This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need to clean up this system

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So, I've cleaned up a lot of the stuff, but would like help cleaning the rest so hopefully I don't have to do a OS reinstall. Thanks in advance for your help!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:04 AM, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\WINDOWS\system32\UMonit.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\mshta.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpCtr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: WinSafe Class - {b6b571fb-b71d-449c-ad70-82e966328795} - C:\WINDOWS\iehost.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237321197109
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 1: (no name) - http://www.themastersofthesecret.com/course/login/

–
End of file - 10284 bytes
All I can see at the moment is a remnant of pakes. What problems are you experiencing ?

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Thanks Essesxboy.

Last night I couldn't get City of Heroes to run after running all day with no problems. Had made no changes, etc. As part of trying to fix this, I was posting HijackThis and CoHHelper to the forums. Eventually I got it running, not sure what the problem was.

In looking at the HJT report, I realized there was a lot of spyware, toolbar carp - things that aren't even on the toolbar, and links to files that I don't even have on the computer anymore, such as Cyberdefender.

My immedate goal right now: clean up my system to get it running optimally, and without spyware and hijacking my browsers.

Here's a new HJT report after doing what was required BEFORE I posted the original post, as well as the OTS report you requested. MBAM report follows.

I'm also uploading, in case that helps you help me :)
-Bliss

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:00 PM, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\WINDOWS\system32\UMonit.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\OTS.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo2.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237321197109
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 1: (no name) - http://www.themastersofthesecret.com/course/login/

–
End of file - 9923 bytes

OTS logfile created on: 6/15/2009 11:40:55 AM - Run 1
OTS by OldTimer - Version 3.0.5.3	 Folder = C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 262.89 Gb Free Space | 88.19% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 149.05 Gb Total Space | 81.85 Gb Free Space | 54.92% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: SHERRI-78C7B973
Current User Name: MISSY's GAMER
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
apache.exe -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -> [2006/02/07 01:13:32 | 00,020,543 | —- | M] (Apache Software Foundation)
apache.exe -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -> [2006/02/07 01:13:32 | 00,020,543 | —- | M] (Apache Software Foundation)
applemobiledeviceservice.exe -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 11:48:14 | 00,144,712 | —- | M] (Apple Inc.)
ashdisp.exe -> C:\Program Files\Alwil Software\Avast4\ashDisp.exe -> [2009/02/05 13:08:45 | 00,081,000 | —- | M] (ALWIL Software)
ashmaisv.exe -> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -> [2009/02/05 13:08:26 | 00,254,040 | —- | M] (ALWIL Software)
ashserv.exe -> C:\Program Files\Alwil Software\Avast4\ashServ.exe -> [2009/02/05 13:08:40 | 00,138,680 | —- | M] (ALWIL Software)
ashwebsv.exe -> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -> [2009/02/05 13:06:04 | 00,352,920 | —- | M] (ALWIL Software)
aswupdsv.exe -> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -> [2009/02/05 13:01:25 | 00,018,752 | —- | M] (ALWIL Software)
btwdins.exe -> C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe -> [2006/04/12 10:29:30 | 00,266,295 | —- | M] (Broadcom Corporation.)
cthelper.exe -> C:\WINDOWS\CTHELPER.EXE -> [2006/06/01 11:34:56 | 00,017,920 | —- | M] (Creative Technology Ltd)
ctxfihlp.exe -> C:\WINDOWS\System32\CTXFIHLP.EXE -> [2006/06/01 11:34:58 | 00,018,944 | —- | M] (Creative Technology Ltd)
ctxfispi.exe -> C:\WINDOWS\System32\CTXFISPI.EXE -> [2006/06/01 11:29:38 | 00,729,600 | —- | M] (Creative Technology Ltd)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/13 17:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
hijackthis.exe -> C:\Program Files\Trend Micro\HijackThis\HijackThis.exe -> [2009/06/14 17:01:16 | 00,396,288 | —- | M] (Trend Micro Inc.)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation)
iexplore.exe -> C:\Program Files\Internet Explorer\IEXPLORE.EXE -> [2009/03/08 14:09:26 | 00,638,816 | —- | M] (Microsoft Corporation)
ipodservice.exe -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 13:39:14 | 00,541,992 | —- | M] (Apple Inc.)
ituneshelper.exe -> C:\Program Files\iTunes\iTunesHelper.exe -> [2009/06/05 13:39:22 | 00,292,136 | —- | M] (Apple Inc.)
j2gdllcmd.exe -> C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe -> [2007/03/06 10:21:31 | 00,116,224 | —- | M] (j2 Global Communications, Inc.)
jqs.exe -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009/05/21 11:34:05 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
jusched.exe -> C:\Program Files\Java\jre6\bin\jusched.exe -> [2009/05/21 11:34:07 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
lcdclock.exe -> C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe -> [2006/03/06 15:16:12 | 00,198,656 | —- | M] (Logitech Inc.)
lcdcountdown.exe -> C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe -> [2006/03/06 15:16:48 | 00,378,880 | —- | M] (Logitech Inc.)
lcdmedia.exe -> C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe -> [2006/03/06 15:15:42 | 00,289,792 | —- | M] (Logitech Inc.)
lcdmon.exe -> C:\Program Files\Logitech\G-series Software\LCDMon.exe -> [2006/03/06 15:14:58 | 00,497,152 | —- | M] (Logitech Inc.)
lcdpop3.exe -> C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe -> [2006/03/06 15:17:24 | 00,307,200 | —- | M] (Logitech Inc.)
lgdcore.exe -> C:\Program Files\Logitech\G-series Software\LGDCore.exe -> [2006/03/06 15:31:52 | 01,122,304 | —- | M] (Logitech Inc.)
lxrsii1s.exe -> C:\WINDOWS\System32\LxrSII1s.exe -> [2005/05/19 15:48:34 | 00,053,248 | —- | M] ()
nsvcappflt.exe -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe -> [2006/03/30 15:58:14 | 00,143,360 | —- | M] ()
nsvcip.exe -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -> [2006/03/30 15:54:48 | 00,131,131 | —- | M] (NVIDIA Corporation)
nsvclog.exe -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -> [2006/03/30 15:54:18 | 00,065,599 | —- | M] (NVIDIA Corporation)
nvsvc32.exe -> C:\WINDOWS\System32\nvsvc32.exe -> [2009/05/01 00:30:18 | 00,168,004 | —- | M] (NVIDIA Corporation)
ots.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\OTS.exe -> [2009/06/15 11:39:14 | 00,507,392 | —- | M] (OldTimer Tools)
umonit.exe -> C:\WINDOWS\System32\UMonit.exe -> [2006/11/15 19:47:18 | 00,200,704 | R— | M] ()
 
[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2009/06/05 11:48:14 | 00,144,712 | —- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2008/07/25 12:16:40 | 00,034,312 | —- | M] (Microsoft Corporation)
(aswUpdSv) avast! iAVS4 Control Service [Win32_Own | Auto | Running] -> C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -> [2009/02/05 13:01:25 | 00,018,752 | —- | M] (ALWIL Software)
(avast! Antivirus) avast! Antivirus [Win32_Own | Auto | Running] -> C:\Program Files\Alwil Software\Avast4\ashServ.exe -> [2009/02/05 13:08:40 | 00,138,680 | —- | M] (ALWIL Software)
(avast! Mail Scanner) avast! Mail Scanner [Win32_Own | On_Demand | Running] -> C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -> [2009/02/05 13:08:26 | 00,254,040 | —- | M] (ALWIL Software)
(avast! Web Scanner) avast! Web Scanner [Win32_Own | On_Demand | Running] -> C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -> [2009/02/05 13:06:04 | 00,352,920 | —- | M] (ALWIL Software)
(btwdins) Bluetooth Service [Win32_Own | Auto | Running] -> C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe -> [2006/04/12 10:29:30 | 00,266,295 | —- | M] (Broadcom Corporation.)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2008/07/25 12:17:02 | 00,069,632 | —- | M] (Microsoft Corporation)
(Creative Audio Engine Licensing Service) Creative Audio Engine Licensing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -> [2009/01/12 16:45:35 | 00,079,360 | —- | M] (Creative Labs)
(FontCache3.0.0.0) Windows Presentation Foundation Font Cache 3.0.0.0 [Win32_Own | On_Demand | Stopped] -> c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -> [2008/07/29 22:10:04 | 00,046,104 | —- | M] (Microsoft Corporation)
(ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM) [Win32_Own | Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe -> [2006/03/30 15:58:14 | 00,143,360 | —- | M] ()
(ForcewareWebInterface) Forceware Web Interface [Win32_Own | Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe -> [2006/02/07 01:13:32 | 00,020,543 | —- | M] (Apache Software Foundation)
(gusvc) Google Software Updater [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -> [2009/03/25 05:10:48 | 00,183,280 | —- | M] (Google)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 17:12:02 | 00,038,400 | —- | M] (Microsoft Corporation)
(idsvc) Windows CardSpace [Win32_Shared | Unknown | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -> [2008/07/29 20:24:50 | 00,881,664 | —- | M] (Microsoft Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> C:\Program Files\iPod\bin\iPodService.exe -> [2009/06/05 13:39:14 | 00,541,992 | —- | M] (Apple Inc.)
(JavaQuickStarterService) Java Quick Starter [Win32_Own | Auto | Running] -> C:\Program Files\Java\jre6\bin\jqs.exe -> [2009/05/21 11:34:05 | 00,152,984 | —- | M] (Sun Microsystems, Inc.)
(LBTServ) Logitech Bluetooth Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -> [2008/05/02 02:42:06 | 00,121,360 | —- | M] (Logitech, Inc.)
(LxrSII1s) Lexar Secure II [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\LxrSII1s.exe -> [2005/05/19 15:48:34 | 00,053,248 | —- | M] ()
(NetTcpPortSharing) Net.Tcp Port Sharing Service [Win32_Shared | Disabled | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -> [2008/07/29 20:16:38 | 00,132,096 | —- | M] (Microsoft Corporation)
(nSvcIp) ForceWare IP service [Win32_Own | Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe -> [2006/03/30 15:54:48 | 00,131,131 | —- | M] (NVIDIA Corporation)
(nSvcLog) ForceWare user log service [Win32_Own | Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe -> [2006/03/30 15:54:18 | 00,065,599 | —- | M] (NVIDIA Corporation)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\nvsvc32.exe -> [2009/05/01 00:30:18 | 00,168,004 | —- | M] (NVIDIA Corporation)
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\System32\HPZipm12.exe -> [2003/03/09 21:31:02 | 00,065,795 | —- | M] (HP)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Windows Media Player\WMPNetwk.exe -> [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
(Aavmker4) avast! Asynchronous Virus Monitor [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\aavmker4.sys -> [2009/02/05 13:05:11 | 00,026,944 | —- | M] (ALWIL Software)
(Afc) PPdus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\Afc.sys -> [2005/02/23 15:58:56 | 00,011,776 | —- | M] (Arcsoft, Inc.)
(aswFsBlk) aswFsBlk [File_System | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\aswFsBlk.sys -> [2009/02/05 13:07:12 | 00,020,560 | —- | M] (ALWIL Software)
(aswMon2) avast! Standard Shield Support [File_System | Auto | Running] -> C:\WINDOWS\System32\drivers\aswmon2.sys -> [2009/02/05 13:08:10 | 00,094,032 | —- | M] (ALWIL Software)
(aswRdr) aswRdr [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\aswRdr.sys -> [2009/02/05 13:06:10 | 00,023,152 | —- | M] (ALWIL Software)
(aswSP) avast! Self Protection [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\aswSP.sys -> [2009/02/05 13:07:23 | 00,114,768 | —- | M] (ALWIL Software)
(aswTdi) avast! Network Shield Support [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\aswTdi.sys -> [2009/02/05 13:06:20 | 00,051,376 | —- | M] (ALWIL Software)
(btaudio) Bluetooth Audio Device [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\btaudio.sys -> [2006/04/12 10:14:50 | 00,329,837 | —- | M] (Broadcom Corporation.)
(BTDriver) Bluetooth Virtual Communications Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\btport.sys -> [2006/04/12 10:05:48 | 00,030,427 | —- | M] (Broadcom Corporation.)
(BTKRNL) Bluetooth Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\btkrnl.sys -> [2006/04/12 10:09:32 | 00,854,538 | —- | M] (Broadcom Corporation.)
(BTSERIAL) Bluetooth Serial Driver [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\btserial.sys -> [2006/04/12 10:11:36 | 00,023,271 | —- | M] (Broadcom Corporation.)
(BTSLBCSP) Bluetooth Port Client Driver [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\btslbcsp.sys -> [2006/04/12 10:11:22 | 00,222,876 | —- | M] (Broadcom Corporation.)
(BTWDNDIS) Bluetooth LAN Access Server [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\btwdndis.sys -> [2006/04/12 10:02:14 | 00,148,932 | —- | M] (Broadcom Corporation.)
(btwmodem) Bluetooth Modem [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\btwmodem.sys -> [2006/04/12 10:05:32 | 00,030,285 | —- | M] (Broadcom Corporation.)
(BTWUSB) WIDCOMM USB Bluetooth Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\btwusb.sys -> [2006/04/12 10:04:46 | 00,065,784 | —- | M] (Broadcom Corporation.)
(ctac32k) Creative AC3 Software Decoder [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ctac32k.sys -> [2006/06/01 11:18:08 | 00,502,272 | —- | M] (Creative Technology Ltd)
(ctaud2k) Creative Audio Driver (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ctaud2k.sys -> [2006/06/01 11:19:00 | 00,499,584 | —- | M] (Creative Technology Ltd)
(ctdvda2k) Creative DVD-Audio Device Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\ctdvda2k.sys -> [2005/11/10 17:06:04 | 00,340,704 | —- | M] (Creative Technology Ltd)
(ctprxy2k) Creative Proxy Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ctprxy2k.sys -> [2006/06/01 11:19:00 | 00,007,168 | —- | M] (Creative Technology Ltd)
(ctsfm2k) Creative SoundFont Management Device Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ctsfm2k.sys -> [2006/06/01 11:18:14 | 00,143,872 | —- | M] (Creative Technology Ltd)
(emupia) E-mu Plug-in Architecture Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\emupia2k.sys -> [2006/06/01 11:18:12 | 00,078,336 | —- | M] (Creative Technology Ltd)
(FIXUSTOR) FIXUSTOR [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\fixustor.sys -> [2006/11/07 17:36:02 | 00,012,672 | R— | M] (Genesys Logic)
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -> [2009/03/19 16:32:48 | 00,023,400 | —- | M] (GEAR Software Inc.)
(giveio) giveio [Kernel | Boot | Running] -> C:\WINDOWS\system32\giveio.sys -> [1996/04/03 12:33:26 | 00,005,248 | —- | M] ()
(GVCplDrv) GVCplDrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\GVCplDrv.sys -> [2006/08/15 23:25:30 | 00,016,899 | R— | M] ()
(ha20x2k) Creative 20X HAL Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ha20x2k.sys -> [2006/06/01 11:18:46 | 01,107,968 | —- | M] (Creative Technology Ltd)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -> [2008/04/13 09:36:05 | 00,144,384 | —- | M] (Windows (R) Server 2003 DDK provider)
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HPZid412.sys -> [2003/03/09 21:31:00 | 00,051,024 | —- | M] (HP)
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HPZipr12.sys -> [2003/03/09 21:31:02 | 00,016,080 | —- | M] (HP)
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HPZius12.sys -> [2003/03/09 21:31:02 | 00,021,456 | —- | M] (HP)
(LBeepKE) LBeepKE [Kernel | Auto | Running] -> C:\WINDOWS\System32\Drivers\LBeepKE.sys -> [2006/06/30 00:53:44 | 00,003,712 | —- | M] (Logitech, Inc.)
(LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LHidFilt.Sys -> [2008/02/29 03:13:16 | 00,035,344 | —- | M] (Logitech, Inc.)
(LHidKe) Logitech SetPoint HID Mouse Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\LHidKE.Sys -> [2006/05/10 09:56:54 | 00,027,264 | —- | M] (Logitech, Inc.)
(LMouFilt) Logitech SetPoint KMDF Mouse Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LMouFilt.Sys -> [2008/02/29 03:13:24 | 00,036,880 | —- | M] (Logitech, Inc.)
(LMouKE) Logitech SetPoint Mouse Filter Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\LMouKE.Sys -> [2006/05/10 09:56:50 | 00,071,680 | —- | M] (Logitech, Inc.)
(LUsbFilt) Logitech SetPoint KMDF USB Filter [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\LUsbFilt.Sys -> [2008/02/29 03:13:46 | 00,028,944 | —- | M] (Logitech, Inc.)
(LxrSII1d) Secure II Driver [Kernel | Auto | Running] -> C:\WINDOWS\System32\Drivers\LxrSII1d.sys -> [2005/05/19 15:48:24 | 00,070,016 | —- | M] ()
(MTsensor) ATK0110 ACPI UTILITY [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ASACPI.sys -> [2004/08/12 19:56:20 | 00,005,810 | R— | M] ()
(nv) nv [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2009/04/30 22:02:00 | 08,055,584 | —- | M] (NVIDIA Corporation)
(nvata) nvata [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\nvata.sys -> [2006/04/24 02:52:28 | 00,100,736 | R— | M] (NVIDIA Corporation)
(NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\NVENETFD.sys -> [2006/03/21 23:24:00 | 00,052,736 | R— | M] (NVIDIA Corporation)
(nvnetbus) NVIDIA Network Bus Enumerator [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\nvnetbus.sys -> [2006/03/21 23:24:02 | 00,018,944 | R— | M] (NVIDIA Corporation)
(NVTCP) NVIDIA TCP/IP Protocol Driver [Kernel | System | Running] -> C:\WINDOWS\System32\DRIVERS\NVTcp.sys -> [2006/03/21 23:23:50 | 00,109,568 | —- | M] (NVIDIA Corporation)
(ossrv) Creative OS Services Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\ctoss2k.sys -> [2006/06/01 11:18:20 | 00,116,224 | —- | M] (Creative Technology Ltd.)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2006/02/28 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> C:\WINDOWS\System32\Drivers\PxHelp20.sys -> [2008/11/20 12:19:06 | 00,043,872 | —- | M] (Sonic Solutions)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 03:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(speedfan) speedfan [Kernel | Boot | Running] -> C:\WINDOWS\system32\speedfan.sys -> [2005/06/15 07:55:53 | 00,004,096 | —- | M] (Windows (R) 2000 DDK provider)
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\usbaapl.sys -> [2008/10/01 13:01:28 | 00,032,000 | —- | M] (Apple, Inc.)
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\usbaudio.sys -> [2008/04/13 11:45:12 | 00,060,032 | —- | M] (Microsoft Corporation)
 
