_Demand | Running])
[2007/07/14 02:01:30 | 02,771,968 | —- | M] (ATI Technologies Inc.) – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag [On_Demand | Running])
[2008/01/19 00:28:26 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\bowser.sys – (bowser [On_Demand | Running])
[2006/11/02 03:24:45 | 00,013,568 | —- | M] (Brother Industries, Ltd.) – C:\Windows\System32\drivers\BrFiltLo.sys – (BrFiltLo [On_Demand | Stopped])
[2006/11/02 03:24:46 | 00,005,248 | —- | M] (Brother Industries, Ltd.) – C:\Windows\System32\drivers\BrFiltUp.sys – (BrFiltUp [On_Demand | Stopped])
[2006/11/02 03:25:24 | 00,071,808 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrSerId.sys – (Brserid [Disabled | Stopped])
[2006/11/02 03:24:44 | 00,062,336 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrSerWdm.sys – (BrSerWdm [Disabled | Stopped])
[2006/11/02 03:24:44 | 00,012,160 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrUsbMdm.sys – (BrUsbMdm [Disabled | Stopped])
[2006/11/02 03:24:47 | 00,011,904 | —- | M] (Brother Industries Ltd.) – C:\Windows\System32\drivers\BrUsbSer.sys – (BrUsbSer [On_Demand | Stopped])
[2006/11/02 03:55:23 | 00,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\bthmodem.sys – (BTHMODEM [Disabled | Stopped])
[2006/10/04 21:42:42 | 00,002,432 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
[2006/10/04 21:42:42 | 00,002,560 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
[2006/11/02 03:55:08 | 00,035,328 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\circlass.sys – (circlass [Disabled | Stopped])
[2008/01/19 02:42:58 | 00,247,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\clfs.sys – (CLFS [Unknown | Running])
[2006/11/02 04:49:28 | 00,016,488 | —- | M] (CMD Technology, Inc.) – C:\Windows\System32\drivers\cmdide.sys – (cmdide [Disabled | Stopped])
[2006/11/02 04:49:43 | 00,022,632 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\crcdisk.sys – (crcdisk [Boot | Running])
[2006/11/02 03:30:18 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\crusoe.sys – (Crusoe [Disabled | Stopped])
[2008/01/19 00:28:20 | 00,075,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dfsc.sys – (DfsC [System | Running])
[2008/08/01 20:01:23 | 00,625,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgkrnl.sys – (DXGKrnl [On_Demand | Running])
[2006/11/02 02:30:54 | 00,117,760 | —- | M] (Intel Corporation) – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60 [On_Demand | Stopped])
[2008/01/19 02:42:11 | 00,143,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ecache.sys – (Ecache [Boot | Running])
[2006/11/02 04:51:34 | 00,316,520 | —- | M] (Emulex) – C:\Windows\System32\drivers\elxstor.sys – (elxstor [Disabled | Stopped])
[2008/01/19 00:28:01 | 00,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\exfat.sys – (exfat [On_Demand | Stopped])
[2008/01/19 02:42:31 | 00,058,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\fileinfo.sys – (FileInfo [Boot | Running])
[2008/01/19 00:30:23 | 00,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\filetrace.sys – (Filetrace [On_Demand | Stopped])
[2006/11/02 04:50:04 | 00,058,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\GAGP30KX.SYS – (gagp30kx [On_Demand | Stopped])
[2006/11/02 02:36:49 | 00,235,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\HdAudio.sys – (HdAudAddService [On_Demand | Running])
[2008/01/18 23:30:49 | 00,053,760 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hdaudbus.sys – (HDAudBus [On_Demand | Running])
[2006/11/02 03:55:22 | 00,029,184 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hidbth.sys – (HidBth [Disabled | Stopped])
[2006/11/02 03:55:01 | 00,021,504 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\hidir.sys – (HidIr [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,037,480 | —- | M] (Hewlett-Packard Company) – C:\Windows\System32\drivers\HpCISSs.sys – (HpCISSs [Disabled | Stopped])
[2006/11/02 04:51:25 | 00,232,040 | —- | M] (Intel Corporation) – C:\Windows\System32\drivers\iaStorV.sys – (iaStorV [Disabled | Stopped])
[2006/11/02 04:50:17 | 00,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\System32\drivers\iirsp.sys – (iirsp [Disabled | Stopped])
[2007/06/12 10:05:34 | 01,787,816 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running])
[2006/11/02 03:42:03 | 00,065,536 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\IPMIDrv.sys – (IPMIDRV [Disabled | Stopped])
[2008/01/19 02:42:35 | 00,181,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msiscsi.sys – (iScsiPrt [On_Demand | Running])
[2006/11/02 04:50:07 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\System32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped])
[2006/11/02 04:50:09 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\System32\drivers\iteraid.sys – (iteraid [Disabled | Stopped])
[2006/11/02 03:51:12 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdhid.sys – (kbdhid [Disabled | Stopped])
[2007/10/31 20:57:55 | 00,219,264 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\KR10I.sys – (KR10I [Disabled | Stopped])
[2007/10/31 20:58:10 | 00,211,072 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\KR10N.sys – (KR10N [Disabled | Stopped])
[2007/10/31 20:59:57 | 00,479,488 | —- | M] (TOSHIBA CORPORATION) – C:\Windows\System32\drivers\kr3npxp.sys – (KR3NPXP [Disabled | Stopped])
[2008/01/19 00:55:03 | 00,047,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\lltdio.sys – (lltdio [Auto | Running])
[2006/07/28 19:25:26 | 00,019,456 | —- | M] (COMPAL ELECTRONIC INC.) – C:\Windows\System32\drivers\LPCFilter.sys – (LPCFilter [Boot | Running])
[2006/11/02 04:50:04 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
[2006/11/02 04:50:05 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
[2006/11/02 04:50:10 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
[2008/01/19 00:30:36 | 00,084,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\luafv.sys – (luafv [Auto | Running])
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys – (MBAMProtector [On_Demand | Running])
