WebThunder? Thats my downloader.
Here's the OTListIt.Txt
OTListIt logfile created on: 4/21/2009 11:11:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Michael\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.36% Memory free
3.85 Gb Paging File | 3.20 Gb Available in Paging File | 83.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.36 Gb Total Space | 44.72 Gb Free Space | 31.41% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: M1710
Current User Name: Michael
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2006/05/01 11:20:52 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
PRC - [2006/05/01 11:22:42 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
PRC - [2006/05/01 11:34:00 | 00,262,217 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
PRC - [2008/10/15 14:31:53 | 00,068,865 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
PRC - [2007/04/02 22:19:34 | 00,151,552 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2008/10/15 14:30:02 | 00,151,297 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
PRC - [2005/12/15 14:14:40 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe
PRC - [2004/08/10 07:00:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2008/11/23 19:18:54 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/03/09 20:50:18 | 00,018,944 | —- | M] (http://libusb-win32.sourceforge.net) – C:\WINDOWS\system32\libusbd-nt.exe
PRC - [2003/06/20 01:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/12/18 10:47:08 | 09,158,656 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
PRC - [2006/09/08 17:41:46 | 00,380,928 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
PRC - [2007/08/02 12:33:50 | 00,080,528 | —- | M] (INCA Internet Co., Ltd.) – C:\Nexon\Mabinogi\npkcmsvc.exe
PRC - [2006/05/01 02:46:00 | 00,143,428 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007/08/27 12:01:42 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe
PRC - [2006/05/01 11:20:26 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
PRC - [2006/11/20 04:42:45 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\snmp.exe
PRC - [2005/08/03 21:05:55 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wdfmgr.exe
PRC - [2008/08/25 10:02:58 | 00,076,800 | —- | M] () – C:\Program Files\VentSrv\ventrilo_svc.exe
PRC - [2008/11/18 11:31:38 | 00,253,952 | —- | M] () – C:\Program Files\VentSrv\ventrilo_srv.exe
PRC - [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe
PRC - [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2007/06/13 06:23:07 | 01,033,216 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2004/08/10 07:00:00 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqsvc.exe
PRC - [2004/08/10 07:00:00 | 00,117,248 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqtgsvc.exe
PRC - [2009/02/06 05:41:05 | 00,227,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2005/09/29 16:01:14 | 00,067,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehtray.exe
PRC - [2008/11/23 19:18:54 | 00,136,600 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2006/05/01 11:28:06 | 00,667,718 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
PRC - [2006/05/01 11:28:26 | 00,602,182 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
PRC - [2005/08/05 15:56:28 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehmsas.exe
PRC - [2006/03/24 18:30:44 | 00,282,624 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [2006/03/08 13:48:02 | 00,761,947 | —- | M] (Synaptics, Inc.) – C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/09/08 07:20:00 | 00,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLACTRLW.EXE
PRC - [2005/08/11 15:30:30 | 00,081,920 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2007/01/25 03:34:47 | 00,169,984 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2006/08/22 17:32:18 | 00,184,320 | —- | M] (CyberLink Corp.) – C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2007/01/25 03:34:47 | 00,555,008 | —- | M] () – C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
PRC - [2007/04/02 22:19:34 | 00,419,408 | —- | M] (Acronis) – C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
PRC - [2007/04/02 22:19:34 | 00,069,632 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2006/05/01 11:26:14 | 00,397,381 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
PRC - [2007/09/26 19:05:58 | 00,734,264 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
PRC - [2008/06/12 14:28:45 | 00,266,497 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
PRC - [2007/07/13 10:36:56 | 00,068,856 | —- | M] (Google Inc.) – C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
PRC - [2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\MsnMsgr.Exe
PRC - [2009/01/19 19:09:28 | 00,160,592 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
PRC - [2009/01/21 13:36:33 | 00,342,848 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe
PRC - [2003/10/29 04:06:00 | 00,024,576 | —- | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2009/04/10 19:22:58 | 03,111,248 | —- | M] (Xfire Inc.) – C:\Program Files\Xfire\xfire.exe
PRC - [2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe
PRC - [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe
PRC - [2009/02/28 00:54:41 | 00,636,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\IEXPLORE.EXE
PRC - [2004/08/10 07:00:00 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wscntfy.exe
PRC - [2007/10/11 09:55:10 | 00,864,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
PRC - [2004/08/10 07:00:00 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cidaemon.exe
PRC - [2004/08/10 07:00:00 | 00,008,192 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\cidaemon.exe
PRC - [2009/04/21 23:09:25 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Michael\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2007/04/02 22:19:34 | 00,151,552 | —- | M] (Acronis) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe – (AcrSch2Svc [Auto | Running])
SRV - [2008/10/15 14:31:53 | 00,068,865 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe – (AntiVirScheduler [Auto | Running])
SRV - [2008/10/15 14:30:02 | 00,151,297 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe – (AntiVirService [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2005/12/15 14:14:40 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe – (ehRecvr [Auto | Running])
SRV - [2005/08/05 15:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe – (ehSched [Auto | Running])
SRV - [2006/05/01 11:20:52 | 00,114,753 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe – (EvtEng [Auto | Running])
SRV - [2007/10/09 12:58:12 | 00,036,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2007/04/02 21:10:19 | 00,138,168 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2004/08/10 07:00:00 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2007/10/11 09:55:10 | 00,864,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Running])
SRV - [2004/08/10 07:00:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe – (IISADMIN [Auto | Running])
SRV - [2008/11/23 19:18:54 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2005/03/09 20:50:18 | 00,018,944 | —- | M] (http://libusb-win32.sourceforge.net) – C:\WINDOWS\system32\libusbd-nt.exe – (libusbd [Auto | Running])
SRV - [2004/08/10 07:00:00 | 00,019,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\tcpsvcs.exe – (LPDSVC [On_Demand | Stopped])
SRV - [2005/08/05 15:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe – (McrdSvc [Auto | Running])
SRV - [2003/06/20 01:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE – (MDM [Auto | Running])
SRV - [2004/08/10 06:11:50 | 00,085,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mhn.dll – (MHN [On_Demand | Stopped])
SRV - [2004/08/10 07:00:00 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqsvc.exe – (MSMQ [Auto | Running])
SRV - [2004/08/10 07:00:00 | 00,117,248 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqtgsvc.exe – (MSMQTriggers [Auto | Running])
SRV - [2008/12/18 10:47:08 | 09,158,656 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe – (MSSQL$MICROSOFTSMLBIZ [Auto | Running])