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" ->  [binary data] -> 
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\"CustomSearch" -> http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html -> 
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Main\\"Default_Search_URL" -> http://www.google.com/ie -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Main\\"Page_Transitions" -> 1 -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Main\\"Search Page" -> http://www.google.com -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Main\\"Start Page" -> about:blank -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Search\\"Default_Search_URL" -> http://www.google.com/ie -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: Search\\"SearchAssistant" -> http://www.google.com/ie -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: SearchURL\\"" -> http://www.google.com/search?q=%s -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\: "ProxyEnable" -> 0 -> 
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Mozilla\FireFox\Profiles\oqezf7k9.default\prefs.js -> 
extensions.enabledItems -> [removed]:1.0 ->
extensions.enabledItems -> {20a82645-c095-46ed-80e3-08825760534b}:1.0 ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.6 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b} -> C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION [C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\] -> [2009/02/06 14:35:03 | 00,000,000 | —D | M]
HKLM\software\mozilla\Firefox\Extensions\\[removed] -> C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF] -> [2009/03/23 06:30:20 | 00,000,000 | —D | M]
< FireFox Extensions [User Folders] > -> 
 -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\mozilla\Extensions -> [2009/02/28 16:06:13 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2009/02/28 16:06:13 | 00,000,000 | —D | M]
 -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\mozilla\Firefox\Profiles\oqezf7k9.default\extensions -> [2009/03/12 16:33:19 | 00,096,270 | —- | M] ()
< HOSTS File > (175 bytes and 3 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
Reset Hosts
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/23 00:08:42 | 00,062,080 | —- | M] (Adobe Systems Incorporated)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> C:\Program Files\Java\jre6\bin\ssv.dll [SSVHelper Class] -> [2009/05/21 11:33:58 | 00,320,920 | —- | M] (Sun Microsystems, Inc.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} [HKLM] -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [Java™ Plug-In 2 SSV Helper] -> [2009/05/21 11:33:59 | 00,041,368 | —- | M] (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} [HKLM] -> C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [JQSIEStartDetectorImpl Class] -> [2009/05/21 11:33:40 | 00,073,728 | —- | M] (Sun Microsystems, Inc.)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/01/11 23:16:38 | 00,039,792 | —- | M] (Adobe Systems Incorporated)
"avast!" -> C:\Program Files\Alwil Software\Avast4\ashDisp.exe [C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe] -> [2009/02/05 13:08:45 | 00,081,000 | —- | M] (ALWIL Software)
"CTHelper" -> C:\WINDOWS\CTHELPER.EXE [CTHELPER.EXE] -> [2006/06/01 11:34:56 | 00,017,920 | —- | M] (Creative Technology Ltd)
"CTxfiHlp" -> C:\WINDOWS\System32\CTXFIHLP.EXE [CTXFIHLP.EXE] -> [2006/06/01 11:34:58 | 00,018,944 | —- | M] (Creative Technology Ltd)
"eFax 4.3" -> C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe ["C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R] -> [2007/03/06 10:21:31 | 00,116,224 | —- | M] (j2 Global Communications, Inc.)
"iTunesHelper" -> C:\Program Files\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2009/06/05 13:39:22 | 00,292,136 | —- | M] (Apple Inc.)
"Kernel and Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2008/02/29 03:12:38 | 00,076,304 | —- | M] (Logitech, Inc.)
"KernelFaultCheck" ->  [%systemroot%\system32\dumprep 0 -k] -> File not found
"Launch LCDMon" -> C:\Program Files\Logitech\G-series Software\LCDMon.exe ["C:\Program Files\Logitech\G-series Software\LCDMon.exe"] -> [2006/03/06 15:14:58 | 00,497,152 | —- | M] (Logitech Inc.)
"Launch LGDCore" ->  ["C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE] -> File not found
"NvCplDaemon" -> C:\WINDOWS\System32\NvCpl.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2009/05/01 00:30:16 | 13,750,272 | —- | M] (NVIDIA Corporation)
"NvMediaCenter" -> C:\WINDOWS\System32\NvMcTray.DLL [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit] -> [2009/05/01 00:30:16 | 00,086,016 | —- | M] (NVIDIA Corporation)
"nwiz" -> C:\WINDOWS\System32\nwiz.exe [nwiz.exe /install] -> [2009/05/01 00:31:10 | 01,657,376 | —- | M] ()
"QuickTime Task" -> C:\Program Files\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2009/05/26 17:18:30 | 00,413,696 | —- | M] (Apple Inc.)
"SunJavaUpdateSched" -> C:\Program Files\Java\jre6\bin\jusched.exe ["C:\Program Files\Java\jre6\bin\jusched.exe"] -> [2009/05/21 11:34:07 | 00,148,888 | —- | M] (Sun Microsystems, Inc.)
"UMonit" -> C:\WINDOWS\System32\UMonit.exe [C:\WINDOWS\system32\UMonit.exe] -> [2006/11/15 19:47:18 | 00,200,704 | R— | M] ()
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
< All Users.WINDOWS Startup Folder > -> C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup -> 
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> 
< Default User.WINDOWS Startup Folder > -> C:\Documents and Settings\Default User.WINDOWS\Start Menu\Programs\Startup -> 
< Guest Startup Folder > -> C:\Documents and Settings\Guest\Start Menu\Programs\Startup -> 
< Missy's Gamer Startup Folder > -> C:\Documents and Settings\Missy's Gamer\Start Menu\Programs\Startup -> 
< MISSY's GAMER.SHERRI-78C7B973 Startup Folder > -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Start Menu\Programs\Startup -> 
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoControlPanel" ->  [0] -> File not found
\\"HonorAutoRunSetting" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" ->  [0] -> File not found
\\"legalnoticecaption" ->  [] -> File not found
\\"legalnoticetext" ->  [] -> File not found
\\"shutdownwithoutlogon" ->  [1] -> File not found
\\"undockwithoutlogon" ->  [1] -> File not found
\\"DisableRegistryTools" ->  [0] -> File not found
\\"DisableTaskMgr" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [0] -> File not found
\\"NoControlPanel" ->  [0] -> File not found
\\"NoWindowsUpdate" ->  [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"DisableRegistryTools" ->  [0] -> File not found
\\"DisableTaskMgr" ->  [0] -> File not found
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Add to Google Photos Screensa&ver; -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/05/01 11:30:36 | 03,366,912 | —- | M] (Google Inc.)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Add to Google Photos Screensa&ver; -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/05/01 11:30:36 | 03,366,912 | —- | M] (Google Inc.)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Add to Google Photos Screensa&ver; -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/05/01 11:30:36 | 03,366,912 | —- | M] (Google Inc.)
E&xport; to Microsoft Excel -> C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE [res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000] -> File not found
Send to &Bluetooth; Device… -> C:\Program Files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm [C:\Program Files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm] -> [2003/05/29 13:53:12 | 00,001,320 | —- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} [HKLM] -> C:\Program Files\Java\jre6\bin\npjpi160_14.dll [Menu: Sun Java Console] -> [2009/05/21 11:33:59 | 00,136,600 | —- | M] (Sun Microsystems, Inc.)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
{F47C1DB5-ED21-4dc1-853E-D1495792D4C5}:Exec [HKLM] -> C:\Program Files\Bodog Poker\BPGame.exe [Button: Bodog Poker] -> File not found
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 17:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime;=%s -> 
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1892 domain(s) found. -> 
102 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 70 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1892 domain(s) found. -> 
102 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 70 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1892 domain(s) found. -> 
102 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 70 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1892 domain(s) found. -> 
102 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 70 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1891 domain(s) found. -> 
102 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 70 range(s) found. -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab [QuickTime Object] -> 
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] -> 
{1E54D648-B804-468d-BC78-4AFFED8E262F} [HKLM] -> http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab [System Requirements Lab Class] -> 
{406B5949-7190-4245-91A9-30A17DE16AD0} [HKLM] -> http://photo2.walgreens.com/WalgreensActivia.cab [Snapfish Activia] -> 
{48DD0448-9209-4F81-9F6D-D83562940134} [HKLM] -> http://lads.myspace.com/upload/MySpaceUploader1006.cab [MySpace Uploader Control] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237321197109 [MUWebControl Class] -> 
{74DBCB52-F298-4110-951D-AD2FF67BC8AB} [HKLM] -> http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab [NVIDIA Smart Scan] -> 
{8A0019EB-51FA-4AE5-A40B-C0496BBFC739} [HKLM] -> http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab [Verizon Wireless Media Upload] -> 
{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab [Java Plug-in 1.6.0_14] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab [Java Plug-in 1.6.0_14] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab [Shockwave Flash Object] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> [removed] [removed] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{1CBFC959-E03B-4C5D-BE77-95A2EC2FAB52}\\DhcpNameServer -> 192.168.1.1   (NVIDIA nForce Networking Controller) -> 
{3B269AD6-18F6-421D-B506-2620EE029952}\\DhcpNameServer -> [removed] [removed]   () -> 
{D6144B53-6D7B-479B-BD1E-39BDB4685E5C}\\DhcpNameServer -> [removed] [removed]   () -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 17:12:19 | 01,033,728 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
LBTWlgn -> c:\program files\common files\logitech\bluetooth\LBTWlgn.dll -> [2008/05/02 02:42:30 | 00,072,208 | —- | M] (Logitech, Inc.)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 17:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List -> 
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 17:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2009/06/05 13:39:18 | 14,073,640 | —- | M] (Apple Inc.)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" -> C:\Program Files\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM] -> File not found
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe" -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe [C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server] -> [2006/02/07 01:13:32 | 00,020,543 | —- | M] (Apache Software Foundation)
"C:\Program Files\Ventrilo\Ventrilo.exe" -> C:\Program Files\Ventrilo\Ventrilo.exe [C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe] -> [2008/11/10 11:23:50 | 01,539,072 | —- | M] ()
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger] -> File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" -> C:\Program Files\Yahoo!\Messenger\YServer.exe [C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server] -> File not found
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000] -> [2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation)
"C:\WINDOWS\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019] -> [2008/04/13 17:12:34 | 00,141,312 | —- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
"AlternateShell" -> cmd.exe -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" ->  [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > ->  -> 
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2006/07/27 23:05:33 | 00,000,000 | -HS- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Antivirus [ Error ] 3/25/2009 3:51:39 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:00 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:00 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 3/25/2009 3:52:59 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\Program Files\Logitech\Desktop Messenger\8876480\Users\MISSY's GAMER\Data\L0000028.FCS failed, 0000A413.  
Antivirus [ Error ] 4/12/2009 12:54:15 PM Computer Name = SHERRI-78C7B973 | Source = avast! | ID = 33554522 -> Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of C:\DOCUMENTS AND SETTINGS\MISSY'S GAMER.SHERRI-78C7B973\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\FEEDS\LESTER~.FEED-MS failed, 00000005.  
Application [ Error ] 6/13/2009 9:35:22 PM Computer Name = SHERRI-78C7B973 | Source = Application Error | ID = 1000 -> Description = Faulting application bpgame.exe, version 2.16.3.49, faulting module bpgame.exe, version 2.16.3.49, fault address 0x000523b2.
Application [ Error ] 6/14/2009 5:23:06 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: Product Software – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 5:23:07 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: Product Drivers – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 5:23:08 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: hp psc 2100 series – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 8:47:12 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: Product Software – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 8:59:38 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: Product Software – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 9:03:41 PM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11327 -> Description = Product: Product Software – Error 1327.Invalid Drive: g:\
Application [ Error ] 6/14/2009 10:55:23 PM Computer Name = SHERRI-78C7B973 | Source = Application Error | ID = 1000 -> Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting module shell32.dll, version 6.0.2900.5622, fault address 0x0002b284.
Application [ Error ] 6/14/2009 10:55:27 PM Computer Name = SHERRI-78C7B973 | Source = Application Error | ID = 1000 -> Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
Application [ Error ] 6/15/2009 5:28:19 AM Computer Name = SHERRI-78C7B973 | Source = MsiInstaller | ID = 11706 -> Description = Product: Glycerine – Error 1706. An installation package for the product Glycerine cannot be found. Try the installation again using a valid copy of the installation package 'Glycerine.msi'.
System [ Error ] 6/15/2009 12:53:15 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842811 -> Description = Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL.  Reference error message: The operation completed successfully.  .
System [ Error ] 6/15/2009 12:53:50 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842784 -> Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.  
System [ Error ] 6/15/2009 12:53:50 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842811 -> Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.  Reference error message: The referenced assembly is not installed on your system.  .
System [ Error ] 6/15/2009 12:53:50 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842811 -> Description = Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL.  Reference error message: The operation completed successfully.  .
System [ Error ] 6/15/2009 12:56:14 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842784 -> Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.  
System [ Error ] 6/15/2009 12:56:14 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842811 -> Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC.  Reference error message: The referenced assembly is not installed on your system.  .
System [ Error ] 6/15/2009 12:56:14 PM Computer Name = SHERRI-78C7B973 | Source = SideBySide | ID = 16842811 -> Description = Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL.  Reference error message: The operation completed successfully.  .
System [ Error ] 6/15/2009 2:26:23 PM Computer Name = SHERRI-78C7B973 | Source = sr | ID = 1 -> Description = The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.
System [ Error ] 6/15/2009 2:26:23 PM Computer Name = SHERRI-78C7B973 | Source = Tcpip | ID = 4191 -> Description = IP could not open the registry key for adapter TCPIP\Parameters\Adapters\NDISWANIP.  Interfaces on this adapter will not be initialized.
System [ Error ] 6/15/2009 2:27:52 PM Computer Name = SHERRI-78C7B973 | Source = Service Control Manager | ID = 7000 -> Description = The yuiovfyw service failed to start due to the following error:   %%2
 