[2006/11/02 04:49:53 | 00,028,776 | —- | M] (LSI Logic Corporation) – C:\Windows\System32\drivers\megasas.sys – (megasas [Disabled | Stopped])
[2008/01/19 00:52:19 | 00,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\monitor.sys – (monitor [On_Demand | Running])
[2007/06/18 20:18:26 | 00,023,680 | —- | M] (Motorola) – C:\Windows\System32\drivers\motmodem.sys – (motmodem [On_Demand | Stopped])
[2006/11/02 04:50:16 | 00,078,952 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mpio.sys – (mpio [Disabled | Stopped])
[2008/01/19 00:54:46 | 00,064,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mpsdrv.sys – (mpsdrv [On_Demand | Running])
[2006/11/02 04:49:59 | 00,033,384 | —- | M] (LSI Logic Corporation) – C:\Windows\System32\drivers\Mraid35x.sys – (Mraid35x [Disabled | Stopped])
[2008/11/15 02:27:29 | 00,212,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys – (mrxsmb10 [On_Demand | Running])
[2008/01/19 00:28:37 | 00,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys – (mrxsmb20 [On_Demand | Running])
[2006/11/02 04:49:44 | 00,023,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msahci.sys – (msahci [Disabled | Stopped])
[2006/11/02 04:50:17 | 00,080,488 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msdsm.sys – (msdsm [Disabled | Stopped])
[2008/01/19 02:41:14 | 00,016,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msisadrv.sys – (msisadrv [Boot | Running])
[2008/01/19 02:42:29 | 00,163,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\msrpc.sys – (MsRPC [On_Demand | Stopped])
[2008/05/19 21:07:31 | 00,148,480 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\nwifi.sys – (NativeWifiP [On_Demand | Running])
[2008/12/27 12:24:51 | 00,027,136 | —- | M] (NCH Swift Sound) – C:\Windows\System32\drivers\nchssvad.sys – (NCHSSVAD [On_Demand | Stopped])
[2006/11/02 04:50:19 | 00,045,160 | —- | M] (IBM Corporation) – C:\Windows\System32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped])
[2008/01/19 00:55:50 | 00,016,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\nsiproxy.sys – (nsiproxy [System | Running])
[2006/11/02 02:36:50 | 00,020,608 | —- | M] (N-trig Innovative Technologies) – C:\Windows\System32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped])
[2006/11/02 04:50:24 | 00,088,680 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvraid.sys – (nvraid [Disabled | Stopped])
[2006/11/02 04:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvstor.sys – (nvstor [Disabled | Stopped])
[2006/11/02 04:50:40 | 00,106,600 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\NV_AGP.SYS – (nv_agp [On_Demand | Stopped])
[2006/11/02 04:04:35 | 00,878,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\PEAuth.sys – (PEAUTH [Auto | Running])
[2008/04/04 20:21:42 | 00,072,192 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\pacer.sys – (PSched [System | Running])
[2008/07/31 17:17:04 | 00,043,872 | —- | M] (Sonic Solutions) – C:\Windows\System32\drivers\pxhelp20.sys – (PxHelp20 [Boot | Running])
[2006/11/02 04:51:45 | 00,900,712 | —- | M] (QLogic Corporation) – C:\Windows\System32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,106,088 | —- | M] (QLogic Corporation) – C:\Windows\System32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped])
[2008/01/19 00:56:07 | 00,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\qwavedrv.sys – (QWAVEdrv [On_Demand | Stopped])
[2008/01/19 00:56:43 | 00,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rassstp.sys – (RasSstp [On_Demand | Running])
[2008/01/19 01:01:09 | 00,006,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\RDPENCDD.sys – (RDPENCDD [System | Running])
[2008/01/19 00:55:03 | 00,060,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\rspndr.sys – (rspndr [Auto | Running])
[2007/04/30 16:42:14 | 00,081,408 | —- | M] (Realtek Corporation ) – C:\Windows\System32\drivers\Rtlh86.sys – (RTL8169 [On_Demand | Running])
[2006/11/02 04:50:16 | 00,076,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sbp2port.sys – (sbp2port [Disabled | Stopped])
[2008/07/07 02:40:49 | 00,056,108 | —- | M] (PowerISO Computing, Inc.) – C:\Windows\System32\drivers\scdemu.sys – (SCDEmu [System | Running])
[2008/01/19 00:32:56 | 00,088,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sdbus.sys – (sdbus [On_Demand | Running])
[2006/11/02 01:37:21 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running])
[2008/01/19 00:49:16 | 00,019,968 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sermouse.sys – (sermouse [Disabled | Stopped])
[2008/01/19 00:49:46 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffdisk.sys – (sffdisk [On_Demand | Stopped])
[2006/11/02 03:51:40 | 00,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffp_mmc.sys – (sffp_mmc [On_Demand | Stopped])
[2008/01/19 00:49:46 | 00,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\sffp_sd.sys – (sffp_sd [On_Demand | Stopped])
[2006/11/02 04:49:51 | 00,053,352 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\SISAGP.SYS – (sisagp [On_Demand | Stopped])
[2006/11/02 04:50:10 | 00,038,504 | —- | M] (Silicon Integrated Systems Corp.) – C:\Windows\System32\drivers\sisraid2.sys – (SiSRaid2 [Disabled | Stopped])
[2006/11/02 04:50:16 | 00,071,784 | —- | M] (Silicon Integrated Systems) – C:\Windows\System32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
[2008/01/19 00:55:27 | 00,066,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\smb.sys – (Smb [System | Running])
[2008/01/19 02:41:30 | 00,021,048 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\spldr.sys – (spldr [Boot | Running])
[2008/01/19 00:29:15 | 00,144,384 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys – (srv2 [On_Demand | Running])
[2008/01/19 00:29:12 | 00,098,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys – (srvnet [On_Demand | Running])
[2006/11/02 04:50:05 | 00,035,944 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped])
[2006/11/02 04:49:56 | 00,031,848 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped])