SRV - [2005/05/04 00:50:28 | 00,073,728 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe – (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2007/10/11 09:55:14 | 00,122,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2006/09/08 17:41:46 | 00,380,928 | —- | M] (Dell Inc.) – C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe – (NICCONFIGSVC [Auto | Running])
SRV - [2009/02/16 20:39:00 | 02,736,890 | —- | M] (INCA Internet Co., Ltd.) – C:\WINDOWS\system32\GameMon.des – (npggsvc [On_Demand | Stopped])
SRV - [2007/08/02 12:33:50 | 00,080,528 | —- | M] (INCA Internet Co., Ltd.) – C:\Nexon\Mabinogi\npkcmsvc.exe – (npkcmsvc [Auto | Running])
SRV - [2006/05/01 02:46:00 | 00,143,428 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\nvsvc32.exe – (NVSvc [Auto | Running])
SRV - [2006/10/26 20:49:34 | 00,441,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE – (odserv [On_Demand | Stopped])
SRV - [2006/10/26 15:03:08 | 00,145,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2008/08/08 21:24:06 | 00,258,048 | —- | M] (KALiNKOsoft) – C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe – (PinnacleUpdateSvc [Auto | Stopped])
SRV - [2007/08/27 12:01:42 | 00,066,872 | —- | M] () – C:\WINDOWS\system32\PnkBstrA.exe – (PnkBstrA [Auto | Running])
SRV - [2006/05/01 11:20:26 | 00,217,164 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe – (RegSrvc [Auto | Running])
SRV - [2006/05/01 11:22:42 | 00,540,745 | —- | M] (Intel Corporation ) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe – (S24EventMonitor [Auto | Running])
SRV - [2004/08/10 07:00:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe – (SMTPSVC [Auto | Running])
SRV - [2006/11/20 04:42:45 | 00,033,280 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\snmp.exe – (SNMP [Auto | Running])
SRV - [2005/05/03 23:42:56 | 00,323,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE – (SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped])
SRV - File not found – – (ThreatFire [Auto | Stopped])
SRV - [2005/08/03 21:05:55 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wdfmgr.exe – (UMWdf [Auto | Running])
SRV - [2007/01/19 12:54:14 | 00,097,136 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc [On_Demand | Running])
SRV - [2008/08/25 10:02:58 | 00,076,800 | —- | M] () – C:\Program Files\VentSrv\ventrilo_svc.exe – (Ventrilo [Auto | Running])
SRV - [2007/01/04 17:38:08 | 00,024,652 | —- | M] (Viewpoint Corporation) – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service [Auto | Running])
SRV - [2004/08/10 07:00:00 | 00,015,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\inetsrv\inetinfo.exe – (W3SVC [Auto | Running])
SRV - [2006/05/01 11:34:00 | 00,262,217 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe – (WLANKEEPER [Auto | Running])
========== Driver Services (SafeList) ==========
DRV - [2007/01/25 03:23:47 | 00,021,275 | —- | M] (Meetinghouse Data Communications) – C:\WINDOWS\system32\DRIVERS\AegisP.sys – (AegisP [Auto | Running])
DRV - [2001/08/17 15:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2004/08/04 01:07:44 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2005/08/12 19:50:46 | 00,016,128 | —- | M] (Dell Inc) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS – (APPDRV [System | Running])
DRV - [2001/08/17 15:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2001/08/17 15:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [2007/02/27 15:25:01 | 00,011,840 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys – (avgio [System | Running])
DRV - [2008/05/20 16:29:41 | 00,052,032 | —- | M] (Avira GmbH) – C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys – (avgntflt [On_Demand | Running])
DRV - [2008/10/30 11:21:03 | 00,075,072 | —- | M] (Avira GmbH) – C:\WINDOWS\system32\DRIVERS\avipbb.sys – (avipbb [System | Running])
DRV - [2005/11/10 11:25:14 | 00,142,720 | —- | M] (Broadcom Corporation) – C:\WINDOWS\system32\DRIVERS\b57xp32.sys – (b57w2k [On_Demand | Running])
DRV - [2001/08/17 15:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 15:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2005/09/08 07:20:00 | 00,025,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS – (DLABOIOM [Auto | Running])
DRV - [2005/08/25 14:16:52 | 00,005,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS – (DLACDBHM [System | Running])
DRV - [2005/09/08 07:20:00 | 00,002,496 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLADResN.SYS – (DLADResN [Auto | Running])
DRV - [2005/09/08 07:20:00 | 00,086,524 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M [Auto | Running])
DRV - [2005/09/08 07:20:00 | 00,014,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM [Auto | Running])
DRV - [2005/09/08 07:20:00 | 00,006,364 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS – (DLAPoolM [Auto | Running])
DRV - [2005/08/25 14:16:16 | 00,022,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS – (DLARTL_N [System | Running])
DRV - [2005/09/08 07:20:00 | 00,094,332 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM [Auto | Running])
DRV - [2005/09/08 07:20:00 | 00,087,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M [Auto | Running])
DRV - [2005/09/12 05:30:00 | 00,089,264 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB [Boot | Running])
DRV - [2005/08/12 07:20:00 | 00,040,544 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS – (DRVNDDM [Auto | Running])
DRV - [2006/01/10 13:07:58 | 00,004,864 | —- | M] (GTek Technologies Ltd.) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys – (DSproct [On_Demand | Stopped])
DRV - [2001/08/17 14:12:10 | 00,117,760 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\e100b325.sys – (E100B [On_Demand | Stopped])
DRV - [2008/05/03 15:58:40 | 00,025,280 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\DRIVERS\hamachi.sys – (hamachi [On_Demand | Stopped])
DRV - [2004/08/12 19:45:54 | 00,137,728 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\system32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2005/12/01 02:40:56 | 00,936,960 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys – (HSF_DPV [On_Demand | Running])
DRV - [2005/12/01 02:40:12 | 00,192,512 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys – (HSXHWAZL [On_Demand | Running])
DRV - [2007/08/24 19:45:22 | 00,101,120 | R— | M] (Huawei Technologies Co., Ltd.) – C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys – (hwdatacard [On_Demand | Stopped])
DRV - [2005/03/09 20:50:16 | 00,033,792 | —- | M] () – C:\WINDOWS\system32\drivers\libusb0.sys – (libusb0 [On_Demand | Running])
DRV - [2005/10/04 23:57:08 | 00,012,544 | —- | M] (Conexant) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2007/07/06 06:05:47 | 00,072,960 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mqac.sys – (MQAC [On_Demand | Running])
DRV - [2001/08/17 15:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2006/05/01 02:46:00 | 03,653,280 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Running])
DRV - [2009/03/31 20:57:24 | 00,033,824 | —- | M] () – C:\WINDOWS\system32\drivers\oreans32.sys – (oreans32 [System | Running])
DRV - [2004/08/10 07:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2008/07/23 12:50:48 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 15:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 15:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 15:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2005/07/14 18:58:14 | 00,028,544 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimmptsk.sys – (rimmptsk [On_Demand | Running])
DRV - [2005/07/12 19:00:30 | 00,051,328 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rimsptsk.sys – (rimsptsk [On_Demand | Running])
DRV - [2005/07/14 17:28:38 | 00,307,968 | —- | M] (REDC) – C:\WINDOWS\system32\DRIVERS\rixdptsk.sys – (rismxdp [On_Demand | Running])
DRV - [2008/05/08 08:28:49 | 00,202,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\RMCast.sys – (RMCAST [On_Demand | Running])
DRV - [2006/05/01 11:52:02 | 00,013,568 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\DRIVERS\s24trans.sys – (s24trans [Auto | Running])
DRV - [2009/02/17 12:43:28 | 00,008,944 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS – (SASDIFSV [System | Running])
DRV - [2009/02/17 12:43:30 | 00,007,408 | R— | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS – (SASENUM [On_Demand | Running])