[Files/Folders - Created Within 30 Days]
OTS.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\OTS.exe -> [2009/06/15 11:39:12 | 00,507,392 | —- | C] (OldTimer Tools)
Mediafire Filesharing.htm -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Mediafire Filesharing.htm -> [2009/06/15 11:38:49 | 00,038,326 | —- | C] ()
System Cleanup Log Files -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\System Cleanup Log Files -> [2009/06/15 11:04:43 | 00,000,000 | —D | C]
Malwarebytes -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Malwarebytes -> [2009/06/15 11:03:09 | 00,000,000 | —D | C]
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/06/15 11:03:06 | 00,040,160 | —- | C] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/06/15 11:03:05 | 00,019,096 | —- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/06/15 11:03:05 | 00,000,000 | —D | C]
Malwarebytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes -> [2009/06/15 11:03:05 | 00,000,000 | —D | C]
mbam-setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\mbam-setup.exe -> [2009/06/15 10:59:38 | 03,371,384 | —- | C] (Malwarebytes Corporation									)
[Closed] infested with spy removal scam, can't get rid of it.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\[Closed] infested with spy removal scam, can't get rid of it.url -> [2009/06/15 10:21:20 | 00,000,188 | —- | C] ()
[Closed] MY HIJACKTHIS log please let me know.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\[Closed] MY HIJACKTHIS log please let me know.url -> [2009/06/15 10:13:17 | 00,000,167 | —- | C] ()
Glycerine.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\Glycerine.lnk -> [2009/06/15 02:32:13 | 00,001,922 | —- | C] ()
TweakCoHSETUP.jpg -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\TweakCoHSETUP.jpg -> [2009/06/15 01:19:49 | 00,242,379 | —- | C] ()
TweakCoH.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\TweakCoH.lnk -> [2009/06/15 00:52:17 | 00,001,886 | —- | C] ()
TweakCoH -> C:\Program Files\TweakCoH -> [2009/06/15 00:52:17 | 00,000,000 | —D | C]
City of Heroes -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\City of Heroes -> [2009/06/14 23:43:35 | 00,000,000 | —D | C]
MissyRenon -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\MissyRenon -> [2009/06/14 23:40:49 | 00,000,000 | —D | C]
OLD FILE screenshots -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\OLD FILE screenshots -> [2009/06/14 23:37:30 | 00,000,000 | —D | C]
The First Steps to Virus-Spyware-Adware Removal - The solution.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\The First Steps to Virus-Spyware-Adware Removal - The solution.url -> [2009/06/14 19:55:04 | 00,000,172 | —- | C] ()
hpoins01.dat -> C:\WINDOWS\hpoins01.dat -> [2009/06/14 18:07:30 | 00,019,558 | —- | C] ()
hpomdl01.dat -> C:\WINDOWS\hpomdl01.dat -> [2009/06/14 18:07:30 | 00,016,606 | —- | C] ()
Drivers - Download NVIDIA Drivers.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Drivers - Download NVIDIA Drivers.url -> [2009/06/14 17:53:42 | 00,000,198 | —- | C] ()
Directions for Download Only option  HP Officejet and PSC Full Feature Software and Driver.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Directions for Download Only option  HP Officejet and PSC Full Feature Software and Driver.url -> [2009/06/14 17:52:57 | 00,000,290 | —- | C] ()
Driver Sweeper -> C:\Program Files\Driver Sweeper -> [2009/06/14 17:30:49 | 00,000,000 | —D | C]
HijackThis.lnk -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\HijackThis.lnk -> [2009/06/14 17:01:16 | 00,001,734 | —- | C] ()
Celebs Story.doc -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Celebs Story.doc -> [2009/06/14 16:33:23 | 00,043,008 | —- | C] ()
My Crash Thread.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\My Crash Thread.url -> [2009/06/14 15:51:57 | 00,000,186 | —- | C] ()
Tech Issues and Bugs.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Tech Issues and Bugs.url -> [2009/06/14 14:11:35 | 00,000,249 | —- | C] ()
HiJackThis.zip -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\HiJackThis.zip -> [2009/06/14 12:32:17 | 00,318,369 | —- | C] ()
CoHHelper -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\CoHHelper -> [2009/06/14 11:47:17 | 00,000,000 | —D | C]
Trend Micro -> C:\Program Files\Trend Micro -> [2009/06/14 11:28:36 | 00,000,000 | —D | C]
22 Widescreen Monitor.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\22 Widescreen Monitor.url -> [2009/06/14 11:21:17 | 00,000,147 | —- | C] ()
avast! Antivirus.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\avast! Antivirus.lnk -> [2009/06/14 07:59:23 | 00,001,709 | —- | C] ()
aswSP.sys -> C:\WINDOWS\System32\drivers\aswSP.sys -> [2009/06/14 07:59:22 | 00,114,768 | —- | C] (ALWIL Software)
AvastSS.scr -> C:\WINDOWS\System32\AvastSS.scr -> [2009/06/14 07:59:22 | 00,097,480 | —- | C] (ALWIL Software)
aswTdi.sys -> C:\WINDOWS\System32\drivers\aswTdi.sys -> [2009/06/14 07:59:22 | 00,051,376 | —- | C] (ALWIL Software)
aavmker4.sys -> C:\WINDOWS\System32\drivers\aavmker4.sys -> [2009/06/14 07:59:22 | 00,026,944 | —- | C] (ALWIL Software)
aswRdr.sys -> C:\WINDOWS\System32\drivers\aswRdr.sys -> [2009/06/14 07:59:22 | 00,023,152 | —- | C] (ALWIL Software)
aswFsBlk.sys -> C:\WINDOWS\System32\drivers\aswFsBlk.sys -> [2009/06/14 07:59:22 | 00,020,560 | —- | C] (ALWIL Software)
aswmon2.sys -> C:\WINDOWS\System32\drivers\aswmon2.sys -> [2009/06/14 07:59:21 | 00,094,032 | —- | C] (ALWIL Software)
aswmon.sys -> C:\WINDOWS\System32\drivers\aswmon.sys -> [2009/06/14 07:59:21 | 00,093,296 | —- | C] (ALWIL Software)
aswBoot.exe -> C:\WINDOWS\System32\aswBoot.exe -> [2009/06/14 07:59:08 | 01,256,296 | —- | C] (ALWIL Software)
actskin4.ocx -> C:\WINDOWS\System32\actskin4.ocx -> [2009/06/14 07:59:08 | 00,380,928 | —- | C] ()
TweetDeck -> C:\Program Files\TweetDeck -> [2009/06/13 00:16:34 | 00,000,000 | —D | C]
TO THE CLOSET, ROBIN!.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\TO THE CLOSET, ROBIN!.url -> [2009/06/12 03:57:27 | 00,000,183 | —- | C] ()
SystemRequirementsLab -> C:\Program Files\SystemRequirementsLab -> [2009/06/11 20:48:20 | 00,000,000 | —D | C]
iTunes.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk -> [2009/06/10 00:34:47 | 00,001,804 | —- | C] ()
iPod -> C:\Program Files\iPod -> [2009/06/10 00:34:25 | 00,000,000 | —D | C]
iTunes -> C:\Program Files\iTunes -> [2009/06/10 00:34:21 | 00,000,000 | —D | C]
QuickTime -> C:\Program Files\QuickTime -> [2009/06/10 00:32:36 | 00,000,000 | —D | C]
vlc -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\vlc -> [2009/05/21 20:12:25 | 00,000,000 | —D | C]
VLC media player.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\VLC media player.lnk -> [2009/05/21 20:10:49 | 00,000,719 | —- | C] ()
VideoLAN -> C:\Program Files\VideoLAN -> [2009/05/21 20:10:33 | 00,000,000 | —D | C]
nvwdmcpl.dll -> C:\WINDOWS\System32\nvwdmcpl.dll -> [2009/05/01 00:31:06 | 01,724,416 | —- | C] ()
nview.dll -> C:\WINDOWS\System32\nview.dll -> [2009/05/01 00:31:06 | 01,507,328 | —- | C] ()
nvwimg.dll -> C:\WINDOWS\System32\nvwimg.dll -> [2009/05/01 00:31:06 | 01,101,824 | —- | C] ()
nvshell.dll -> C:\WINDOWS\System32\nvshell.dll -> [2009/05/01 00:31:06 | 00,466,944 | —- | C] ()
st_affiliate.ini -> C:\WINDOWS\st_affiliate.ini -> [2009/03/17 13:37:20 | 00,000,063 | —- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2009/02/16 14:57:49 | 00,001,793 | —- | C] ()
{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini -> C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini -> [2008/12/02 10:49:17 | 00,000,262 | —- | C] ()
physxcudart_20.dll -> C:\WINDOWS\System32\physxcudart_20.dll -> [2008/10/07 10:13:30 | 00,197,912 | —- | C] ()
AgCPanelTraditionalChinese.dll -> C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll -> [2008/10/07 10:13:22 | 00,058,648 | —- | C] ()
AgCPanelSwedish.dll -> C:\WINDOWS\System32\AgCPanelSwedish.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelSpanish.dll -> C:\WINDOWS\System32\AgCPanelSpanish.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelSimplifiedChinese.dll -> C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelPortugese.dll -> C:\WINDOWS\System32\AgCPanelPortugese.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelKorean.dll -> C:\WINDOWS\System32\AgCPanelKorean.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelJapanese.dll -> C:\WINDOWS\System32\AgCPanelJapanese.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelGerman.dll -> C:\WINDOWS\System32\AgCPanelGerman.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
AgCPanelFrench.dll -> C:\WINDOWS\System32\AgCPanelFrench.dll -> [2008/10/07 10:13:20 | 00,058,648 | —- | C] ()
cdplayer.ini -> C:\WINDOWS\cdplayer.ini -> [2008/03/07 22:57:45 | 00,000,025 | —- | C] ()
JGFR400.DLL -> C:\WINDOWS\System32\JGFR400.DLL -> [2008/01/06 09:19:02 | 00,109,568 | —- | C] ()
ustor.dll -> C:\WINDOWS\System32\ustor.dll -> [2008/01/04 16:38:43 | 00,151,552 | R— | C] ()
IconCfg0.ini -> C:\WINDOWS\System32\IconCfg0.ini -> [2008/01/04 16:38:43 | 00,001,255 | R— | C] ()
INT14PPP.dll -> C:\WINDOWS\System32\INT14PPP.dll -> [2007/12/07 13:18:32 | 00,532,480 | —- | C] ()
UTL10PPP.dll -> C:\WINDOWS\System32\UTL10PPP.dll -> [2007/12/07 13:18:32 | 00,061,440 | —- | C] ()
exchng.ini -> C:\WINDOWS\exchng.ini -> [2007/04/16 18:12:57 | 00,000,022 | —- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2007/04/16 18:12:56 | 00,000,611 | —- | C] ()
GVCplDrv.sys -> C:\WINDOWS\System32\drivers\GVCplDrv.sys -> [2006/11/16 17:55:47 | 00,016,899 | R— | C] ()
iPlayer.INI -> C:\WINDOWS\iPlayer.INI -> [2006/09/30 16:23:35 | 00,000,000 | —- | C] ()
PCFriend.INI -> C:\WINDOWS\PCFriend.INI -> [2006/09/30 16:18:37 | 00,000,000 | —- | C] ()
LxrSII1d.sys -> C:\WINDOWS\System32\drivers\LxrSII1d.sys -> [2006/07/31 20:52:43 | 00,070,016 | —- | C] ()
instwdm.ini -> C:\WINDOWS\System32\instwdm.ini -> [2006/07/31 11:42:25 | 00,081,447 | —- | C] ()
CTXFIRES.DLL -> C:\WINDOWS\CTXFIRES.DLL -> [2006/07/31 11:42:25 | 00,003,072 | —- | C] ()
ctzapxx.ini -> C:\WINDOWS\System32\ctzapxx.ini -> [2006/07/31 11:42:25 | 00,000,191 | —- | C] ()
raidmgmt.ini -> C:\WINDOWS\System32\raidmgmt.ini -> [2006/07/31 11:31:16 | 00,000,402 | R— | C] ()
AsusSetup.ini -> C:\WINDOWS\System32\AsusSetup.ini -> [2006/07/31 11:31:15 | 00,000,804 | R— | C] ()
ASACPI.sys -> C:\WINDOWS\System32\drivers\ASACPI.sys -> [2006/07/31 11:30:54 | 00,005,810 | R— | C] ()
Ascd_tmp.ini -> C:\WINDOWS\Ascd_tmp.ini -> [2006/07/31 11:30:43 | 00,025,717 | —- | C] ()
ASUSHWIO.SYS -> C:\WINDOWS\System32\drivers\ASUSHWIO.SYS -> [2006/07/31 11:30:31 | 00,005,824 | —- | C] ()
CTBURST.DLL -> C:\WINDOWS\System32\CTBURST.DLL -> [2006/06/01 11:43:48 | 00,037,888 | —- | C] ()
a3d.dll -> C:\WINDOWS\System32\a3d.dll -> [2006/06/01 11:38:44 | 00,033,792 | —- | C] ( )
KILL.INI -> C:\WINDOWS\System32\KILL.INI -> [2006/05/18 15:04:18 | 00,000,269 | —- | C] ()
btprn2k.dll -> C:\WINDOWS\System32\btprn2k.dll -> [2006/04/12 10:23:54 | 00,090,112 | —- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2006/02/28 05:00:00 | 00,001,090 | —- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2006/02/28 05:00:00 | 00,000,231 | —- | C] ()
CTMMACTL.DLL -> C:\WINDOWS\System32\CTMMACTL.DLL -> [2005/06/07 21:10:50 | 00,070,656 | —- | C] ()
BTNeighborhood.dll.manifest -> C:\WINDOWS\System32\BTNeighborhood.dll.manifest -> [2005/02/17 12:41:32 | 00,000,603 | —- | C] ()
btcss.dll.manifest -> C:\WINDOWS\System32\btcss.dll.manifest -> [2005/02/17 12:41:30 | 00,000,593 | —- | C] ()
hpotscl.dll -> C:\WINDOWS\System32\hpotscl.dll -> [2003/03/09 21:31:04 | 00,561,152 | —- | C] ()
lcppn21.dll -> C:\WINDOWS\System32\lcppn21.dll -> [2001/11/14 13:56:00 | 01,802,240 | —- | C] ()
Iticheck.dll -> C:\WINDOWS\System32\Iticheck.dll -> [1998/10/11 01:07:38 | 00,088,576 | —- | C] ()
ODBCSTF.DLL -> C:\WINDOWS\System32\ODBCSTF.DLL -> [1996/11/17 00:00:00 | 00,022,016 | —- | C] ()
DOCOBJ.DLL -> C:\WINDOWS\System32\DOCOBJ.DLL -> [1996/11/17 00:00:00 | 00,022,016 | —- | C] ()
HLINKPRX.DLL -> C:\WINDOWS\System32\HLINKPRX.DLL -> [1996/11/17 00:00:00 | 00,012,288 | —- | C] ()
giveio.sys -> C:\WINDOWS\System32\giveio.sys -> [1996/04/03 12:33:26 | 00,005,248 | —- | C] ()
 