[2006/11/02 04:50:03 | 00,034,920 | —- | M] (LSI Logic) – C:\Windows\System32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped])
[2008/06/20 07:37:00 | 00,200,112 | —- | M] (Synaptics, Inc.) – C:\Windows\System32\drivers\SynTP.sys – (SynTP [On_Demand | Running])
[2008/01/19 00:56:07 | 00,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys – (tcpipreg [Auto | Running])
[2006/10/18 14:50:04 | 00,016,128 | —- | M] (TOSHIBA Corporation.) – C:\Windows\System32\drivers\tdcmdpst.sys – (tdcmdpst [On_Demand | Running])
[2008/01/19 00:55:58 | 00,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tdx.sys – (tdx [System | Running])
[2007/01/24 17:44:06 | 00,290,304 | —- | M] (Texas Instruments) – C:\Windows\System32\drivers\tifm21.sys – (tifm21 [On_Demand | Running])
[2008/02/15 23:39:30 | 00,052,496 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon [Auto | Running])
[2008/02/15 23:39:30 | 00,138,384 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm [Auto | Running])
[2008/02/15 23:39:30 | 00,052,240 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr [Auto | Running])
[2008/02/15 23:39:32 | 00,141,840 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmlwf.sys – (tmlwf [System | Running])
[2008/11/26 17:42:40 | 00,036,368 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmpreflt.sys – (tmpreflt [Auto | Running])
[2008/02/15 23:39:32 | 00,065,936 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi [System | Running])
[2008/02/15 23:39:32 | 00,234,512 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmwfp.sys – (tmwfp [Auto | Running])
[2008/11/26 17:42:42 | 00,205,328 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\tmxpflt.sys – (tmxpflt [Auto | Running])
[2007/06/28 19:23:14 | 00,285,184 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\drivers\tos_sps32.sys – (tos_sps32 [Boot | Running])
[2008/01/19 01:01:15 | 00,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tssecsrv.sys – (tssecsrv [On_Demand | Stopped])
[2008/01/19 00:55:41 | 00,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\TUNMP.SYS – (tunmp [On_Demand | Running])
[2008/01/19 00:55:50 | 00,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys – (tunnel [On_Demand | Running])
[2007/11/09 05:00:52 | 00,023,640 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\drivers\TVALZ_O.SYS – (TVALZ [Boot | Running])
[2006/11/02 04:49:59 | 00,056,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\UAGP35.SYS – (uagp35 [On_Demand | Stopped])
[2006/11/02 04:50:04 | 00,058,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ULIAGPKX.SYS – (uliagpkx [On_Demand | Stopped])
[2006/11/02 04:51:25 | 00,235,112 | —- | M] (ULi Electronics Inc.) – C:\Windows\System32\drivers\uliahci.sys – (uliahci [Disabled | Stopped])
[2006/11/02 04:50:35 | 00,098,408 | —- | M] (Promise Technology, Inc.) – C:\Windows\System32\drivers\ulsata.sys – (UlSata [Disabled | Stopped])
[2006/11/02 04:50:45 | 00,115,816 | —- | M] (Promise Technology, Inc.) – C:\Windows\System32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped])
[2008/01/19 00:53:40 | 00,034,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\umbus.sys – (umbus [On_Demand | Running])
[2008/01/19 00:53:23 | 00,073,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\USBAUDIO.sys – (usbaudio [On_Demand | Stopped])
[2006/11/02 03:55:09 | 00,068,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbcir.sys – (usbcir [Disabled | Stopped])
[2008/01/19 00:53:38 | 00,134,016 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\usbvideo.sys – (usbvideo [On_Demand | Running])
[2007/04/16 13:19:10 | 00,011,776 | —- | M] (Chicony Electronics Co., Ltd.) – C:\Windows\System32\drivers\UVCFTR_S.SYS – (UVCFTR [On_Demand | Running])
[2006/11/02 03:53:56 | 00,026,112 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\vgapnp.sys – (vga [On_Demand | Stopped])
[2006/11/02 03:30:19 | 00,039,424 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\viac7.sys – (ViaC7 [Disabled | Stopped])
[2006/11/02 04:49:30 | 00,017,512 | —- | M] (VIA Technologies, Inc.) – C:\Windows\System32\drivers\viaide.sys – (viaide [Disabled | Stopped])
[2008/01/19 02:42:18 | 00,052,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgr.sys – (volmgr [Boot | Running])
[2008/01/19 02:43:03 | 00,294,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgrx.sys – (volmgrx [Boot | Running])
[2008/11/26 17:39:56 | 01,195,384 | —- | M] (Trend Micro Inc.) – C:\Windows\System32\drivers\vsapint.sys – (vsapint [Auto | Running])
[2006/11/02 04:50:41 | 00,112,232 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\System32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped])
[2006/11/02 03:52:52 | 00,020,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wacompen.sys – (WacomPen [Disabled | Stopped])
[2006/11/02 04:49:38 | 00,019,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wd.sys – (Wd [Disabled | Stopped])
[2008/01/19 02:43:27 | 00,503,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\Wdf01000.sys – (Wdf01000 [Boot | Running])
[2006/11/02 03:35:03 | 00,011,264 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\wmiacpi.sys – (WmiAcpi [Disabled | Stopped])
[2008/01/19 00:56:49 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ws2ifsl.sys – (ws2ifsl [Disabled | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/
"StartPageCache"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\Windows\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.com/
"StartPageCache"=
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) – C:\Windows\System32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
First 25 entries…
127.0.0.1 localhost
::1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) – Reg Error: Key does not exist or could not be opened. File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) – C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) – C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe (Alps Electric Co., Ltd.)