DRV - [2009/02/17 12:43:28 | 00,055,024 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys – (SASKUTIL [System | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2004/08/04 01:07:44 | 00,041,088 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2007/04/02 22:19:33 | 00,082,400 | —- | M] (Acronis) – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman [Boot | Running])
DRV - [2001/08/17 16:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2007/03/01 10:34:22 | 00,028,352 | —- | M] (Avira GmbH) – C:\WINDOWS\system32\DRIVERS\ssmdrv.sys – (ssmdrv [System | Running])
DRV - [2006/03/24 18:34:30 | 01,156,648 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\system32\drivers\sthda.sys – (STHDA [On_Demand | Running])
DRV - [2001/08/17 16:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2001/08/17 16:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2001/08/17 16:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 16:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2006/03/08 13:35:10 | 00,191,872 | —- | M] (Synaptics, Inc.) – C:\WINDOWS\system32\DRIVERS\SynTP.sys – (SynTP [On_Demand | Running])
DRV - [2007/04/02 22:19:33 | 00,028,896 | —- | M] (Acronis) – C:\WINDOWS\system32\DRIVERS\tifsfilt.sys – (tifsfilter [Auto | Running])
DRV - [2007/04/02 22:19:33 | 00,211,520 | —- | M] (Acronis) – C:\WINDOWS\system32\DRIVERS\timntr.sys – (timounter [Boot | Running])
DRV - [2001/08/17 15:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2004/08/03 23:07:56 | 00,059,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio [On_Demand | Stopped])
DRV - [2005/05/13 17:27:56 | 00,028,672 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\usbccid.sys – (USBCCID [On_Demand | Running])
DRV - [2006/04/26 18:13:04 | 01,429,632 | —- | M] (Intel® Corporation) – C:\WINDOWS\system32\DRIVERS\w39n51.sys – (w39n51 [On_Demand | Running])
DRV - [2005/12/01 02:40:08 | 00,669,696 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2006/10/13 18:48:24 | 00,050,048 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\xusb20.sys – (xusb20 [On_Demand | Stopped])
DRV - [2007/02/26 17:15:22 | 00,061,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\xusb21.sys – (xusb21 [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=6070125
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=6070125
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=6070125
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25c}:0.2.1.3
FF - prefs.js..extensions.enabledItems: {096fce39-df8c-49ad-a4ce-9ef4a875bb76}:2.3
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20090325
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/21 19:56:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/29 23:25:45 | 00,000,000 | —D | M]
[2009/01/19 19:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Extensions
[2009/01/19 19:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/20 21:43:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\c69znd8a.default\extensions
[2009/01/19 19:43:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\c69znd8a.default\extensions\{096fce39-df8c-49ad-a4ce-9ef4a875bb76}
[2009/04/16 18:33:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\c69znd8a.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/01/19 19:37:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\mozilla\Firefox\Profiles\c69znd8a.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25c}
[2009/01/19 19:31:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/29 23:25:45 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/29 23:25:37 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/29 23:25:37 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/03/19 22:21:08 | 00,036,864 | —- | M] (????) – C:\Program Files\mozilla firefox\components\NsThunderLoader.dll
[2008/12/02 04:04:40 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 04:04:40 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/02 04:04:40 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 04:04:40 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 04:04:40 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 04:04:40 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 04:04:40 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (WebThunder Browser Helper) - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll (Thunder Networking Technologies,LTD)
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {94C70A2D-68A1-4EC4-BDF5-7D28DFF73E7A} - Reg Error: Key error. File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {6E4E76A0-E99A-410F-B895-9F8DA72A4DAB} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Veoh Browser Plug-in) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {6E4E76A0-E99A-410F-B895-9F8DA72A4DAB} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {89FDCC4B-8D91-49B0-81A6-18BCFF582735} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" (Acronis)
O4 - HKLM..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" (Acronis)
O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup ()
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (Macrovision Corporation)
O4 - HKLM..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] "rundll32.exe" nvHotkey.dll,Start (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] "nwiz.exe" /installquiet ()
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" (Synaptics, Inc.)
O4 - HKLM..\Run: [WebThunder] C:\Program Files\Thunder Network\WebThunder\WebThunder.exe (?????????????)
O4 - HKLM..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (AOL LLC)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe ()
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [PlayNC Launcher] C:\program files\ncsoft\launcher\NCLauncher.exe /Minimized (NCSoft)
O4 - HKCU..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (Siber Systems)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide (Veoh Networks)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickSet.lnk = C:\Program Files\Dell\QuickSet\Quickset.exe (Dell Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Michael\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: ʹÓÃÍøÒ³Ñ¸À×ÏÂÔØ - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm ()
O8 - Extra context menu item: ʹÓÃÍøÒ³Ñ¸À×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm ()
O8 - Extra context menu item: ʹÓÃWebѸÀ×ÏÂÔØ - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm ()
O8 - Extra context menu item: ʹÓÃWebѸÀ×ÏÂÔØÈ«²¿Á´½Ó - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm ()
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html File not found
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Æô¶¯ÍøÒ³Ñ¸À× - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - File not found
O9 - Extra 'Tools' menuitem : Æô¶¯ÍøÒ³Ñ¸À× - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc…OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab (ijjiPlugin2 Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (Reg Error: Key error.)
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A}
http://www.acclaim.com/cabs/acclaim_v5.cab (GameLauncher Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jre…ows-i586-jc.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C}
http://dist.globalgamecdn.com/dist/neffy/NeffyLauncher.cab (NeffyLauncherCtl Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab (HGPlugin9USA Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - AppInit_DLLs: (tnrdmt.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\ssqNDsSI: DllName - ssqNDsSI.dll - File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\hgGvsrqq) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{018b040a-1016-11de-bdbb-00188bb6253a}\Shell - "" = AutoRun
O33 - MountPoints2\{018b040a-1016-11de-bdbb-00188bb6253a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{018b040a-1016-11de-bdbb-00188bb6253a}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{018b040b-1016-11de-bdbb-00188bb6253a}\Shell - "" = AutoRun
O33 - MountPoints2\{018b040b-1016-11de-bdbb-00188bb6253a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{018b040b-1016-11de-bdbb-00188bb6253a}\Shell\AutoRun\command - "" = F:\AutoRun.exe – File not found
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{375fac78-5231-11dd-8cfe-00188bb6253a}\Shell - "" = AutoRun