[Files/Folders - Modified Within 30 Days]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
19 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
1 C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\*.tmp files -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\*.tmp -> 
1843 C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\*.tmp -> 
5 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> 
OTS.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\OTS.exe -> [2009/06/15 11:39:14 | 00,507,392 | —- | M] (OldTimer Tools)
Mediafire Filesharing.htm -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Mediafire Filesharing.htm -> [2009/06/15 11:38:49 | 00,038,326 | —- | M] ()
My Crash Thread.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\My Crash Thread.url -> [2009/06/15 11:37:10 | 00,000,186 | —- | M] ()
nvapps.xml -> C:\WINDOWS\System32\nvapps.xml -> [2009/06/15 11:34:25 | 00,206,916 | —- | M] ()
Perflib_Perfdata_834.dat -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Perflib_Perfdata_834.dat -> [2009/06/15 11:34:18 | 00,016,384 | —- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/06/15 11:34:01 | 00,013,646 | —- | M] ()
Perflib_Perfdata_124.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_124.dat -> [2009/06/15 11:26:32 | 00,016,384 | —- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/06/15 11:26:23 | 00,000,006 | -H– | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/06/15 11:26:13 | 00,002,048 | –S- | M] ()
DVCState-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> C:\WINDOWS\System32\DVCState-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> [2009/06/15 11:25:27 | 00,064,980 | —- | M] ()
BMXStateBkp-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> C:\WINDOWS\System32\BMXStateBkp-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> [2009/06/15 11:25:27 | 00,054,680 | —- | M] ()
BMXState-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> C:\WINDOWS\System32\BMXState-{00000001-00000000-00000007-00001102-00000005-00211102}.rfx -> [2009/06/15 11:25:27 | 00,054,680 | —- | M] ()
settingsbkup.sfm -> C:\WINDOWS\System32\settingsbkup.sfm -> [2009/06/15 11:25:27 | 00,002,056 | —- | M] ()
settings.sfm -> C:\WINDOWS\System32\settings.sfm -> [2009/06/15 11:25:27 | 00,002,056 | —- | M] ()
NTUSER.DAT -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\NTUSER.DAT -> [2009/06/15 11:25:05 | 07,864,320 | -H– | M] ()
ntuser.ini -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\ntuser.ini -> [2009/06/15 11:25:05 | 00,000,178 | -HS- | M] ()
mbam-setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\mbam-setup.exe -> [2009/06/15 10:59:38 | 03,371,384 | —- | M] (Malwarebytes Corporation									)
hpfr5550.xml -> C:\hpfr5550.xml -> [2009/06/15 10:58:11 | 00,000,488 | —- | M] ()
[Closed] infested with spy removal scam, can't get rid of it.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\[Closed] infested with spy removal scam, can't get rid of it.url -> [2009/06/15 10:21:20 | 00,000,188 | —- | M] ()
[Closed] MY HIJACKTHIS log please let me know.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\[Closed] MY HIJACKTHIS log please let me know.url -> [2009/06/15 10:13:17 | 00,000,167 | —- | M] ()
Glycerine.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\Glycerine.lnk -> [2009/06/15 02:32:13 | 00,001,922 | —- | M] ()
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSDE.tmp\DotNetFX\dotnetchk.exe -> [2009/06/15 02:31:58 | 00,087,552 | —- | M] (Microsoft Corporation)
TweakCoHSETUP.jpg -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\TweakCoHSETUP.jpg -> [2009/06/15 01:37:18 | 00,242,379 | —- | M] ()
TweakCoH.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\TweakCoH.lnk -> [2009/06/15 00:52:17 | 00,001,886 | —- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2009/06/15 00:13:06 | 00,009,216 | —- | M] ()
MISSY's GAMER8.xlb -> C:\WINDOWS\MISSY's GAMER8.xlb -> [2009/06/15 00:11:28 | 00,007,206 | —- | M] ()
hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2009/06/15 00:03:24 | 00,000,175 | R— | M] ()
Perflib_Perfdata_154.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_154.dat -> [2009/06/14 20:15:27 | 00,016,384 | —- | M] ()
The First Steps to Virus-Spyware-Adware Removal - The solution.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\The First Steps to Virus-Spyware-Adware Removal - The solution.url -> [2009/06/14 19:55:04 | 00,000,172 | —- | M] ()
IconCache.db -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Application Data\IconCache.db -> [2009/06/14 19:39:48 | 03,846,516 | -H– | M] ()
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/06/14 19:20:38 | 00,522,724 | —- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/06/14 19:20:38 | 00,442,026 | —- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/06/14 19:20:38 | 00,071,674 | —- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/06/14 19:02:34 | 00,004,566 | —- | M] ()
hpothb07.tif -> C:\Documents and Settings\All Users.WINDOWS\Desktop\hpothb07.tif -> [2009/06/14 18:12:14 | 00,958,737 | -H– | M] ()
hpothb07.dat -> C:\Documents and Settings\All Users.WINDOWS\Desktop\hpothb07.dat -> [2009/06/14 18:12:14 | 00,002,595 | -H– | M] ()
win.ini -> C:\WINDOWS\win.ini -> [2009/06/14 18:10:45 | 00,001,090 | —- | M] ()
hpoins01.dat -> C:\WINDOWS\hpoins01.dat -> [2009/06/14 18:10:35 | 00,019,558 | —- | M] ()
HP Photo & Imaging.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Photo & Imaging.lnk -> [2009/06/14 18:08:31 | 00,000,851 | —- | M] ()
HP Director.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\HP Director.lnk -> [2009/06/14 18:08:31 | 00,000,851 | —- | M] ()
Directions for Download Only option  HP Officejet and PSC Full Feature Software and Driver.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Directions for Download Only option  HP Officejet and PSC Full Feature Software and Driver.url -> [2009/06/14 17:58:14 | 00,000,290 | —- | M] ()
Drivers - Download NVIDIA Drivers.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Drivers - Download NVIDIA Drivers.url -> [2009/06/14 17:54:32 | 00,000,198 | —- | M] ()
Perflib_Perfdata_534.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_534.dat -> [2009/06/14 17:53:16 | 00,016,384 | —- | M] ()
HijackThis.lnk -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\HijackThis.lnk -> [2009/06/14 17:01:16 | 00,001,734 | —- | M] ()
Celebs Story.doc -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Celebs Story.doc -> [2009/06/14 16:33:23 | 00,043,008 | —- | M] ()
Tech Issues and Bugs.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\Tech Issues and Bugs.url -> [2009/06/14 14:33:45 | 00,000,249 | —- | M] ()
HiJackThis.zip -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\HiJackThis.zip -> [2009/06/14 12:32:17 | 00,318,369 | —- | M] ()
22 Widescreen Monitor.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\22 Widescreen Monitor.url -> [2009/06/14 11:21:17 | 00,000,147 | —- | M] ()
avast! Antivirus.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\avast! Antivirus.lnk -> [2009/06/14 07:59:23 | 00,001,709 | —- | M] ()
CONFIG.NT -> C:\WINDOWS\System32\CONFIG.NT -> [2009/06/14 07:59:22 | 00,002,626 | —- | M] ()
setupeng.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\_av_inet.tm~a02196\setupeng.exe -> [2009/06/14 07:58:46 | 35,272,712 | —- | M] ()
Perflib_Perfdata_664.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_664.dat -> [2009/06/14 01:34:44 | 00,016,384 | —- | M] ()
TweetDeck.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\TweetDeck.lnk -> [2009/06/13 00:16:34 | 00,000,640 | —- | M] ()
TO THE CLOSET, ROBIN!.url -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\TO THE CLOSET, ROBIN!.url -> [2009/06/12 03:57:27 | 00,000,183 | —- | M] ()
qmgr0.dat -> C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/06/12 02:15:21 | 00,004,232 | —- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/06/12 02:15:20 | 00,005,937 | —- | M] ()
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD4.tmp\DotNetFX\dotnetchk.exe -> [2009/06/11 17:57:07 | 00,087,552 | —- | M] (Microsoft Corporation)
Perflib_Perfdata_20c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_20c.dat -> [2009/06/11 17:53:47 | 00,016,384 | —- | M] ()
Perflib_Perfdata_640.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_640.dat -> [2009/06/11 17:53:37 | 00,016,384 | —- | M] ()
AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2009/06/11 15:45:02 | 00,000,284 | —- | M] ()
Perflib_Perfdata_960.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_960.dat -> [2009/06/11 15:29:37 | 00,016,384 | —- | M] ()
Perflib_Perfdata_638.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_638.dat -> [2009/06/11 15:29:25 | 00,016,384 | —- | M] ()
iTunes.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk -> [2009/06/10 00:34:47 | 00,001,804 | —- | M] ()
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation)
Perflib_Perfdata_24c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_24c.dat -> [2009/05/22 16:25:22 | 00,016,384 | —- | M] ()
VLC media player.lnk -> C:\Documents and Settings\All Users.WINDOWS\Desktop\VLC media player.lnk -> [2009/05/21 20:10:49 | 00,000,719 | —- | M] ()
Perflib_Perfdata_64c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_64c.dat -> [2009/04/23 12:40:39 | 00,016,384 | —- | M] ()
Perflib_Perfdata_93c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_93c.dat -> [2009/04/19 12:41:51 | 00,016,384 | —- | M] ()
Perflib_Perfdata_8ec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8ec.dat -> [2009/04/19 12:23:53 | 00,016,384 | —- | M] ()
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD62.tmp\DotNetFX\dotnetchk.exe -> [2009/04/15 17:10:27 | 00,087,552 | —- | M] (Microsoft Corporation)
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD56.tmp\DotNetFX\dotnetchk.exe -> [2009/04/15 17:09:31 | 00,087,552 | —- | M] (Microsoft Corporation)
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD57.tmp\DotNetFX\dotnetchk.exe -> [2009/03/27 20:23:26 | 00,087,552 | —- | M] (Microsoft Corporation)
ci.dll -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\ci.dll -> [2009/03/25 05:10:46 | 01,204,208 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\GoogleUpdaterAdminPrefs.exe -> [2009/03/25 05:10:46 | 00,227,824 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gisc1af0\GoogleUpdaterService.exe -> [2009/03/25 05:10:46 | 00,183,280 | —- | M] (Google)
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\GoogleUpdaterSetup.exe -> [2009/03/25 05:10:46 | 00,176,112 | —- | M] (Google Inc.)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\GoogleUpdaterInstallMgr.exe -> [2009/03/25 05:10:46 | 00,169,968 | —- | M] (Google)
GoogleUpdater.exe -> C:\WINDOWS\Temp\gisc1af0\GoogleUpdater.exe -> [2009/03/25 05:10:46 | 00,161,776 | —- | M] (Google)
cires.dll -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\cires.dll -> [2009/03/25 05:10:46 | 00,100,848 | —- | M] ()
npCIDetect13.dll -> C:\WINDOWS\Temp\gisc1af0\2.4.1536.6592\npCIDetect13.dll -> [2009/03/25 05:10:46 | 00,099,824 | —- | M] (Google)
Perflib_Perfdata_ab4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ab4.dat -> [2009/03/16 19:39:11 | 00,016,384 | —- | M] ()
Perflib_Perfdata_10c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_10c.dat -> [2009/03/16 14:23:12 | 00,016,384 | —- | M] ()
Perflib_Perfdata_938.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_938.dat -> [2009/03/15 17:12:03 | 00,016,384 | —- | M] ()
Perflib_Perfdata_1bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_1bc.dat -> [2009/03/15 02:06:03 | 00,016,384 | —- | M] ()
Perflib_Perfdata_f8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f8.dat -> [2009/03/13 13:35:08 | 00,016,384 | —- | M] ()
_unps.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\_unps.exe -> [2009/03/13 00:58:59 | 00,352,256 | —- | M] ()
Perflib_Perfdata_b00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b00.dat -> [2009/03/12 20:35:34 | 00,016,384 | —- | M] ()
Perflib_Perfdata_b18.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b18.dat -> [2009/03/12 19:33:11 | 00,016,384 | —- | M] ()
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2009/03/12 16:49:27 | 00,049,152 | -HS- | M] ()
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat -> [2009/03/12 16:49:27 | 00,016,384 | -HS- | M] ()
SetupAdmin[1].exe -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\LBMOY1I1\SetupAdmin[1].exe -> [2009/03/12 15:58:35 | 00,075,048 | —- | M] (Apple Inc.)
Perflib_Perfdata_814.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_814.dat -> [2009/03/02 21:05:14 | 00,016,384 | —- | M] ()
Perflib_Perfdata_990.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_990.dat -> [2009/02/28 11:00:09 | 00,016,384 | —- | M] ()
Perflib_Perfdata_a04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a04.dat -> [2009/02/12 23:01:51 | 00,016,384 | —- | M] ()
Perflib_Perfdata_a5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a5c.dat -> [2009/02/12 21:33:41 | 00,016,384 | —- | M] ()
Perflib_Perfdata_fc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fc.dat -> [2009/02/05 12:24:37 | 00,016,384 | —- | M] ()