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" (Chicony)
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
"KeNotify"=C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray (Malwarebytes Corporation)
"NDSTray.exe"=NDSTray.exe File not found
"RtHDVCpl"=RtHDVCpl.exe (Realtek Semiconductor)
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe ()
"SVPWUTIL"=C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL (TOSHIBA)
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE (TOSHIBA Corporation)
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" (Trend Micro Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe ()
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe ()
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Users\Dwight\AppData\Local\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"ConsentPromptBehaviorAdmin"=2
"ConsentPromptBehaviorUser"=1
"EnableInstallerDetection"=1
"EnableLUA"=1
"EnableSecureUIAPaths"=1
"EnableVirtualization"=1
"PromptOnSecureDesktop"=1
"ValidateAdminCodeSignatures"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=0
"EnableUIADesktopToggle"=0
"DisableRegistryTools"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=1
"CF_BITMAP"=2
"CF_OEMTEXT"=7
"CF_DIB"=8
"CF_PALETTE"=9
"CF_UNICODETEXT"=13
"CF_DIBV5"=17
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDrives"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE File not found
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE File not found
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE File not found
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\Software\Microsoft\Internet Explorer\MenuExt\]
Add to Google Photos Screensa&ver: C:\Windows\System32\GPhotos.scr [2009/01/05 17:33:03 | 03,751,995 | —- | M] (Google Inc.)
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE File not found
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console – %ProgramFiles%\Java\jre1.6.0\bin\ssv.dll [2007/11/21 00:10:56 | 00,501,384 | —- | M] (Sun Microsystems, Inc.)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find…=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}: http://download.microsoft.com/download/e/4…/OGAControl.cab – Office Genuine Advantage Validation Tool
{166B1BCA-3F9C-11CF-8075-444553540000}: http://download.macromedia.com/pub/shockwa…director/sw.cab – Shockwave ActiveX Control
{48DD0448-9209-4F81-9F6D-D83562940134}: http://lads.myspace.com/upload/MySpaceUploader1006.cab – MySpace Uploader Control
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}:
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab – Reg Error: Key does not exist or could not be opened.
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab – Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{02F7655A-98D3-4039-9B74-F755FB566EA8} (Servers: | Description: Atheros AR5007EG Wireless Network Adapter)
{46AD3553-38E8-46D5-8E94-9B847D02D5DB} (Servers: | Description: Realtek RTL8101E Family PCI-E Fast Ethernet NIC (NDIS 6.0))
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders"=credssp.dll
>[2008/01/19 02:33:59 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\credssp.dll
========== LSA *Security Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages"=kerberos,msv1_0,schannel,wdigest,tspkg,
>[2008/01/19 02:36:42 | 00,062,464 | —- | M] (Microsoft Corporation) – C:\Windows\System32\TSpkg.dll
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
autoexec.bat [REM Dummy file for NTVDM | ]
[2006/09/18 16:43:36 | 00,000,024 | —- | M] () – C:\autoexec.bat – [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{225fef0d-cea6-11dd-bc21-001eec011f5b}\Shell\AutoRun\command]
""=G:\PhotoViewerAP-V305.exe – File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4bc05cc0-e1b3-11dd-9e3d-001eec011f5b}\Shell\AutoRun\command]
""=E:\wd_windows_tools\setup.exe – File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{747cd9e6-bc5a-11dd-a296-001eec011f5b}\Shell\AutoRun\command]
""=C:\Windows\System32\shell32.dll – [2008/11/06 08:14:25 | 11,580,928 | —- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\Shell\AutoRun\command]
""=E:\wd_windows_tools\setup.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/02/18 14:34:44 | 00,422,912 | —- | C] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe
[2009/02/16 15:51:04 | 00,000,496 | —- | C] () – C:\Windows\tasks\Malwarebytes' Scheduled Scan for Dwight.job
[2009/02/10 19:29:38 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/02/10 19:29:37 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/02/10 19:29:37 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/02/10 19:29:36 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/02/10 19:29:36 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/02/10 19:28:39 | 03,580,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/02/10 19:28:38 | 06,069,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/02/10 19:28:38 | 01,166,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/02/10 19:28:37 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/02/10 19:28:37 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/02/10 19:28:37 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/02/10 19:28:37 | 00,458,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/02/10 19:28:37 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/02/10 19:28:37 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/02/07 23:20:47 | 00,000,000 | —D | C] – C:\Windows\temp