O33 - MountPoints2\{375fac78-5231-11dd-8cfe-00188bb6253a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{375fac78-5231-11dd-8cfe-00188bb6253a}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O33 - MountPoints2\{ef6f7ddf-0f4b-11de-bdba-00188bb6253a}\Shell - "" = AutoRun
O33 - MountPoints2\{ef6f7ddf-0f4b-11de-bdba-00188bb6253a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ef6f7ddf-0f4b-11de-bdba-00188bb6253a}\Shell\AutoRun\command - "" = E:\AutoRun.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\*.tmp files]
[2009/04/21 23:09:20 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Michael\Desktop\OTListIt2.exe
[2009/04/21 23:06:32 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/04/21 22:55:39 | 00,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2009/04/21 22:55:39 | 00,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2009/04/21 22:47:29 | 00,001,571 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Fiesta.lnk
[2009/04/21 22:47:29 | 00,000,000 | —D | C] – C:\Program Files\Outspark
[2009/04/21 19:56:17 | 00,001,615 | —- | C] () – C:\Documents and Settings\All Users\Desktop\ÍøÒ³Ñ¸À×2009.lnk
[2009/04/20 23:09:25 | 00,017,272 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2009/04/20 23:07:47 | 00,000,000 | —D | C] – C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
[2009/04/20 23:01:52 | 00,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2009/04/20 21:11:03 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/20 21:11:03 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/20 21:11:03 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/20 21:11:03 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/20 21:11:03 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/20 21:11:03 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/04/20 21:11:03 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/20 21:11:02 | 00,715,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/20 21:11:02 | 00,617,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/20 21:04:32 | 01,193,414 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/20 21:04:32 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/20 02:21:45 | 00,029,184 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Business with Germany.doc
[2009/04/20 00:01:23 | 00,020,992 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Business_in_Germany.doc
[2009/04/19 23:23:43 | 00,370,944 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Adrian - I Need You (Ringtone).mp3
[2009/04/16 21:46:22 | 00,482,304 | —- | C] () – C:\Documents and Settings\Michael\Desktop\The_Government_Enterprise.ppt
[2009/04/16 19:04:38 | 00,001,734 | —- | C] () – C:\Documents and Settings\Michael\Desktop\HijackThis.lnk
[2009/04/16 19:04:38 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/16 18:03:14 | 01,880,648 | —- | C] () – C:\Documents and Settings\Michael\Desktop\TeamViewer_Setup.exe
[2009/04/16 16:48:08 | 00,026,624 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Cheese String.doc
[2009/04/14 22:08:45 | 00,026,112 | —- | C] () – C:\Documents and Settings\Michael\Desktop\mrsfields.doc
[2009/04/13 14:21:44 | 00,463,360 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Les_Effets_de_Drogues.ppt
[2009/04/12 18:15:31 | 06,540,480 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Hip Hop Beat.mp3
[2009/04/12 18:12:48 | 05,456,064 | —- | C] () – C:\Documents and Settings\Michael\Desktop\R&B Beat.mp3
[2009/04/10 19:23:02 | 00,041,808 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2009/04/08 21:24:27 | 03,143,424 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Smooth R & B Beat New 2008.mp3
[2009/04/08 02:14:22 | 00,028,672 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Supersize Journal.doc
[2009/04/08 00:39:27 | 02,370,432 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Emotional R&B Beat.mp3
[2009/04/06 00:41:33 | 00,027,136 | —- | C] () – C:\Documents and Settings\Michael\My Documents\Effects of Closed Borders.doc
[2009/04/05 19:38:54 | 04,905,408 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Emotions.mp3
[2009/04/05 17:52:00 | 00,001,314 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Mabinogi Homepage.lnk
[2009/04/05 17:52:00 | 00,000,634 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Mabinogi.lnk
[2009/04/05 17:38:49 | 00,000,000 | –SD | C] – C:\Documents and Settings\Michael\My Documents\Mabinogi
[2009/04/05 16:57:30 | 12,494,93287 | —- | C] () – C:\Documents and Settings\Michael\Desktop\MabinogiSetup38R.exe
[2009/04/04 00:07:15 | 00,000,646 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Grand Chase.lnk
[2009/04/03 22:13:26 | 00,000,000 | —D | C] – C:\Program Files\Persona
[2009/04/03 02:19:36 | 00,060,928 | —- | C] () – C:\Documents and Settings\Michael\My Documents\Supersize_Me_minnie.doc
[2009/04/03 02:19:27 | 00,090,624 | —- | C] () – C:\Documents and Settings\Michael\My Documents\Supersize_Me.doc
[2009/04/03 01:12:13 | 02,798,976 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Emotional Beat.mp3
[2009/04/02 22:44:01 | 00,033,280 | —- | C] () – C:\Documents and Settings\Michael\My Documents\Magna_International.doc
[2009/04/02 21:36:14 | 00,037,376 | —- | C] () – C:\Documents and Settings\Michael\My Documents\RIM edit.doc
[2009/04/02 20:00:36 | 00,001,517 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Shin Megami Tensei Imagine Online.lnk
[2009/04/02 19:50:54 | 00,000,000 | —D | C] – C:\AeriaGames
[2009/04/02 17:00:02 | 00,001,116 | —- | C] () – C:\Documents and Settings\Michael\Desktop\Ether Saga Online.lnk
[2009/04/02 16:55:59 | 00,000,000 | —D | C] – C:\Program Files\Perfect World Entertainment
[2009/04/02 08:12:05 | 00,258,352 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\unicows.dll
[2009/04/01 20:59:58 | 21,458,69824 | -HS- | C] () – C:\hiberfil.sys
[2009/04/01 18:51:31 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/04/01 18:12:36 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\My Documents\Downloads
[2009/03/31 20:57:24 | 00,033,824 | —- | C] () – C:\WINDOWS\System32\drivers\oreans32.sys
[2009/03/31 20:48:42 | 00,000,000 | —D | C] – C:\Program Files\Servers-Extreme
[2009/03/30 21:28:49 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/30 21:28:49 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/30 21:28:47 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/30 21:28:45 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/29 20:15:30 | 00,001,751 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FreeStyle.lnk
[2009/03/29 20:15:28 | 00,000,143 | —- | C] () – C:\WINDOWS\GKLauncherInfo.ini
[2009/03/29 20:15:02 | 00,000,208 | —- | C] () – C:\WINDOWS\freestylegameInfo.xml
[2009/03/29 20:13:11 | 00,000,000 | —D | C] – C:\Program Files\GameKiss
[2009/03/29 17:25:41 | 08,098,304 | —- | C] () – C:\Documents and Settings\Michael\My Documents\Patrick_Roy.ppt
[2009/03/25 05:56:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\Desktop\Loops
[2009/03/25 05:51:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\Application Data\Sony
[2009/03/25 05:49:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\Application Data\Publish Providers
[2009/03/25 05:49:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\Application Data\NetMedia Providers
[2009/03/25 05:49:15 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\My Documents\ACID Xpress 7.0 Projects
[2009/03/25 05:48:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Michael\Local Settings\Application Data\Sony
[2009/03/25 05:48:00 | 00,001,746 | —- | C] () – C:\Documents and Settings\Michael\Desktop\ACID Xpress 7.0.lnk
[2009/03/25 05:47:26 | 00,000,000 | —D | C] – C:\Program Files\Sony
[2009/03/25 05:46:52 | 00,000,000 | —D | C] – C:\Program Files\Sony Setup
[2009/02/08 02:04:38 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/01/06 00:00:08 | 00,000,194 | —- | C] () – C:\WINDOWS\CS_MD_T.ini
[2008/12/13 17:57:58 | 00,616,720 | -HS- | C] () – C:\WINDOWS\System32\qqrsvGgh.ini2
[2008/12/13 17:57:57 | 00,616,720 | -HS- | C] () – C:\WINDOWS\System32\qqrsvGgh.ini
[2008/11/25 22:30:39 | 00,001,996 | —- | C] () – C:\WINDOWS\System32\msexcr.ini
[2008/08/17 12:16:22 | 00,033,792 | —- | C] () – C:\WINDOWS\System32\drivers\libusb0.sys
[2008/08/17 11:00:30 | 00,057,344 | —- | C] () – C:\WINDOWS\System32\ADsSecurity.dll
[2008/08/17 11:00:30 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\zlib.dll