Perflib_Perfdata_d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d4.dat -> [2009/02/01 20:50:36 | 00,016,384 | —- | M] ()
Perflib_Perfdata_7fc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7fc.dat -> [2009/02/01 18:35:05 | 00,016,384 | —- | M] ()
Perflib_Perfdata_89c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_89c.dat -> [2009/01/31 20:06:44 | 00,016,384 | —- | M] ()
Perflib_Perfdata_6d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6d4.dat -> [2009/01/30 14:44:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f0.dat -> [2009/01/27 10:30:02 | 00,016,384 | —- | M] ()
Perflib_Perfdata_6a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6a8.dat -> [2009/01/23 16:08:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_8c0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8c0.dat -> [2009/01/21 23:07:57 | 00,016,384 | —- | M] ()
Perflib_Perfdata_7a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7a8.dat -> [2009/01/21 19:02:59 | 00,016,384 | —- | M] ()
Perflib_Perfdata_f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f4.dat -> [2009/01/21 18:46:58 | 00,016,384 | —- | M] ()
Perflib_Perfdata_79c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_79c.dat -> [2009/01/21 11:59:36 | 00,016,384 | —- | M] ()
Perflib_Perfdata_798.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_798.dat -> [2009/01/21 04:32:27 | 00,016,384 | —- | M] ()
dotNetFx35setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD36.tmp\DotNetFX35\dotNetFx35setup.exe -> [2009/01/20 11:31:25 | 02,869,264 | —- | M] (Microsoft Corporation)
Perflib_Perfdata_6ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6ac.dat -> [2009/01/19 14:06:48 | 00,016,384 | —- | M] ()
Perflib_Perfdata_78c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_78c.dat -> [2009/01/19 14:02:33 | 00,016,384 | —- | M] ()
Perflib_Perfdata_578.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_578.dat -> [2009/01/19 13:53:37 | 00,016,384 | —- | M] ()
Perflib_Perfdata_980.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_980.dat -> [2009/01/17 22:16:19 | 00,016,384 | —- | M] ()
Perflib_Perfdata_b4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b4.dat -> [2009/01/16 10:09:30 | 00,016,384 | —- | M] ()
Perflib_Perfdata_668.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_668.dat -> [2009/01/15 21:01:37 | 00,016,384 | —- | M] ()
Perflib_Perfdata_9a0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9a0.dat -> [2009/01/15 20:49:58 | 00,016,384 | —- | M] ()
setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E161524-F495-47EA-8209-BBCFA413DA59}\setup.exe -> [2009/01/15 20:46:59 | 00,379,424 | —- | M] (Macrovision Corporation)
Perflib_Perfdata_6bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6bc.dat -> [2009/01/15 20:42:36 | 00,016,384 | —- | M] ()
ISSetup.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{D0A364C3-18AA-4D54-8AB0-C61C867F349B}\ISSetup.dll -> [2009/01/15 20:42:28 | 00,535,552 | —- | M] (Macrovision Corporation)
SETUP.EXE -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{D0A364C3-18AA-4D54-8AB0-C61C867F349B}\SETUP.EXE -> [2009/01/15 20:42:28 | 00,379,424 | —- | M] (Macrovision Corporation)
_Setup.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{D0A364C3-18AA-4D54-8AB0-C61C867F349B}\_Setup.dll -> [2009/01/15 20:42:28 | 00,324,552 | —- | M] (Macrovision Corporation)
_Setup.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{44E6FBA4-CB89-4A8F-B63E-EBC4F3C94896}\_Setup.dll -> [2009/01/15 20:35:39 | 00,148,416 | —- | M] (Macrovision Corporation)
Perflib_Perfdata_a20.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a20.dat -> [2009/01/15 20:34:21 | 00,016,384 | —- | M] ()
Perflib_Perfdata_314.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_314.dat -> [2009/01/15 20:11:18 | 00,016,384 | —- | M] ()
setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{3EAB1021-6BA8-4D3D-A32E-03803EECD543}\setup.exe -> [2009/01/15 18:19:28 | 00,379,424 | —- | M] (Macrovision Corporation)
Perflib_Perfdata_770.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_770.dat -> [2009/01/15 18:17:54 | 00,016,384 | —- | M] ()
Perflib_Perfdata_3d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3d4.dat -> [2009/01/15 16:38:40 | 00,016,384 | —- | M] ()
Perflib_Perfdata_a0c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a0c.dat -> [2009/01/15 16:35:09 | 00,016,384 | —- | M] ()
Perflib_Perfdata_97c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_97c.dat -> [2009/01/15 16:35:05 | 00,016,384 | —- | M] ()
Perflib_Perfdata_e3c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e3c.dat -> [2009/01/15 16:33:25 | 00,016,384 | —- | M] ()
Perflib_Perfdata_4b0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4b0.dat -> [2009/01/15 16:32:59 | 00,016,384 | —- | M] ()
Perflib_Perfdata_718.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_718.dat -> [2009/01/15 16:32:57 | 00,016,384 | —- | M] ()
Perflib_Perfdata_54c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_54c.dat -> [2009/01/14 22:45:39 | 00,016,384 | —- | M] ()
Perflib_Perfdata_550.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_550.dat -> [2009/01/14 10:24:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_780.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_780.dat -> [2009/01/14 01:52:40 | 00,016,384 | —- | M] ()
Perflib_Perfdata_784.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_784.dat -> [2009/01/13 15:27:52 | 00,016,384 | —- | M] ()
Perflib_Perfdata_a40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a40.dat -> [2009/01/13 10:18:47 | 00,016,384 | —- | M] ()
Perflib_Perfdata_df0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_df0.dat -> [2009/01/13 10:15:33 | 00,016,384 | —- | M] ()
Perflib_Perfdata_950.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_950.dat -> [2009/01/13 10:15:10 | 00,016,384 | —- | M] ()
Perflib_Perfdata_794.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_794.dat -> [2009/01/13 10:11:27 | 00,016,384 | —- | M] ()
Perflib_Perfdata_77c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_77c.dat -> [2009/01/12 20:59:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_1ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_1ac.dat -> [2009/01/12 20:40:51 | 00,016,384 | —- | M] ()
Perflib_Perfdata_790.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_790.dat -> [2009/01/12 20:38:02 | 00,016,384 | —- | M] ()
Perflib_Perfdata_510.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_510.dat -> [2009/01/12 20:33:11 | 00,016,384 | —- | M] ()
Perflib_Perfdata_4a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4a8.dat -> [2009/01/12 20:33:11 | 00,016,384 | —- | M] ()
Perflib_Perfdata_76c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_76c.dat -> [2009/01/12 16:58:51 | 00,016,384 | —- | M] ()
Perflib_Perfdata_600.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_600.dat -> [2009/01/12 15:57:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_320.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_320.dat -> [2009/01/12 15:55:52 | 00,016,384 | —- | M] ()
Perflib_Perfdata_778.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_778.dat -> [2009/01/12 15:23:52 | 00,016,384 | —- | M] ()
Perflib_Perfdata_768.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_768.dat -> [2009/01/12 15:02:50 | 00,016,384 | —- | M] ()
Perflib_Perfdata_504.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_504.dat -> [2009/01/12 14:37:53 | 00,016,384 | —- | M] ()
Perflib_Perfdata_574.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_574.dat -> [2009/01/12 14:30:46 | 00,016,384 | —- | M] ()
Perflib_Perfdata_6c4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6c4.dat -> [2009/01/12 14:20:12 | 00,016,384 | —- | M] ()
Perflib_Perfdata_8c4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8c4.dat -> [2009/01/12 13:45:09 | 00,016,384 | —- | M] ()
Perflib_Perfdata_498.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_498.dat -> [2009/01/12 11:43:49 | 00,016,384 | —- | M] ()
Perflib_Perfdata_dd0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dd0.dat -> [2009/01/11 18:38:50 | 00,016,384 | —- | M] ()
Perflib_Perfdata_924.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_924.dat -> [2009/01/07 11:43:56 | 00,016,384 | —- | M] ()
Perflib_Perfdata_6ec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6ec.dat -> [2009/01/07 11:35:50 | 00,016,384 | —- | M] ()
_ISUser.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_ISUser.dll -> [2008/12/23 22:59:42 | 00,012,288 | —- | M] ()
nvupnp-amd64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnp-amd64.exe -> [2008/12/23 22:59:22 | 00,028,160 | —- | M] ()
nvupnpbr.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnpbr.exe -> [2008/12/23 22:59:18 | 00,032,768 | —- | M] ()
nvuninst-amd64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvuninst-amd64.exe -> [2008/12/23 22:59:08 | 00,501,280 | —- | M] (NVIDIA Corporation)
NVUninst.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\NVUninst.exe -> [2008/12/23 22:58:50 | 00,453,152 | —- | M] (NVIDIA Corporation)
NvInstNT.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\NvInstNT.dll -> [2008/12/23 22:58:02 | 00,229,376 | —- | M] (NVIDIA Corporation)
setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD36.tmp\setup.exe -> [2008/12/17 11:56:42 | 00,467,456 | R— | M] ()
ci.dll -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\ci.dll -> [2008/10/04 12:12:16 | 01,119,232 | —- | M] (Google)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\GoogleUpdaterInstallMgr.exe -> [2008/10/04 12:12:16 | 00,834,032 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\GoogleUpdaterAdminPrefs.exe -> [2008/10/04 12:12:16 | 00,228,336 | —- | M] (Google)
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\GoogleUpdaterSetup.exe -> [2008/10/04 12:12:16 | 00,175,600 | —- | M] (Google Inc.)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis7ff3d\GoogleUpdaterService.exe -> [2008/10/04 12:12:16 | 00,168,432 | —- | M] (Google)
GoogleUpdater.exe -> C:\WINDOWS\Temp\gis7ff3d\GoogleUpdater.exe -> [2008/10/04 12:12:16 | 00,161,264 | —- | M] (Google)
npCIDetect13.dll -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\npCIDetect13.dll -> [2008/10/04 12:12:16 | 00,094,208 | —- | M] (Google)
cires.dll -> C:\WINDOWS\Temp\gis7ff3d\2.4.1368.5602\cires.dll -> [2008/10/04 12:12:16 | 00,094,208 | —- | M] ()
Common.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\Common.dll -> [2008/10/02 10:23:36 | 00,094,208 | —- | M] (Creative Technology Ltd.)
_ISUSER.DLL -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\_ISUSER.DLL -> [2008/10/02 02:17:00 | 00,167,936 | —- | M] (Creative Technology Ltd.)
_ISUser.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_ISUser.dll -> [2008/08/22 03:00:46 | 00,012,288 | —- | M] ()
nvupnp-amd64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnp-amd64.exe -> [2008/08/22 03:00:38 | 00,028,160 | —- | M] ()
nvupnpbr.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnpbr.exe -> [2008/08/22 03:00:34 | 00,032,768 | —- | M] ()
nvuninst-amd64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvuninst-amd64.exe -> [2008/08/22 03:00:24 | 00,501,280 | —- | M] (NVIDIA Corporation)
NVUninst.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\NVUninst.exe -> [2008/08/22 03:00:16 | 00,453,152 | —- | M] (NVIDIA Corporation)
NvInstNT.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\NvInstNT.dll -> [2008/08/22 03:00:04 | 00,221,184 | —- | M] (NVIDIA Corporation)
_ISUSER.DLL -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{4E17F823-EE0E-4B3B-B6FA-6EAA3354DDD7}\{886A66BC-2255-4379-A88A-F523258A5746}\_ISUSER.DLL -> [2008/07/11 03:15:00 | 00,167,936 | —- | M] (Creative Technology Ltd.)
_isressm.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_isressm.dll -> [2008/06/25 20:10:30 | 00,299,008 | —- | M] (InstallShield Software Corporation)
nvuninst-ia64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvuninst-ia64.exe -> [2008/06/25 20:10:30 | 00,242,688 | —- | M] (NVIDIA Corporation)
nvupnp-ia64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnp-ia64.exe -> [2008/06/25 20:10:30 | 00,056,832 | —- | M] ()
_isressm.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_isressm.dll -> [2008/06/20 16:45:00 | 00,299,008 | —- | M] (InstallShield Software Corporation)
nvuninst-ia64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvuninst-ia64.exe -> [2008/06/20 16:45:00 | 00,242,688 | —- | M] (NVIDIA Corporation)
nvupnp-ia64.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\nvupnp-ia64.exe -> [2008/06/20 16:45:00 | 00,056,832 | —- | M] ()
Perflib_Perfdata_b8c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b8c.dat -> [2008/04/14 20:36:13 | 00,016,384 | —- | M] ()
ci.dll -> C:\WINDOWS\Temp\gis13cb758\ci.dll -> [2008/04/10 21:57:43 | 00,877,056 | —- | M] (Google)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis13cb758\GoogleUpdaterInstallMgr.exe -> [2008/04/10 21:57:43 | 00,666,296 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis13cb758\GoogleUpdaterAdminPrefs.exe -> [2008/04/10 21:57:43 | 00,187,064 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis13cb758\GoogleUpdaterService.exe -> [2008/04/10 21:57:43 | 00,138,680 | —- | M] (Google)