[2009/02/07 23:17:09 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2009/02/07 23:17:09 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2009/02/07 23:17:09 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2009/02/07 23:17:09 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2009/02/07 23:17:09 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\Windows\fdsv.exe
[2009/02/07 23:17:09 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2009/02/07 23:17:09 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2009/02/07 23:17:09 | 00,049,152 | —- | C] () – C:\Windows\VFIND.exe
[2009/02/07 23:17:04 | 00,000,000 | —D | C] – C:\ComboFix
[2009/02/07 23:08:55 | 00,001,845 | —- | C] () – C:\Users\Dwight\Desktop\HijackThis.lnk
[2009/02/07 15:08:07 | 00,017,408 | —- | C] () – C:\Users\Dwight\Documents\Expenses.xls
[2009/02/06 21:36:45 | 00,024,887 | —- | C] () – C:\Users\Dwight\Documents\LCIHZM.pdf
[2009/02/05 21:38:06 | 00,019,968 | —- | C] () – C:\Users\Dwight\Documents\1995 judy cr marrietta 30060.doc
[2009/02/05 15:04:29 | 00,012,387 | —- | C] () – C:\Users\Dwight\Documents\hey_hey_acoustic.gp3
[2009/02/04 22:19:22 | 00,007,038 | —- | C] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).gp3
[2009/02/04 22:18:50 | 00,001,379 | —- | C] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).zip
[2009/02/04 19:10:14 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Local\Adobe
[2009/02/03 12:07:39 | 00,086,753 | —- | C] () – C:\Users\Dwight\Documents\stuck_in_the_middle.gp3
[2009/02/02 21:06:42 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/02/01 13:59:18 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/02/01 13:59:18 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/02/01 13:59:17 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/02/01 13:59:17 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/02/01 13:59:17 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/02/01 13:59:17 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/02/01 13:59:16 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/02/01 13:59:14 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/02/01 13:50:43 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/02/01 13:50:39 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/02/01 13:50:39 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/02/01 13:50:29 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/02/01 13:50:27 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/01/30 14:12:17 | 00,000,000 | —D | C] – C:\Users\Dwight\Desktop\PSP
[2009/01/28 16:59:22 | 00,700,927 | —- | C] () – C:\Users\Dwight\Documents\BH souther draw gary pfaff.wma
[2009/01/27 16:34:02 | 00,000,000 | —D | C] – C:\Users\Dwight\Documents\Recordpad
[2009/01/27 16:34:01 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Recordpad
[2009/01/26 16:09:38 | 04,617,920 | —- | C] () – C:\Users\Dwight\Documents\sa210v200.exe
[2009/01/24 22:35:29 | 00,029,696 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2009/01/24 22:35:21 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/01/24 22:35:21 | 00,000,000 | —D | C] – C:\Qoobox
[2009/01/24 21:27:59 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Local\AOL
[2009/01/24 21:06:09 | 03,048,418 | R— | C] () – C:\Users\Dwight\Documents\ComboFix.exe
[2009/01/24 20:30:49 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Malwarebytes
[2009/01/24 20:30:42 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/01/24 20:30:39 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/01/24 20:30:38 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/01/24 20:30:38 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/23 16:09:10 | 00,038,912 | —- | C] () – C:\Users\Dwight\Desktop\from Charleston.doc
[2009/01/21 20:25:58 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\WinRAR
[2009/01/20 19:51:33 | 00,000,000 | —D | C] – C:\Users\Dwight\AppData\Roaming\Mozilla
[2009/01/20 16:27:58 | 00,030,208 | —- | C] () – C:\Users\Dwight\Documents\Faith Of the Heart.doc
[2009/01/19 15:08:45 | 00,029,184 | —- | C] () – C:\Users\Dwight\Desktop\TO Charleston.doc
========== Files - Modified Within 30 Days ==========
[1 C:\Windows\*.tmp files]
[2009/02/18 14:38:24 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/02/18 14:38:23 | 00,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/02/18 14:38:17 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/02/18 14:38:14 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/02/18 14:37:00 | 04,121,740 | -H– | M] () – C:\Users\Dwight\AppData\Local\IconCache.db
[2009/02/18 14:34:57 | 00,422,912 | —- | M] (OldTimer Tools) – C:\Users\Dwight\Desktop\OTViewIt.exe
[2009/02/18 11:22:19 | 00,716,878 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/02/18 11:22:19 | 00,613,514 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/02/18 11:22:19 | 00,108,694 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/02/16 15:53:22 | 00,000,496 | —- | M] () – C:\Windows\tasks\Malwarebytes' Scheduled Scan for Dwight.job