[2008/08/17 11:00:30 | 00,036,864 | —- | C] () – C:\WINDOWS\System32\dxinputdll.dll
[2008/05/11 16:40:19 | 00,001,977 | —- | C] () – C:\WINDOWS\tabled32.ini
[2007/12/14 00:26:22 | 00,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2007/09/23 22:19:59 | 00,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2007/09/23 22:19:58 | 00,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2007/09/23 22:19:27 | 00,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2007/09/23 22:19:27 | 00,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2007/09/23 22:19:27 | 00,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2007/08/27 12:03:54 | 00,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/07/03 23:53:54 | 00,002,984 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/07/03 23:53:54 | 00,000,088 | RHS- | C] () – C:\WINDOWS\System32\F263B5C14D.sys
[2007/06/12 16:48:15 | 00,000,033 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2007/04/02 22:19:33 | 00,037,888 | —- | C] () – C:\WINDOWS\System32\setupnt.dll
[2007/01/25 03:44:32 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/01/25 03:37:25 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/01/25 03:33:19 | 00,000,214 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/01/25 03:00:11 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/01/25 03:00:01 | 01,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/01/25 03:00:01 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/01/25 03:00:01 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/01/25 03:00:00 | 01,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/01/25 02:59:58 | 00,098,304 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2007/01/25 02:59:04 | 00,000,492 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 03:56:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/16 06:37:24 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 06:18:43 | 00,000,552 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/16 06:18:41 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 16:01:54 | 00,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/04/21 23:09:25 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Michael\Desktop\OTListIt2.exe
[2009/04/21 23:06:45 | 00,524,580 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/21 23:06:45 | 00,101,280 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/21 23:06:44 | 00,638,182 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/21 23:06:14 | 00,000,576 | —- | M] () – C:\Documents and Settings\Michael\My Documents\My Sharing Folders.lnk
[2009/04/21 23:03:54 | 00,000,730 | —- | M] () – C:\WINDOWS\System32\cid_store.dat
[2009/04/21 23:02:49 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/04/21 23:02:38 | 00,050,868 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/04/21 23:02:37 | 00,039,187 | —- | M] () – C:\WINDOWS\System32\nvModes.001
[2009/04/21 23:01:24 | 00,000,298 | —- | M] () – C:\WINDOWS\tasks\pcxlycph.job
[2009/04/21 23:01:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/21 23:01:11 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/21 23:01:04 | 21,458,69824 | -HS- | M] () – C:\hiberfil.sys
[2009/04/21 22:47:29 | 00,001,571 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Fiesta.lnk
[2009/04/21 19:56:17 | 00,001,615 | —- | M] () – C:\Documents and Settings\All Users\Desktop\ÍøÒ³Ñ¸À×2009.lnk
[2009/04/21 00:52:24 | 00,300,440 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/20 23:09:27 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/20 02:21:45 | 00,029,184 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Business with Germany.doc
[2009/04/20 00:01:23 | 00,020,992 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Business_in_Germany.doc
[2009/04/19 23:26:21 | 00,370,944 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Adrian - I Need You (Ringtone).mp3
[2009/04/19 17:43:30 | 00,039,187 | —- | M] () – C:\WINDOWS\System32\nvModes.dat
[2009/04/17 01:19:51 | 00,482,304 | —- | M] () – C:\Documents and Settings\Michael\Desktop\The_Government_Enterprise.ppt
[2009/04/16 19:04:38 | 00,001,734 | —- | M] () – C:\Documents and Settings\Michael\Desktop\HijackThis.lnk
[2009/04/16 18:03:14 | 01,880,648 | —- | M] () – C:\Documents and Settings\Michael\Desktop\TeamViewer_Setup.exe
[2009/04/16 16:48:09 | 00,026,624 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Cheese String.doc
[2009/04/14 22:08:45 | 00,026,112 | —- | M] () – C:\Documents and Settings\Michael\Desktop\mrsfields.doc
[2009/04/13 14:21:47 | 00,463,360 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Les_Effets_de_Drogues.ppt
[2009/04/12 18:39:48 | 05,456,064 | —- | M] () – C:\Documents and Settings\Michael\Desktop\R&B Beat.mp3
[2009/04/12 18:15:43 | 06,540,480 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Hip Hop Beat.mp3
[2009/04/10 19:23:02 | 00,041,808 | —- | M] () – C:\WINDOWS\System32\xfcodec.dll
[2009/04/09 18:00:37 | 03,143,424 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Smooth R & B Beat New 2008.mp3
[2009/04/08 02:14:22 | 00,028,672 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Supersize Journal.doc
[2009/04/08 01:32:12 | 02,370,432 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Emotional R&B Beat.mp3
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 00:41:34 | 00,027,136 | —- | M] () – C:\Documents and Settings\Michael\My Documents\Effects of Closed Borders.doc
[2009/04/05 21:48:21 | 04,905,408 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Emotions.mp3
[2009/04/05 17:52:00 | 00,001,314 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Mabinogi Homepage.lnk
[2009/04/05 17:52:00 | 00,000,634 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Mabinogi.lnk
[2009/04/05 17:38:39 | 12,494,93287 | —- | M] () – C:\Documents and Settings\Michael\Desktop\MabinogiSetup38R.exe
[2009/04/05 11:53:00 | 02,646,112 | -H– | M] () – C:\Documents and Settings\Michael\Local Settings\Application Data\IconCache.db
[2009/04/04 00:07:15 | 00,000,646 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Grand Chase.lnk
[2009/04/03 02:45:44 | 00,090,624 | —- | M] () – C:\Documents and Settings\Michael\My Documents\Supersize_Me.doc
[2009/04/03 02:19:39 | 00,060,928 | —- | M] () – C:\Documents and Settings\Michael\My Documents\Supersize_Me_minnie.doc
[2009/04/03 02:15:44 | 00,033,280 | —- | M] () – C:\Documents and Settings\Michael\My Documents\Magna_International.doc
[2009/04/03 01:46:31 | 02,798,976 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Emotional Beat.mp3
[2009/04/02 21:48:32 | 00,037,376 | —- | M] () – C:\Documents and Settings\Michael\My Documents\RIM edit.doc
[2009/04/02 20:00:36 | 00,001,517 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Shin Megami Tensei Imagine Online.lnk
[2009/04/02 17:00:02 | 00,001,116 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Ether Saga Online.lnk
[2009/04/01 19:05:01 | 00,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/04/01 18:51:31 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/03/31 20:57:24 | 00,033,824 | —- | M] () – C:\WINDOWS\System32\drivers\oreans32.sys
[2009/03/30 21:28:49 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/29 22:57:00 | 00,002,039 | —- | M] () – C:\Documents and Settings\Michael\Desktop\Rakion.lnk
[2009/03/29 20:29:18 | 00,000,208 | —- | M] () – C:\WINDOWS\freestylegameInfo.xml
[2009/03/29 20:15:45 | 00,000,143 | —- | M] () – C:\WINDOWS\GKLauncherInfo.ini
[2009/03/29 20:15:30 | 00,001,751 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FreeStyle.lnk
[2009/03/29 17:25:41 | 08,098,304 | —- | M] () – C:\Documents and Settings\Michael\My Documents\Patrick_Roy.ppt
[2009/03/27 03:09:32 | 01,193,414 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/25 05:47:36 | 00,001,746 | —- | M] () – C:\Documents and Settings\Michael\Desktop\ACID Xpress 7.0.lnk
========== LOP Check ==========
[2009/03/04 02:18:55 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2007/01/25 03:35:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/12/31 15:46:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/12/31 15:47:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2009/03/02 00:55:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/02 00:43:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avira