cires_en.dll -> C:\WINDOWS\Temp\gis13cb758\cires_en.dll -> [2008/04/10 21:57:43 | 00,125,952 | —- | M] ()
GoogleUpdater.exe -> C:\WINDOWS\Temp\gis13cb758\GoogleUpdater.exe -> [2008/04/10 21:57:43 | 00,125,624 | —- | M] (Google)
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis13cb758\GoogleUpdaterSetup.exe -> [2008/04/10 21:57:43 | 00,125,624 | —- | M] (Google Inc.)
npCIDetect11.dll -> C:\WINDOWS\Temp\gis13cb758\npCIDetect11.dll -> [2008/04/10 21:57:43 | 00,083,968 | —- | M] (Google)
gtfirstboot.exe -> C:\WINDOWS\Temp\gis13cb758\gtfirstboot.exe -> [2008/04/10 21:57:43 | 00,065,536 | —- | M] ()
Perflib_Perfdata_d28.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d28.dat -> [2008/04/10 15:55:36 | 00,016,384 | —- | M] ()
Perflib_Perfdata_cc8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cc8.dat -> [2008/04/10 15:53:13 | 00,016,384 | —- | M] ()
RealOneArcadeBundle.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\__ArcadeDownloadFoler__supermahjong_EN_eldnub\RealOneArcadeBundle.exe -> [2008/03/08 03:42:37 | 12,878,405 | —- | M] (RealNetworks, Inc.)
RngcBundler.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\__ArcadeDownloadFoler__supermahjong_EN_eldnub\RngcBundler.exe -> [2008/03/08 03:42:20 | 00,148,616 | —- | M] (RealNetworks)
RealOneArcadeBundle.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\__ArcadeDownloadFoler__realarcade_EN_eldnub\RealOneArcadeBundle.exe -> [2008/03/08 03:39:00 | 10,979,340 | —- | M] (RealNetworks, Inc.)
RngcBundler.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\__ArcadeDownloadFoler__realarcade_EN_eldnub\RngcBundler.exe -> [2008/03/08 03:38:44 | 00,148,616 | —- | M] (RealNetworks)
Perflib_Perfdata_a10.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a10.dat -> [2008/02/20 11:43:31 | 00,016,384 | —- | M] ()
Perflib_Perfdata_fb0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fb0.dat -> [2008/01/02 16:11:06 | 00,016,384 | —- | M] ()
Perflib_Perfdata_b54.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b54.dat -> [2007/12/28 14:29:09 | 00,016,384 | —- | M] ()
Perflib_Perfdata_c04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c04.dat -> [2007/10/05 20:01:33 | 00,016,384 | —- | M] ()
Perflib_Perfdata_cd0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cd0.dat -> [2007/09/29 18:58:26 | 00,016,384 | —- | M] ()
Perflib_Perfdata_a8c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a8c.dat -> [2007/09/28 11:01:08 | 00,016,384 | —- | M] ()
ci.dll -> C:\WINDOWS\Temp\gis128c69\ci.dll -> [2007/08/10 09:36:38 | 00,908,800 | —- | M] (Google)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis128c69\GoogleUpdaterInstallMgr.exe -> [2007/08/10 09:36:38 | 00,664,560 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis128c69\GoogleUpdaterAdminPrefs.exe -> [2007/08/10 09:36:38 | 00,185,840 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis128c69\GoogleUpdaterService.exe -> [2007/08/10 09:36:38 | 00,138,680 | —- | M] (Google)
cires_en.dll -> C:\WINDOWS\Temp\gis128c69\cires_en.dll -> [2007/08/10 09:36:38 | 00,126,464 | —- | M] ()
GoogleUpdater.exe -> C:\WINDOWS\Temp\gis128c69\GoogleUpdater.exe -> [2007/08/10 09:36:38 | 00,124,912 | —- | M] (Google)
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis128c69\GoogleUpdaterSetup.exe -> [2007/08/10 09:36:38 | 00,124,400 | —- | M] (Google Inc.)
npCIDetect11.dll -> C:\WINDOWS\Temp\gis128c69\npCIDetect11.dll -> [2007/08/10 09:36:38 | 00,083,968 | —- | M] (Google)
gtfirstboot.exe -> C:\WINDOWS\Temp\gis128c69\gtfirstboot.exe -> [2007/08/10 09:36:38 | 00,065,536 | —- | M] ()
Perflib_Perfdata_ebc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ebc.dat -> [2007/08/05 08:48:15 | 00,016,384 | —- | M] ()
HijackThis.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe -> [2007/06/28 14:36:16 | 00,401,720 | —- | M] (Trend Micro Inc.)
ci.dll -> C:\WINDOWS\Temp\gis2c791ed\ci.dll -> [2007/06/03 23:29:41 | 00,887,808 | —- | M] (Google)
SearchWithGoogleUpdate_en.exe -> C:\WINDOWS\Temp\gis2c791ed\SearchWithGoogleUpdate_en.exe -> [2007/06/03 23:29:41 | 00,742,328 | —- | M] (Google Inc.)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis2c791ed\GoogleUpdaterInstallMgr.exe -> [2007/06/03 23:29:41 | 00,649,976 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis2c791ed\GoogleUpdaterAdminPrefs.exe -> [2007/06/03 23:29:41 | 00,185,080 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis2c791ed\GoogleUpdaterService.exe -> [2007/06/03 23:29:41 | 00,138,680 | —- | M] (Google)
GoogleUpdater.exe -> C:\WINDOWS\Temp\gis2c791ed\GoogleUpdater.exe -> [2007/06/03 23:29:41 | 00,125,176 | —- | M] (Google)
cires_en.dll -> C:\WINDOWS\Temp\gis2c791ed\cires_en.dll -> [2007/06/03 23:29:41 | 00,124,928 | —- | M] ()
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis2c791ed\GoogleUpdaterSetup.exe -> [2007/06/03 23:29:41 | 00,124,664 | —- | M] (Google Inc.)
npCIDetect11.dll -> C:\WINDOWS\Temp\gis2c791ed\npCIDetect11.dll -> [2007/06/03 23:29:41 | 00,083,968 | —- | M] (Google)
ci.dll -> C:\WINDOWS\Temp\gisa8aecc\ci.dll -> [2007/05/20 14:25:49 | 00,886,784 | —- | M] (Google)
SearchWithGoogleUpdate_en.exe -> C:\WINDOWS\Temp\gisa8aecc\SearchWithGoogleUpdate_en.exe -> [2007/05/20 14:25:49 | 00,742,328 | —- | M] (Google Inc.)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gisa8aecc\GoogleUpdaterInstallMgr.exe -> [2007/05/20 14:25:49 | 00,648,952 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gisa8aecc\GoogleUpdaterAdminPrefs.exe -> [2007/05/20 14:25:49 | 00,185,080 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gisa8aecc\GoogleUpdaterService.exe -> [2007/05/20 14:25:49 | 00,138,680 | —- | M] (Google)
GoogleUpdater.exe -> C:\WINDOWS\Temp\gisa8aecc\GoogleUpdater.exe -> [2007/05/20 14:25:49 | 00,125,176 | —- | M] (Google)
cires_en.dll -> C:\WINDOWS\Temp\gisa8aecc\cires_en.dll -> [2007/05/20 14:25:49 | 00,124,928 | —- | M] ()
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gisa8aecc\GoogleUpdaterSetup.exe -> [2007/05/20 14:25:49 | 00,124,664 | —- | M] (Google Inc.)
npCIDetect11.dll -> C:\WINDOWS\Temp\gisa8aecc\npCIDetect11.dll -> [2007/05/20 14:25:49 | 00,083,968 | —- | M] (Google)
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD20A6.tmp\dotnetfx\dotnetchk.exe -> [2007/05/16 02:27:30 | 00,061,632 | —- | M] (Microsoft Corporation)
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD20A0.tmp\dotnetfx\dotnetchk.exe -> [2007/05/16 02:26:36 | 00,061,632 | —- | M] (Microsoft Corporation)
dotnetinstaller.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\dotnetinstaller.exe -> [2007/04/24 18:21:26 | 00,010,704 | —- | M] (InstallShield Software Corporation)
isrt.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\isrt.dll -> [2007/04/24 18:20:48 | 00,222,144 | —- | M] (Macrovision Corporation)
dotnetinstaller.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\dotnetinstaller.exe -> [2007/04/24 17:21:26 | 00,010,704 | —- | M] (InstallShield Software Corporation)
isrt.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\isrt.dll -> [2007/04/24 17:20:48 | 00,222,144 | —- | M] (Macrovision Corporation)
_IsRes.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{0E736B96-51F3-4FA4-A1E2-A93288404748}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_IsRes.dll -> [2007/04/18 21:14:10 | 00,103,424 | —- | M] (Macrovision Corporation)
_IsRes.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{EA5543D6-9B08-4E0B-BF75-C8E766D4786A}\{EFB7D050-CAD2-11D4-B34D-00105A1C23DD}\_IsRes.dll -> [2007/04/18 20:14:10 | 00,103,424 | —- | M] (Macrovision Corporation)
The_Weather_Channel_Application.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\The_Weather_Channel_Application.exe -> [2007/04/14 00:57:05 | 00,234,278 | —- | M] ()
ci.dll -> C:\WINDOWS\Temp\gis88b41\ci.dll -> [2007/03/31 20:11:31 | 00,882,176 | —- | M] (Google)
SearchWithGoogleUpdate_en.exe -> C:\WINDOWS\Temp\gis88b41\SearchWithGoogleUpdate_en.exe -> [2007/03/31 20:11:31 | 00,741,304 | —- | M] (Google Inc.)
GoogleUpdaterInstallMgr.exe -> C:\WINDOWS\Temp\gis88b41\GoogleUpdaterInstallMgr.exe -> [2007/03/31 20:11:31 | 00,645,880 | —- | M] (Google)
GoogleUpdaterAdminPrefs.exe -> C:\WINDOWS\Temp\gis88b41\GoogleUpdaterAdminPrefs.exe -> [2007/03/31 20:11:31 | 00,184,056 | —- | M] (Google)
GoogleUpdaterService.exe -> C:\WINDOWS\Temp\gis88b41\GoogleUpdaterService.exe -> [2007/03/31 20:11:31 | 00,136,952 | —- | M] (Google)
cires_en.dll -> C:\WINDOWS\Temp\gis88b41\cires_en.dll -> [2007/03/31 20:11:31 | 00,124,928 | —- | M] ()
GoogleUpdater.exe -> C:\WINDOWS\Temp\gis88b41\GoogleUpdater.exe -> [2007/03/31 20:11:31 | 00,124,152 | —- | M] (Google)
GoogleUpdaterSetup.exe -> C:\WINDOWS\Temp\gis88b41\GoogleUpdaterSetup.exe -> [2007/03/31 20:11:31 | 00,123,640 | —- | M] (Google Inc.)
npCIDetect10.dll -> C:\WINDOWS\Temp\gis88b41\npCIDetect10.dll -> [2007/03/31 20:11:31 | 00,083,968 | —- | M] (Google)
UninstallRC-8876480.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\UninstallRC-8876480.dll -> [2007/03/19 19:04:32 | 00,065,536 | —- | M] ()
GLF40.EXE -> C:\WINDOWS\Temp\GLF40.EXE -> [2007/03/16 07:55:06 | 00,167,171 | —- | M] ()
opa12.dat -> C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2007/03/07 08:34:29 | 00,008,410 | —- | M] ()
LOCK.EXE -> C:\WINDOWS\Temp\LOCK.EXE -> [2007/02/12 15:50:18 | 00,651,264 | —- | M] ()
ufddll.dll -> C:\WINDOWS\Temp\ufddll.dll -> [2007/02/12 15:50:18 | 00,229,376 | —- | M] ()
FORMAT.EXE -> C:\WINDOWS\Temp\FORMAT.EXE -> [2006/11/22 11:07:26 | 01,327,104 | —- | M] ()
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD37.tmp\dotnetfx\dotnetchk.exe -> [2006/10/12 11:09:29 | 00,061,632 | —- | M] (Microsoft Corporation)
RegEdit.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\RegEdit.dll -> [2006/08/28 01:00:00 | 00,057,344 | —- | M] (Creative Technology Ltd)
InstHelp.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\InstHelp.exe -> [2006/08/24 01:00:00 | 00,051,200 | —- | M] (Creative Technology Ltd)
index.dat -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat -> [2006/08/01 08:45:06 | 00,032,768 | —- | M] ()
dotnetfx.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD3.tmp\dotnetfx\dotnetfx.exe -> [2006/07/31 11:51:38 | 23,510,720 | —- | M] (Microsoft Corporation)
dotnetchk.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD3.tmp\dotnetfx\dotnetchk.exe -> [2006/07/31 11:51:09 | 00,061,632 | —- | M] (Microsoft Corporation)
setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\VSD3.tmp\setup.exe -> [2006/06/06 01:15:36 | 00,430,592 | R— | M] ()
Inst.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for GBU221-321.zip\GBU221-321\Win32\Inst.exe -> [2006/04/12 10:33:08 | 00,253,952 | —- | M] (					   )
Setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for GBU221-321.zip\GBU221-321\Win32\Setup.exe -> [2006/04/12 09:20:16 | 00,090,112 | —- | M] (Broadcom Corporation.)
Setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for GBU221-321.zip\GBU221-321\Setup.exe -> [2006/04/12 09:20:16 | 00,090,112 | —- | M] (Broadcom Corporation.)
_setup.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\_setup.dll -> [2004/08/25 01:00:00 | 00,368,640 | —- | M] (InstallShield Software Corporation)
CTCabEx.DLL -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{4E17F823-EE0E-4B3B-B6FA-6EAA3354DDD7}\{886A66BC-2255-4379-A88A-F523258A5746}\CTCabEx.DLL -> [2004/03/25 02:10:00 | 00,286,720 | —- | M] (Creative Technology Ltd.)
CTCabEx.DLL -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\{07911EC8-E29C-4153-9456-11F042EAC973}\{888347B3-AEC5-4BB5-8BAB-781D72A57C73}\CTCabEx.DLL -> [2004/03/25 02:10:00 | 00,286,720 | —- | M] (Creative Technology Ltd.)
TFR84.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\TFR84.exe -> [2004/03/22 12:22:16 | 00,132,608 | —- | M] (Microsoft Corp.)
setup.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\setup.exe -> [2003/10/08 23:11:54 | 00,225,280 | R— | M] (WIDCOMM, Inc.											   )
BtBalloon.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\BtBalloon.dll -> [2003/09/14 20:54:40 | 00,036,864 | R— | M] (WIDCOMM, Inc.)
install.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\install.exe -> [2003/09/11 02:16:20 | 00,616,960 | R— | M] ()
btw_ci.dll -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\btw_ci.dll -> [2003/08/13 22:36:56 | 00,077,824 | R— | M] (WIDCOMM, Inc.)
BtserverSpylite.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\BtserverSpylite.exe -> [2003/08/13 22:34:26 | 00,344,064 | R— | M] (WIDCOMM, Inc.)
license.dat -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\license.dat -> [2003/08/06 00:28:18 | 00,000,176 | R— | M] ()
MSVCP60.DLL -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\MSVCP60.DLL -> [2003/06/12 00:38:42 | 00,401,462 | R— | M] (Microsoft Corporation)
instmsia.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\instmsia.exe -> [2002/03/11 07:45:04 | 01,708,856 | R— | M] (Microsoft Corporation)
instmsiw.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Temporary Directory 1 for Bluetooth1.4.2_Build_10.zip\instmsiw.exe -> [2002/03/10 19:06:30 | 01,822,520 | R— | M] (Microsoft Corporation)
migload.exe -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\usmt\migload.exe -> [2001/08/17 23:36:48 | 00,098,816 | —- | M] (Microsoft Corporation)
 