[2009/02/16 15:49:34 | 00,236,544 | —- | M] () – C:\Users\Dwight\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/16 13:49:22 | 03,293,740 | —- | M] () – C:\Users\Dwight\Desktop\Coldplay - Don't panic.mp3
[2009/02/11 10:19:42 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/02/11 10:19:34 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/02/08 11:04:47 | 00,025,600 | —- | M] () – C:\Users\Dwight\Desktop\Pass an ID.doc
[2009/02/07 23:19:22 | 00,000,215 | —- | M] () – C:\Windows\system.ini
[2009/02/07 23:08:55 | 00,001,845 | —- | M] () – C:\Users\Dwight\Desktop\HijackThis.lnk
[2009/02/07 15:08:07 | 00,017,408 | —- | M] () – C:\Users\Dwight\Documents\Expenses.xls
[2009/02/06 21:36:46 | 00,024,887 | —- | M] () – C:\Users\Dwight\Documents\LCIHZM.pdf
[2009/02/05 21:38:08 | 00,019,968 | —- | M] () – C:\Users\Dwight\Documents\1995 judy cr marrietta 30060.doc
[2009/02/05 15:08:51 | 00,012,106 | —- | M] () – C:\Users\Dwight\Documents\summer_of_69_acoustic.gp3
[2009/02/05 15:04:30 | 00,012,387 | —- | M] () – C:\Users\Dwight\Documents\hey_hey_acoustic.gp3
[2009/02/04 22:18:52 | 00,001,379 | —- | M] () – C:\Users\Dwight\Documents\Clapton, Eric - Tears in Heaven (4).zip
[2009/02/03 19:20:17 | 00,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\tmvsthfud.bin
[2009/02/03 19:20:10 | 00,000,761 | —- | M] () – C:\Windows\System32\drivers\etc\tmvsthfss.bin
[2009/02/03 18:21:12 | 21,244,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/02/03 12:07:39 | 00,086,753 | —- | M] () – C:\Users\Dwight\Documents\stuck_in_the_middle.gp3
[2009/02/02 21:06:42 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
[2009/01/28 16:59:22 | 00,700,927 | —- | M] () – C:\Users\Dwight\Documents\BH souther draw gary pfaff.wma
[2009/01/26 16:09:39 | 04,617,920 | —- | M] () – C:\Users\Dwight\Documents\sa210v200.exe
[2009/01/24 22:47:24 | 00,111,184 | —- | M] () – C:\Users\Dwight\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/01/24 22:45:29 | 00,390,536 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/01/24 21:06:14 | 03,048,418 | R— | M] () – C:\Users\Dwight\Documents\ComboFix.exe
[2009/01/23 16:09:11 | 00,038,912 | —- | M] () – C:\Users\Dwight\Desktop\from Charleston.doc
[2009/01/20 16:27:59 | 00,030,208 | —- | M] () – C:\Users\Dwight\Documents\Faith Of the Heart.doc
[2009/01/19 19:29:15 | 00,000,376 | —- | M] () – C:\Windows\ODBC.INI
[2009/01/19 19:29:03 | 00,000,240 | —- | M] () – C:\Windows\win.ini
[2009/01/19 15:08:46 | 00,029,184 | —- | M] () – C:\Users\Dwight\Desktop\TO Charleston.doc
< End of report >
OTViewIt Extras logfile created on: 2/18/2009 2:39:55 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Users\Dwight\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys;
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 231.42 Gb Total Space | 59.08 Gb Free Space | 25.53% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 4.18 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DWIGHT-PC
Current User Name: Dwight
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval"=1
"UacDisableNotify"=0
"InternetSettingsDisableNotify"=0
"AutoUpdateDisableNotify"=1
"FirewallDisableNotify"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride"=0
"AntiSpywareOverride"=0
"FirewallOverride"=0
"VistaSp1"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications"=0
"EnableFirewall"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2007/01/25 21:49:34 | 00,472,688 | —- | M] (TOSHIBA Corporation) – C:\TOSHIBA\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
[2007/01/25 21:47:50 | 00,136,816 | —- | M] () – C:\TOSHIBA\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
========== (O10) Winsock2 Catalogs ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] – C:\Windows\System32\nlaapi.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] – C:\Windows\System32\NapiNSP.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] – C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] – C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Protocol Defaults ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - Default Protocols
ldap – 4 = Restricted sites (Not a Default Protocol)
news – 4 = Restricted sites (Not a Default Protocol)
nntp – 4 = Restricted sites (Not a Default Protocol)
oecmd – 4 = Restricted sites (Not a Default Protocol)
snews – 4 = Restricted sites (Not a Default Protocol)
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt – @ivt protocol not assigned
file – file protocol not assigned
ftp – ftp protocol not assigned
http – http protocol not assigned
https – https protocol not assigned
shell – shell protocol not assigned
========== HKEY_USERS Protocol Defaults ==========
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults] - Default Protocols
@ivt – @ivt protocol not assigned
file – file protocol not assigned
ftp – ftp protocol not assigned
http – http protocol not assigned
https – https protocol not assigned
shell – shell protocol not assigned
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2004/01/29 09:08:23 | 01,130,496 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2004/01/29 09:08:23 | 01,130,496 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/01/24 15:22:56 | 07,255,384 | —- | M] (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}"=TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{0556F885-2415-4666-B53E-33727E46AEA1}"=The Movies™