[2008/03/31 20:28:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2007/01/25 03:29:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Corel
[2007/01/25 03:38:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/01/25 20:49:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2005/08/16 22:54:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2007/01/25 03:35:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2007/01/25 03:37:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/06/17 16:28:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HighAndes
[2007/01/25 03:34:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2007/01/25 03:23:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2009/03/01 17:55:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/03/02 00:21:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/01 19:39:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2007/04/02 21:20:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/12/21 01:29:43 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/04/20 23:09:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2007/10/27 12:15:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\mvcache
[2008/08/29 14:02:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2007/09/17 18:10:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2007/10/12 20:02:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2007/04/10 00:46:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NVIDIA
[2008/06/26 17:04:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Outspark
[2009/02/24 09:06:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2009/04/05 16:57:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/03/04 02:18:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2008/10/19 18:06:07 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2007/01/25 03:34:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sonic
[2009/03/02 00:38:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/01 19:37:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/08/27 11:49:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Thunder Network
[2008/02/02 15:12:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\thunder_dctemp
[2007/08/17 13:02:20 | 00,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\thunder_vod_cache
[2007/12/31 15:46:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/04/24 17:31:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vucache
[2007/04/02 21:33:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/11/15 18:19:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2008/11/23 20:00:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2008/11/23 20:04:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/03/25 05:51:29 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Michael\Application Data
[2007/12/31 15:56:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\acccore
[2007/04/02 22:23:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Acronis
[2007/06/17 19:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Adobe
[2007/09/19 21:38:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\AdobeUM
[2009/04/19 23:23:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Audacity
[2008/12/11 00:26:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Corel
[2007/04/02 22:34:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\CyberLink
[2009/04/21 23:03:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\DNA
[2009/04/02 00:52:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\GetRightToGo
[2007/04/03 22:56:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Google
[2007/01/25 03:37:59 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Michael\Application Data\Gtek
[2008/07/12 09:58:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Hamachi
[2007/04/20 23:29:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Help
[2008/06/17 16:28:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\HighAndes
[2005/08/16 06:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Identities
[2009/03/05 01:48:25 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Michael\Application Data\ijjigame
[2007/11/15 18:37:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\InstallShield
[2007/01/25 03:23:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Intel
[2008/08/17 12:12:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\KALiNKOsoft
[2008/04/16 20:45:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\LimeWire
[2007/08/28 18:21:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Macromedia
[2009/03/02 00:21:37 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Malwarebytes
[2009/02/12 02:19:58 | 00,000,000 | –SD | M] – C:\Documents and Settings\Michael\Application Data\Microsoft
[2009/01/19 19:31:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Mozilla
[2008/08/29 14:02:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\NCH Swift Sound
[2009/03/25 05:49:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\NetMedia Providers
[2007/11/07 17:49:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Nexon
[2007/12/01 12:40:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\NHN Corporation
[2009/03/04 02:19:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Propellerhead Software
[2009/03/25 05:49:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Publish Providers
[2008/06/19 20:31:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\QQ Games
[2008/06/19 18:58:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\QQ Games Plugin
[2008/05/14 23:16:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Secret of the Solstice
[2009/03/25 05:51:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Sony
[2007/08/20 18:37:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Sun
[2009/03/02 00:38:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\SUPERAntiSpyware.com
[2009/04/16 18:54:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\TeamViewer
[2008/12/20 20:49:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Tencent
[2008/12/15 19:21:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Twain
[2009/03/08 20:57:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\U3
[2009/02/08 20:27:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Ventrilo
[2009/01/16 17:06:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Viewpoint
[2009/04/19 14:46:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Xfire
[2008/11/23 19:59:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Michael\Application Data\Yahoo!
[2004/08/10 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/21 23:01:24 | 00,000,298 | —- | M] () – C:\WINDOWS\Tasks\pcxlycph.job
[2009/04/21 23:01:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 382 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
Here is the Extras.Txt
OTListIt Extras logfile created on: 4/21/2009 11:11:01 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Michael\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 66.36% Memory free
3.85 Gb Paging File | 3.20 Gb Available in Paging File | 83.14% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.36 Gb Total Space | 44.72 Gb Free Space | 31.41% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: M1710
Current User Name: Michael
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"57936:TCP" = 57936:TCP:*:Enabled:Pando Media Booster
"57936:UDP" = 57936:UDP:*:Enabled:Pando Media Booster
"58949:TCP" = 58949:TCP:*:Enabled:Pando Media Booster
"58949:UDP" = 58949:UDP:*:Enabled:Pando Media Booster
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2004/08/10 07:00:00 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing
[2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2008/08/17 12:41:14 | 00,286,720 | —- | M] () – C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel
File not found – C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
File not found – C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2006/08/22 17:32:18 | 00,184,320 | —- | M] (CyberLink Corp.) – C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program
[2006/10/10 08:44:50 | 00,557,568 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found – C:\sysreset\mirc.exe:*:Enabled:mIRC
File not found – C:\Program Files\NEXON\MapleStory\Patcher.exe:*:Enabled:Patcher MFC ?? ????