[File - Lop Check]
Application Data -> C:\Documents and Settings\Administrator\Application Data -> [2006/07/31 03:41:25 | 00,000,000 | RH-D | M]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2006/07/29 07:59:11 | 00,000,000 | RH-D | M]
Ulead Systems -> C:\Documents and Settings\All Users\Application Data\Ulead Systems -> [2006/07/27 23:21:47 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\All Users.WINDOWS\Application Data -> [2009/06/15 11:03:05 | 00,000,000 | RH-D | M]
{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} -> C:\Documents and Settings\All Users.WINDOWS\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3} -> [2009/03/12 16:10:33 | 00,000,000 | —D | M]
{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> C:\Documents and Settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} -> [2009/04/14 15:49:04 | 00,000,000 | —D | M]
eFax Messenger 4.3 Output -> C:\Documents and Settings\All Users.WINDOWS\Application Data\eFax Messenger 4.3 Output -> [2007/05/11 16:56:01 | 00,000,000 | —D | M]
eFax Messenger 4.3 Setup -> C:\Documents and Settings\All Users.WINDOWS\Application Data\eFax Messenger 4.3 Setup -> [2007/05/11 16:55:56 | 00,000,000 | —D | M]
LogiShrd -> C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd -> [2008/05/01 23:43:46 | 00,000,000 | —D | M]
RoboForm -> C:\Documents and Settings\All Users.WINDOWS\Application Data\RoboForm -> [2007/07/31 09:34:37 | 00,000,000 | —D | M]
TEMP -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP -> [2009/02/16 13:53:00 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Default User\Application Data -> [2006/07/27 15:54:15 | 00,000,000 | RH-D | M]
Application Data -> C:\Documents and Settings\Default User.WINDOWS\Application Data -> [2006/07/31 03:41:25 | 00,000,000 | RH-D | M]
Application Data -> C:\Documents and Settings\Guest\Application Data -> [2009/01/18 13:32:04 | 00,000,000 | RH-D | M]
ArcSoft -> C:\Documents and Settings\Guest\Application Data\ArcSoft -> [2009/01/18 13:00:19 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService\Application Data -> [2006/07/27 23:08:09 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data -> [2006/07/31 11:00:58 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\Missy's Gamer\Application Data -> [2009/02/16 12:03:02 | 00,000,000 | RH-D | M]
Application Data -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data -> [2009/06/15 11:21:47 | 00,000,000 | RH-D | M]
ArcSoft -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\ArcSoft -> [2009/01/11 18:45:20 | 00,000,000 | —D | M]
eFax Messenger -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\eFax Messenger -> [2007/07/29 11:27:51 | 00,000,000 | —D | M]
ICAClient -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\ICAClient -> [2006/10/21 08:26:20 | 00,000,000 | —D | M]
ImgBurn -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\ImgBurn -> [2009/01/13 15:14:48 | 00,000,000 | —D | M]
Move Networks -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Move Networks -> [2009/05/16 12:52:17 | 00,000,000 | -H-D | M]
MSNInstaller -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\MSNInstaller -> [2009/03/17 22:10:50 | 00,000,000 | —D | M]
SupportSoft -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\SupportSoft -> [2008/08/17 14:24:44 | 00,000,000 | —D | M]
TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1 -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1 -> [2009/04/26 23:40:26 | 00,000,000 | —D | M]
U3 -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\U3 -> [2007/07/10 01:42:20 | 00,000,000 | —D | M]
Ventrilo -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Ventrilo -> [2008/11/27 22:19:04 | 00,000,000 | —D | M]
VersionTracker Pro -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\VersionTracker Pro -> [2009/01/13 09:49:41 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService\Application Data -> [2006/07/27 23:07:57 | 00,000,000 | —D | M]
Application Data -> C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data -> [2006/07/31 10:58:52 | 00,000,000 | —D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2009/06/15 11:21:47 | 00,000,000 | –SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2009/06/11 15:45:02 | 00,000,284 | —- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2006/02/28 05:00:00 | 00,000,065 | RH– | M] ()
FRU Task #Hewlett-Packard#hp psc 2100 series#1181011518.job -> C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1181011518.job -> [2007/09/15 21:33:29 | 00,000,358 | —- | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2009/06/15 11:26:23 | 00,000,006 | -H– | M] ()
 