"{07DE4C59-1853-ED4C-D7F3-58B8D62A52D1}"=CCC Help Swedish
"{0DD37678-746F-0292-8061-119F51CAEEB5}"=Catalyst Control Center Localization Russian
"{0F7CB237-1CAF-FAFB-A59E-F37849B036D7}"=CCC Help Finnish
"{11765420-93F3-7FBE-B534-9C5D08741F18}"=CCC Help Hungarian
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}"=Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}"=TOSHIBA Assist
"{130555D4-8394-C474-7187-56BE801E8EBA}"=CCC Help Dutch
"{1C85F7CD-26A9-57FD-7EEE-33F92B0D5AFE}"=Catalyst Control Center Localization Portuguese
"{1D5DE126-2E69-965C-B208-E8ECD8A1234B}"=Catalyst Control Center Graphics Full New
"{22543949-70E8-45D0-A938-F38143EB8BF8}"=Catalyst Control Center - Branding
"{249D150B-3925-54BC-3128-636944EA35DA}"=Catalyst Control Center Graphics Light
"{28006915-2739-4EBE-B5E8-49B25D32EB33}"=Atheros Driver Installation Program
"{2BE9962D-0585-4AB5-00BD-6142B888EF07}"=Catalyst Control Center Localization Swedish
"{2F1EAAEC-2128-E168-42E2-FB3028EB29A0}"=Catalyst Control Center Graphics Full Existing
"{305305E9-E188-05A2-3ED6-D46C986A1AF5}"=Catalyst Control Center Core Implementation
"{3090202E-C8DF-C97F-5191-D26181952198}"=CCC Help Russian
"{320E0701-F0AF-614D-993F-CC0315FCACA6}"=CCC Help Czech
"{3248F0A8-6813-11D6-A77B-00B0D0160000}"=Java™ SE Runtime Environment 6
"{3685E0FA-A49E-4998-F1E7-B1ADFD4E7DCF}"=CCC Help Norwegian
"{37C866E4-AA67-4725-9E95-A39968DD7960}"=Camera Assistant Software for Toshiba
"{3C1A9655-2EF5-8B55-54BD-F197DC5B4120}"=CCC Help Japanese
"{3D17CA85-B2C4-0770-0FD7-91E981F49A21}"=CCC Help Polish
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}"=TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{4160DC5B-4C56-D0C3-C5FD-F5BDAD3C882B}"=ATI Catalyst Install Manager
"{425A2BC2-AA64-4107-9C29-484245BBEA05}"=TOSHIBA Software Upgrades
"{43257822-3659-C7FC-7FA1-39DB6CA8729B}"=Catalyst Control Center Localization Spanish
"{475FC1B8-37D5-61AB-C7E5-23E484BB192F}"=Catalyst Control Center Localization Italian
"{4BAEB03C-945F-DD06-CB66-BB7FA01E6F74}"=Catalyst Control Center Localization Chinese Traditional
"{4E9FF0C3-A9DE-833A-0363-C59C6E82C4C6}"=Catalyst Control Center Localization German
"{510937B5-7839-725E-0BDF-4DC6C904FA5E}"=Catalyst Control Center Localization Turkish
"{5164F8DC-F412-F815-09D4-8831ED068A2C}"=CCC Help Portuguese
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}"=TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}"=TOSHIBA Hardware Setup
"{5569EC1D-EB0A-2B1F-7556-0EFF544655BB}"=Catalyst Control Center Localization Norwegian
"{56D366C8-CD07-598D-1CEF-B8CE0B012557}"=CCC Help Korean
"{596C35F8-5E89-235D-2FEC-D418B35C92B3}"=Catalyst Control Center Localization Dutch
"{5C0DBA7C-C8D4-FAAE-F9B3-E19E006FED9E}"=Catalyst Control Center Localization Danish
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}"=TOSHIBA Disc Creator
"{5DB6B0A9-2C0B-3351-804C-D96D315BB0BC}"=CCC Help Chinese Standard
"{5E69185C-D66E-6FA5-5936-D7188B113EE5}"=Catalyst Control Center Localization Thai
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}"=TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}"=TOSHIBA Flash Cards Support Utility
"{676F4F10-4AE7-1318-2F73-D63BB95A9C6C}"=CCC Help English
"{6849D118-BF82-F0CB-EF52-F48220D351D9}"=CCC Help Chinese Traditional
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}"=TOSHIBA DVD PLAYER
"{70154DC9-1283-8C9E-0DA1-ADD9B9E7BA20}"=Catalyst Control Center Localization French
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}"=Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{7671EA0A-4072-061C-9470-DDEAEAE0ADDD}"=Catalyst Control Center Localization Chinese Standard
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}"=TOSHIBA ConfigFree
"{7BF1756D-09B7-7789-BA2D-7C5BE41EE019}"=Catalyst Control Center Localization Polish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}"=Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{890EF3F8-742F-46BD-9E8E-084B3A1F4364}"=QuickBooks Financial Center
"{8CA50864-D2A8-C5E4-B37A-577EF430E564}"=ccc-core-static
"{8EB29328-86D5-030F-BD19-84E0719182B0}"=CCC Help Italian
"{90280409-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Professional with FrontPage
"{9D516A16-8CF2-A41A-B08E-2E926DE216D2}"=Catalyst Control Center Localization Czech
"{9F1D6FA1-F26E-7462-7BA1-F9314AFECEE5}"=CCC Help Danish
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}"=ALPS Touch Pad Driver
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}"=CD/DVD Drive Acoustic Silencer
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}"=Microsoft Visual C++ 2005 Redistributable
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}"=Trend Micro Internet Security
"{AACAFAC3-AFED-3F46-C42C-5614EA1E1C2D}"=CCC Help German
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{AC76BA86-7AD7-5464-3428-800000000003}"=Spelling Dictionaries Support For Adobe Reader 8
"{B279F2F1-3B2F-3A96-AC11-5743CD43DCCB}"=Google Talk Plugin
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}"=Microsoft XML Parser
"{B6111119-1868-579F-F823-83FD3B31871C}"=CCC Help Spanish
"{B70889DF-1F95-33BA-726A-C977BAF3D0EE}"=Catalyst Control Center Localization Greek