File not found – C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer
File not found – C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2009/03/04 23:48:04 | 01,400,832 | —- | M] (Softnyx) – C:\ijji\ENGLISH\Gunbound Revolution\GunBound.gme:*:Enabled:GunBound
File not found – C:\ijji\ENGLISH\Gunz\Gunz.exe:*:Enabled:Gunz
File not found – C:\Documents and Settings\Michael\Desktop\MMORPG\Server 1.4.2\server.exe:*:Enabled:server
[2009/04/10 19:22:58 | 03,111,248 | —- | M] (Xfire Inc.) – C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire
File not found – C:\Program Files\Bots\bots.dat:*:Enabled:Bout_d
File not found – C:\Program Files\NEXON\MapleStory\MapleStory.exe:*:Enabled:MapleStory
[2009/03/12 18:18:07 | 01,161,216 | —- | M] (Softnyx Co., Ltd.) – C:\Program Files\Softnyx\WolfTeam2\WolfTeam\Wolfteam.bin:*:Enabled:WolfTeam
[2004/08/10 07:00:00 | 00,004,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mqsvc.exe:*:Enabled:Message Queuing
[2008/07/24 10:15:46 | 00,159,744 | —- | M] (Nexon) – C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager
File not found – C:\Nexon\KartRider\NMService.exe:*:Enabled:Nexon Messenger Core
[2008/05/19 22:06:05 | 00,868,352 | —- | M] (NHN USA inc.) – C:\ijji\ENGLISH\u_gbound.exe:*:Enabled:
[2008/11/12 20:32:49 | 03,170,352 | —- | M] (Wizet) – C:\Nexon\MapleStory\MapleStory.exe:*:Enabled:MapleStory
[2007/01/19 12:54:56 | 05,674,352 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
[2007/01/04 16:10:02 | 00,297,752 | —- | M] (Microsoft Corporation) – C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[2007/12/11 13:33:31 | 00,765,952 | —- | M] (NHN USA inc.) – C:\ijji\ENGLISH\u_skid.exe:*:Enabled:
File not found – C:\Program Files\DriftCity\DriftCity.exe:*:Enabled:DriftCity
[2007/12/12 18:17:42 | 01,323,520 | —- | M] () – C:\ijji\ENGLISH\u_sf\soldierfront.exe:*:Enabled:soldierfront
File not found – C:\Program Files\LittleFighter2\LF2_v1.9c\lf2.exe:*:Enabled:lf2
[2008/12/18 20:39:24 | 00,393,216 | —- | M] () – C:\Program Files\Acclaim\2Moons\minilauncher.exe:*:Enabled:2moons
[2006/11/03 03:17:27 | 00,010,800 | —- | M] (AOL LLC) – C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
[2009/04/19 14:43:23 | 04,053,504 | —- | M] () – C:\Ntreev\Grand Chase\main.exe:*:Enabled:GrandChase
[2008/08/28 10:18:24 | 03,660,848 | —- | M] (Veoh Networks) – C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client
File not found – C:\Program Files\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility
[2008/08/17 12:41:14 | 00,286,720 | —- | M] () – C:\Program Files\NCsoft\Exteel\System\Exteel.exe:*:Enabled:Exteel
File not found – C:\Program Files\Codemasters\RF Online;\RF.exe:*:Enabled:RFLauncher
[2004/10/13 12:24:37 | 01,694,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found – C:\Rohan\rohanclient.exe:*:Enabled:Rohan Online Game
File not found – C:\TDDownload\SRO_NEW_Full-Client_Downloader.exe:*:Enabled:Full-Client Downloader
[2007/11/02 23:31:00 | 00,038,288 | —- | M] (Tencent America LLC) – C:\Program Files\Tencent\QQ Games\QQGames.exe:*:Enabled:QQ Games
[2007/12/18 15:04:17 | 00,050,528 | —- | M] (AOL LLC) – C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
[2008/05/27 18:31:30 | 00,868,352 | —- | M] (NHN USA inc.) – C:\ijji\ENGLISH\u_gunz.exe:*:Enabled:
[2008/05/27 18:31:16 | 00,868,352 | —- | M] (NHN USA inc.) – C:\ijji\ENGLISH\u_goonzu.exe:*:Enabled:
[2006/05/01 21:47:06 | 01,380,476 | —- | M] (None) – C:\Documents and Settings\Michael\Desktop\VisualBoyAdvance.exe:*:Enabled:VisualBoyAdvance emulator
File not found – C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
File not found – C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
[2008/08/06 03:02:28 | 03,243,816 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\Michael\temp\TeamViewer3\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application
File not found – C:\Program Files\Outspark\Project Powder\Run.exe:*:Enabled:ProjectPowder
File not found – C:\Program Files\NEXON\Mabinogi\Mabinogi.exe:*:Enabled:Mabinogi
[2009/01/21 13:36:33 | 00,342,848 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe:*:Enabled:DNA
[2008/11/05 22:59:00 | 04,347,120 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
File not found – C:\Program Files\uTorrent\uTorrent.exe:*:Disabled:µTorrent
File not found – C:\Documents and Settings\Michael\Local Settings\Temp\nso2CD.tmp\utorrent.exe:*:Disabled:µTorrent
[2007/12/12 23:56:18 | 12,829,216 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook
File not found – C:\Program Files\Savage 2 - A Tortured Soul\savage2.exe:*:Enabled:savage2
File not found – C:\Program Files\Softnyx\Rakion\NyxLauncher.exe:*:Enabled:NyxLauncher
[2009/04/17 20:30:27 | 01,442,816 | —- | M] () – C:\Program Files\Softnyx\RakionIS\Bin\rakion.bin:*:Enabled:rakion
[2009/03/23 06:22:06 | 04,054,312 | —- | M] (TeamViewer GmbH) – C:\Documents and Settings\Michael\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application
[2008/11/18 11:31:38 | 00,253,952 | —- | M] () – C:\Program Files\VentSrv\ventrilo_srv.exe:*:Enabled:ventrilo_srv
[2008/11/10 11:23:50 | 01,539,072 | —- | M] () – C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe
[2009/03/29 23:25:39 | 00,307,704 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
[2009/01/16 22:16:28 | 03,316,496 | —- | M] (Garena Interactive PTE LTD) – C:\Program Files\Garena\Garena.exe:*:Enabled:Garena
[2009/02/16 23:47:18 | 00,274,432 | —- | M] (Blizzard Entertainment) – C:\Program Files\Warcraft III\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne
[2009/02/16 23:47:19 | 00,274,432 | —- | M] (Blizzard Entertainment) – C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
[2009/02/16 23:47:20 | 00,069,632 | —- | M] (Blizzard Entertainment) – C:\Program Files\Warcraft III\World Editor.exe:*:Enabled:Warcraft III World Editor
[2009/01/19 19:09:28 | 00,139,343 | —- | M] (Siber Systems) – C:\Program Files\Siber Systems\AI RoboForm\passwordgenerator.exe:*:Enabled:Generate Passwords
[2009/02/16 23:47:37 | 00,397,312 | —- | M] () – C:\Program Files\Common Files\Blizzard Entertainment\Warcraft III\Uninstall.exe:*:Enabled:Warcraft III Uninstall
[2008/04/30 09:58:24 | 00,075,072 | —- | M] (Kaspersky Lab) – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\german\setup.exe:*:Enabled:Installationsprogramm für Kaspersky Anti-Virus 2009
File not found – C:\Program Files\Kaspersky\setup.exe:*:Enabled:Installationsprogramm für Kaspersky Anti-Virus 2009
[2009/03/02 09:06:01 | 01,403,904 | —- | M] () – C:\Program Files\Softnyx\RakionIS-bdrs\Bin\rakion.bin:*:Enabled:rakion
File not found – C:\Documents and Settings\Michael\Desktop\CyberStep\SplashFightersIjji\amped.exe:*:Enabled:amped
[2009/02/13 08:18:34 | 01,353,224 | —- | M] (CDNetworks Co.,Ltd) – C:\Program Files\Persona\Persona.exe:*:Enabled:Persona
[2009/04/05 16:55:53 | 02,906,440 | —- | M] () – C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster
[2009/02/28 00:54:41 | 00,636,072 | —- | M] (Microsoft Corporation) – C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer
[2009/04/19 23:03:24 | 00,742,816 | —- | M] (?????????????) – C:\Program Files\Thunder Network\WebThunder\WebThunder.exe:*:Enabled:WebThunder
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00D15456-F679-4AD4-8BD2-56450D4C3F72}" = WarRock
"{02A17452-B723-4A32-88A4-E1A1C9CCF1E8}" = MapleStory
"{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{075473F5-846A-448B-BCB3-104AA1760205}" = Roxio RecordNow Data
"{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}" = Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB03}" = La Tale
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Roxio DLA
"{1C4C5C53-D960-4E1C-96A6-F6B52EA43A45}" = ACID Xpress 7.0
"{1D46A3A0-B37D-423A-91C2-101A49E2FF80}" = Ventrilo Server
"{1DCC7418-2089-4BDD-B321-3771956160FC}" = ijji Auto Installer
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Roxio MyDVD LE
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 10
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Advanced Control Suite
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}" = Microsoft SQL Server Compact 3.5 Design Tools ENU
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{311EBF70-9282-41D1-BAB0-AD22220301B9}" = 3Dカスタム少女
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{49BF48CC-ABB6-4795-9B35-B5DE005D8612}" = Pinnacle Game Profiler
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = PlayNC Launcher
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{688E07FE-9832-4FB9-8666-FB198D86ADC6}" = 2MOONS
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6E4E76A0-E99A-410F-B895-9F8DA72A4DAB}" = Mirar
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7ADE3A47-B425-45E9-8FF6-11BE2B775645}" = Corel Snapfire Plus
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{842FAF7C-50EF-4463-9B8F-6222E1384D7D}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
"{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}" = Garena
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{9275098D-F695-4248-8D14-C22AD04B6CC9}" = AsdaStory
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{961346DF-FE43-4392-99FC-47B1F5A882C3}" = GKLauncher
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{9E05BFA2-9B4E-43E4-A51E-B9E690AE0E94}" = Exteel
"{A2556818-D48A-42C4-B976-D89567725845}" = Fiesta
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Roxio RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-A70800000002}" = Adobe Reader 7.0.8
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Roxio RecordNow Copy
"{B4C0A315-07FB-39F9-85CD-8CE20C019350}" = Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B5560986-7A6A-4CCA-A808-853D2CED3796}" = Outspark Sharp Launcher
"{BA68600E-96D9-4E92-80F2-26B9681B5A63}" = Microsoft Office Outlook 2003 with Business Contact Manager Update
"{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}" = Microsoft SQL Server Compact 3.5 ENU
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
"{E127B28D-1A2A-45C4-A74E-C817E0A74E3E}" = Fiesta
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"adspipe" = Browser Optimizer AlmightyAds
"Aim Plugin for QQ Games" = Aim Plugin for QQ Games
"AIM_6" = AIM 6
"AntiVir PersonalEdition Classic" = Avira AntiVir Personal - Free Antivirus
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.5 (Unicode)
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CABAL Online_is1" = CABAL Online
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ESPNMotion" = ESPNMotion
"Fraps" = Fraps
"GoldWave v5.14" = GoldWave v5.14
"Google Desktop" = Google Desktop
"Grand Chase" = Grand Chase
"Guild Wars" = Guild Wars
"Gunbound Revolution_is1" = Gunbound Revolution
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{0405E51E-9582-4207-8F38-AC44201D3808}" = VeohTV BETA
"LibUSB-Win32_is1" = LibUSB-Win32-0.1.10.1
"Mabinogi" = Mabinogi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"Mobile Partner" = Mobile Partner
"Mozilla Firefox (3.0.8)" = Mozilla Firefox (3.0.8)
"Neffy" = Neffy 1,2,0,12
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"p2psoft" = p2psoft.biz Browser Optimizer
"Persona" = Hybrid Downloader 1,0,2,6
"PRO" = Microsoft Office Professional 2007
"ProInst" = Intel® PROSet/Wireless Software
"QQ Bubble Arena" = QQ Bubble Arena
"QQ Chess" = QQ Chess
"QQ Games" = QQ Games
"QQ Hearts" = QQ Hearts
"QQ Match Master" = QQ Match Master
"QQ Pool" = QQ Pool
"QQ Texas Hold'em" = QQ Texas Hold'em
"QQ Treasure Hunter" = QQ Treasure Hunter
"Ragnarok Sakray" = Ragnarok Sakray
"Rakion International_is1" = Rakion International
"RumbleFighter" = Rumble Fighter
"Shin Megami Tensei: Imagine Online" = Shin Megami Tensei: Imagine Online
"StepMania" = StepMania (remove only)
"Super Card_is1" = SC Ver 2.68
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TrueImage" = Acronis True Image
"ViewpointMediaPlayer" = Viewpoint Media Player
"Warcraft III" = Warcraft III
"WavePad" = WavePad Sound Editor
"Wdf01001" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
"WebThunder" = ÍøÒ³Ñ¸À×2009
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinRAR archiver" = WinRAR archiver
"WolfTeam International_is1" = WolfTeam International
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"AI RoboForm" = AI RoboForm
"BitTorrent DNA" = DNA
"ijji.com" = ijji
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/4/2009 4:22:28 PM | Computer Name = M1710 | Source = Application Error | ID = 1000
Description = Faulting application xfire.exe, version 1.0.0.13133, faulting module
msvcr71.dll, version 7.10.3052.4, fault address 0x00002f30.
Error - 4/5/2009 11:47:02 PM | Computer Name = M1710 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/5/2009 11:47:04 PM | Computer Name = M1710 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/7/2009 12:11:16 AM | Computer Name = M1710 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16762, faulting
module unknown, version 0.0.0.0, fault address 0x05740f26.
Error - 4/12/2009 12:35:44 AM | Computer Name = M1710 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16762, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/12/2009 12:38:55 AM | Computer Name = M1710 | Source = Application Hang | ID = 1002
Description = Hanging application WebThunder.exe, version 1.13.1.224, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/12/2009 12:38:57 AM | Computer Name = M1710 | Source = Application Hang | ID = 1002
Description = Hanging application WebThunder.exe, version 1.13.1.224, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 4/13/2009 10:00:02 PM | Computer Name = M1710 | Source = Application Error | ID = 1000
Description = Faulting application rumblefighter.exe, version 0.9.0.0, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.
Error - 4/16/2009 4:47:48 PM | Computer Name = M1710 | Source = Microsoft Office 12 | ID = 1000
Description = Faulting application winword.exe, version 12.0.4518.1014, stamp 45428028,
faulting module mso.dll, version 12.0.4518.1014, stamp 4542867b, debug? 0, fault
address 0x00657524.
Error - 4/19/2009 2:43:41 PM | Computer Name = M1710 | Source = Application Error | ID = 1000
Description = Faulting application rumblefighter.exe, version 0.9.0.0, faulting
module rumblefighter.exe, version 0.9.0.0, fault address 0x00130aec.
[ OSession Events ]
Error - 4/16/2009 4:47:45 PM | Computer Name = M1710 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 51
seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 4/20/2009 8:57:16 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 4/20/2009 8:57:17 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly. It has
done this 1 time(s).
Error - 4/21/2009 12:52:50 AM | Computer Name = M1710 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2
Error - 4/21/2009 12:52:50 AM | Computer Name = M1710 | Source = Service Control Manager | ID = 7000
Description = The ThreatFire service failed to start due to the following error:
%%2
Error - 4/21/2009 12:52:50 AM | Computer Name = M1710 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 4/21/2009 12:52:50 AM | Computer Name = M1710 | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly. It has
done this 1 time(s).
Error - 4/21/2009 11:02:14 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7000
Description = The npkcrypt service failed to start due to the following error: %%2
Error - 4/21/2009 11:02:14 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7000
Description = The ThreatFire service failed to start due to the following error:
%%2
Error - 4/21/2009 11:02:14 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
TfFsMon TfSysMon
Error - 4/21/2009 11:02:14 PM | Computer Name = M1710 | Source = Service Control Manager | ID = 7034
Description = The PinnacleUpdate Service service terminated unexpectedly. It has
done this 1 time(s).
< End of report >