"{BC9EB8C7-158C-FE97-C2AC-7BD719C34169}"=CCC Help Turkish
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}"=Toshiba Registration
"{CA0ACBD9-4385-D03C-4C25-76160158F4B7}"=Catalyst Control Center Graphics Previews Vista
"{CCAC0157-2138-666F-E512-86697966300F}"=ccc-utility
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}"=Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}"=Bluetooth Stack for Windows by Toshiba
"{DB238FBC-C8B1-FE77-9851-58E2257E2AAE}"=CCC Help Thai
"{DB780B85-B4B5-4864-A49C-9B706B169C93}"=TIPCI
"{DF76BE47-9C57-A83E-C01D-A0CAE4B905E6}"=Catalyst Control Center Localization Japanese
"{E09B48B5-E141-427A-AB0C-D3605127224A}"=Microsoft SQL Server Desktop Engine
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}"=Windows Media Encoder 9 Series
"{E3B67656-DAC1-D6C7-7347-3874F4F4327C}"=Skins
"{E426EFC7-7619-F987-6753-52408FBED13D}"=Catalyst Control Center Localization Korean
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}"=TOSHIBA SD Memory Utilities
"{ED017667-DB2E-4BD1-C8E4-154742C560D1}"=Catalyst Control Center Localization Hungarian
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}"=TOSHIBA Speech System Applications
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}"=DVD MovieFactory for TOSHIBA
"{F3400EA2-11D2-62BF-8AB4-1E590A8D947B}"=CCC Help Greek
"{F40D5162-FEE0-C312-9F27-2B262F23B6CD}"=Catalyst Control Center Localization Finnish
"{F766457E-BBE1-B55A-1D46-D2D30016E52B}"=CCC Help French
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}"=TOSHIBA Value Added Package
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"AIM_6"=AIM 6
"Guild Wars"=Guild Wars
"Guitar Pro 5_is1"=Guitar Pro 5.2
"HijackThis"=HijackThis 2.0.2
"InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}"=The Movies™
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}"=TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}"=TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}"=TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}"=TOSHIBA Flash Cards Support Utility
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}"=Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}"=TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1"=Microsoft .NET Framework 3.5 SP1
"MySpaceIM"=MySpaceIM
"Picasa 3"=Picasa 3
"PitchPerfect"=PitchPerfect Uninstall
"PowerISO"=PowerISO
"Switch"=Switch Sound File Converter
"SynTPDeinstKey"=Synaptics Pointing Device Driver
"ToolBox"=NCH Toolbox
"TOSHIBA Software Modem"=TOSHIBA Software Modem
"ViewpointMediaPlayer"=Viewpoint Media Player
"VLC media player"=VideoLAN VLC media player 0.8.6c
"Windows Media Encoder 9"=Windows Media Encoder 9 Series
"WinRAR archiver"=WinRAR archiver
"Yahoo! Messenger"=Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer
"uTorrent"=µTorrent
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3808634989-3168378001-4255807635-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer
"uTorrent"=µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/16/2009 1:15:46 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/16/2009 2:15:35 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/16/2009 3:15:41 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/16/2009 4:15:42 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/16/2009 5:15:46 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/16/2009 6:15:35 AM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/17/2009 7:39:38 PM | Computer Name = Dwight-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 7.0.6001.18000 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: cfc Start Time: 01c978fa2c7b2235 Termination Time: 16
Error - 1/23/2009 7:21:07 PM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/24/2009 4:32:32 PM | Computer Name = Dwight-PC | Source = Google Update | ID = 20
Description =
Error - 1/24/2009 11:43:51 PM | Computer Name = Dwight-PC | Source = EventSystem | ID = 4621
Description =
[ Media Center Events ]
Error - 12/18/2008 2:34:24 PM | Computer Name = Dwight-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ System Events ]
Error - 1/28/2009 6:43:03 PM | Computer Name = Dwight-PC | Source = bowser | ID = 8003
Description =
Error - 1/28/2009 11:53:31 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =
Error - 1/29/2009 5:04:44 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =
Error - 1/29/2009 5:05:03 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 1/30/2009 3:43:28 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =
Error - 1/30/2009 6:53:25 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =
Error - 1/30/2009 6:53:38 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 1/30/2009 6:59:58 PM | Computer Name = Dwight-PC | Source = DCOM | ID = 10010
Description =
Error - 1/30/2009 7:01:09 PM | Computer Name = Dwight-PC | Source = HTTP | ID = 15016
Description =
Error - 1/30/2009 7:01:24 PM | Computer Name = Dwight-PC | Source = Service Control Manager | ID = 7000
Description =
< End of report >
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 6.0.6001 Service Pack 1
2/18/2009 5:33:59 PM
mbam-log-2009-02-18 (17-33-59).txt
Scan type: Full Scan (C:\|D:\|F:\|)
Objects scanned: 166794
Time elapsed: 2 hour(s), 8 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)