[File - Purity Scan]
 
 
[Alternate Data Streams]
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
< End of report >

Malwarebytes' Anti-Malware 1.37
Database version: 2284
Windows 5.1.2600 Service Pack 3

6/15/2009 11:21:47 AM
mbam-log-2009-06-15 (11-21-47).txt

Scan type: Quick Scan
Objects scanned: 129589
Time elapsed: 1 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 8
Files Infected: 217

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\winapp.winsafe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\winapp.winsafe.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{16406580-14ce-4441-b904-ad56cc8064ca} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6b571fb-b71d-449c-ad70-82e966328795} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\Log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\Quarantine (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25 (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42 (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44 (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35 (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\Settings (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\fp.dat (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\Log\2009 Jun 14 - 03_00_03 AM_343.log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\Log\2009 Jun 14 - 03_00_03 AM_765.log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\0.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\0.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\1.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\1.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\10.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\10.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\11.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\11.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\12.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\12.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\13.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\13.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\14.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\14.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\15.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\15.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\16.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\16.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\17.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\17.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\18.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\18.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\19.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\19.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\2.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\2.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\20.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\20.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\21.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\21.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\22.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\22.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\23.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\23.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\24.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\24.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\25.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\25.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\26.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\26.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\27.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\27.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\28.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\28.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\29.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\29.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\3.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\3.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\30.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\30.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\31.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\31.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\32.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\32.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\33.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\33.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\34.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\34.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\35.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\35.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\4.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\4.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\5.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\5.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\6.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\6.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\7.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\7.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\8.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\8.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\9.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\14-06-2009-03-19-25\9.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\0.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\0.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\1.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\1.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\10.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\10.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\11.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\11.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\12.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\12.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\13.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\13.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\14.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\14.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\15.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\15.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\16.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\16.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\17.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\17.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\18.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\18.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\19.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\19.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\2.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\2.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\20.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\20.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\21.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\21.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\22.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\22.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\23.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\23.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\24.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\24.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\25.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\25.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\26.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\26.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\27.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\27.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\28.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\28.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\29.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\29.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\3.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\3.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\4.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\4.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\5.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\5.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\6.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\6.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\7.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\7.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\8.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\8.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\9.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\18-05-2009-00-02-42\9.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\0.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\0.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\1.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\1.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\10.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\10.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\11.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\11.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\12.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\12.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\13.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\13.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\14.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\14.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\15.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\15.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\2.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\2.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\3.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\3.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\4.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\4.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\5.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\5.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\6.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\6.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\7.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\7.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\8.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\8.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\9.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\24-05-2009-10-05-44\9.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\0.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\0.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\1.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\1.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\10.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\10.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\11.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\11.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\12.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\12.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\13.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\13.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\14.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\14.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\15.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\15.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\16.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\16.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\17.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\17.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\18.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\18.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\19.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\19.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\2.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\2.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\20.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\20.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\21.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\21.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\22.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\22.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\3.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\3.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\4.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\4.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\5.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\5.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\6.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\6.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\7.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\7.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\8.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\8.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\9.qit (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\documents and settings\missy's gamer.sherri-78c7b973\application data\malwareremovalbot\quarantine\28-05-2009-06-40-35\9.qnf (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\UAClhtkbgot.dat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\UACvpokiqsp.log (Trojan.Agent) -> Quarantined and deleted successfully.
Looks like you had a rootkit there - so lets finish it off

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
[Files/Folders - Modified Within 30 Days]
NY -> 3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 19 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> 1 C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\*.tmp files -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\*.tmp
NY -> 1843 C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\*.tmp
NY -> 5 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

I will review the information when it comes back in.

THEN

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
[Registry - Safe List] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found. Registry value HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found. Registry value HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{724D43A0-0D85-11D4-9908-00400523E39A}\ not found. Registry value HKEY_USERS\S-1-5-21-1454471165-602609370-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6}\ not found. [Files/Folders - Modified Within 30 Days] [Empty Temp Folders] [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: All Users.WINDOWS User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User.WINDOWS ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService.NT AUTHORITY ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 33170 bytes User: Missy's Gamer ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: MISSY's GAMER.SHERRI-78C7B973 File delete failed. C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Perflib_Perfdata_d90.dat scheduled to be deleted on reboot. ->Temp folder emptied: 16384 bytes File delete failed. C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 1167250 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes User: MISSY'~1~SHE User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService.NT AUTHORITY ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_280.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_65c.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 33251 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.41 mb < End of fix log > OTS by OldTimer - Version 3.0.5.3 fix logfile created on 06152009_175522 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\MISSY's GAMER.SHERRI-78C7B973\Local Settings\Temp\Perflib_Perfdata_d90.dat not found! File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_280.dat not found! File move failed. C:\WINDOWS\temp\Perflib_Perfdata_65c.dat scheduled to be moved on reboot. Registry entries deleted on Reboot…
ComboFix 09-06-15.05 - MISSY's GAMER 06/15/2009 19:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2841 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090615-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *enabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_UACD.SYS
——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 00:50 . 2009-06-16 00:50 ——– d—–w- C:\_OTS
2009-06-15 19:19 . 2009-06-15 19:19 ——– d—–w- c:\program files\ieSpell
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Malwarebytes
2009-06-15 18:03 . 2009-05-26 20:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-06-15 18:03 . 2009-05-26 20:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 07:52 . 2009-06-15 07:52 ——– d—–w- c:\program files\TweakCoH
2009-06-15 01:07 . 2009-06-15 01:10 19558 —-a-w- c:\windows\hpoins01.dat
2009-06-15 01:07 . 2003-04-22 17:24 16606 ——w- c:\windows\hpomdl01.dat
2009-06-15 00:30 . 2009-06-15 00:30 ——– d—–w- c:\program files\Driver Sweeper
2009-06-14 18:28 . 2009-06-14 18:28 ——– d—–w- c:\program files\Trend Micro
2009-06-14 14:59 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-14 14:59 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-14 14:59 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-14 14:59 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-14 14:59 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-14 14:59 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-06-14 14:59 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-14 14:59 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-14 14:59 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-06-13 07:16 . 2009-06-13 07:16 ——– d—–w- c:\program files\TweetDeck
2009-06-12 04:22 . 2009-06-12 04:22 ——– d-sh–w- c:\documents and settings\Default User.WINDOWS\IETldCache
2009-06-12 04:19 . 2009-06-12 04:19 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-12 03:48 . 2009-06-12 03:48 ——– d—–w- c:\program files\SystemRequirementsLab
2009-06-10 07:34 . 2009-06-10 07:34 ——– d—–w- c:\program files\iPod
2009-06-10 07:34 . 2009-06-10 07:34 ——– d—–w- c:\program files\iTunes
2009-06-10 07:32 . 2009-06-10 07:33 ——– d—–w- c:\program files\QuickTime
2009-06-10 07:28 . 2009-06-10 07:28 75048 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-28 14:09 . 2009-05-28 14:09 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Google
2009-05-22 03:12 . 2009-05-22 03:13 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\vlc
2009-05-22 03:10 . 2009-05-22 03:10 ——– d—–w- c:\program files\VideoLAN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 16:50 . 2006-07-31 19:19 ——– d—–w- c:\program files\City of Heroes
2009-06-15 09:32 . 2009-01-20 18:34 ——– d—–w- c:\program files\Glycerine
2009-06-15 07:03 . 2006-08-15 01:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-06-15 06:47 . 2006-07-31 18:56 ——– d—–w- c:\program files\City Game Tracker
2009-06-15 02:17 . 2009-03-15 09:51 ——– d—–w- c:\program files\NOS
2009-06-15 02:17 . 2009-03-15 09:51 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2009-06-15 02:05 . 2007-02-23 04:57 ——– d—–w- c:\program files\Google
2009-06-15 01:59 . 2006-07-28 18:13 ——– d—–w- c:\program files\Logitech
2009-06-15 01:44 . 2009-04-23 02:06 ——– d—–w- c:\program files\Fstcv101
2009-06-15 01:39 . 2008-01-06 03:46 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Yahoo!
2009-06-15 01:39 . 2008-01-06 03:45 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2009-06-15 01:38 . 2009-04-22 03:19 ——– d—–w- c:\program files\Poker Pages Odds Calculator
2009-06-15 01:37 . 2006-08-11 20:29 ——– d—–w- c:\program files\Java
2009-06-15 01:30 . 2008-03-08 05:56 ——– d—–w- c:\program files\Real
2009-06-15 01:28 . 2008-03-08 05:56 ——– d—–w- c:\program files\Common Files\Real
2009-06-15 01:28 . 2008-01-02 23:44 ——– d—–w- c:\program files\Poker Tracker V2
2009-06-14 21:59 . 2006-07-29 00:00 ——– d—–w- c:\program files\SpeedFan
2009-06-12 03:52 . 2008-02-09 19:31 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-12 03:52 . 2009-01-12 20:58 ——– d—–w- c:\program files\AGEIA Technologies
2009-06-10 07:34 . 2008-05-07 01:31 ——– d—–w- c:\program files\Common Files\Apple
2009-05-21 18:33 . 2008-12-06 21:11 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 19:52 . 2007-04-17 23:07 ——– d–h–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Move Networks
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-05-01 07:31 . 2009-05-01 07:31 1657376 —-a-w- c:\windows\system32\nwiz.exe
2009-05-01 07:31 . 2009-05-01 07:31 449056 —-a-w- c:\windows\system32\nvappbar.exe
2009-05-01 07:31 . 2009-05-01 07:31 436768 —-a-w- c:\windows\system32\keystone.exe
2009-05-01 07:31 . 2009-05-01 07:31 466944 —-a-w- c:\windows\system32\nvshell.dll
2009-05-01 07:31 . 2009-05-01 07:31 1724416 —-a-w- c:\windows\system32\nvwdmcpl.dll
2009-05-01 07:31 . 2009-05-01 07:31 1507328 —-a-w- c:\windows\system32\nview.dll
2009-05-01 07:31 . 2009-05-01 07:31 1101824 —-a-w- c:\windows\system32\nvwimg.dll
2009-05-01 05:02 . 2009-05-01 05:02 663552 —-a-w- c:\windows\system32\nvcuvid.dll
2009-05-01 05:02 . 2009-05-01 05:02 1579630 —-a-w- c:\windows\system32\nvdata.bin
2009-05-01 05:02 . 2009-05-01 05:02 1314816 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-05-01 05:02 . 2008-12-26 08:08 9994240 —-a-w- c:\windows\system32\nvoglnt.dll
2009-05-01 05:02 . 2008-12-26 08:08 806912 —-a-w- c:\windows\system32\nvapi.dll
2009-05-01 05:02 . 2008-12-26 08:08 1720320 —-a-w- c:\windows\system32\nvcuda.dll
2009-05-01 05:02 . 2008-12-26 08:08 143360 —-a-w- c:\windows\system32\nvcodins.dll
2009-05-01 05:02 . 2008-12-26 08:08 143360 —-a-w- c:\windows\system32\nvcod.dll
2009-05-01 05:02 . 2006-07-31 18:17 457248 —-a-w- c:\windows\system32\nvudisp.exe
2009-05-01 05:02 . 2006-06-02 00:22 8055584 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-05-01 05:02 . 2006-06-02 00:22 5896320 —-a-w- c:\windows\system32\nv4_disp.dll
2009-04-27 07:42 . 2006-07-31 18:17 457248 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-04-27 06:40 . 2009-04-27 06:40 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-04-27 06:40 . 2009-04-27 06:40 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-04-27 06:39 . 2009-04-27 06:40 38208 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-04-03 19:39 . 2009-04-03 19:39 70936 —-a-w- c:\windows\system32\PhysXLoader.dll
2009-04-01 18:33 . 2009-04-01 18:33 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-23 13:29 . 2009-03-23 13:29 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 23:32 . 2008-01-29 19:01 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 05:10 . 2009-03-18 05:10 1244648 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\MSNInstaller\msnauins.exe
2008-03-08 10:39 . 2008-03-08 10:39 774144 —-a-w- c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"eFax 4.3"="c:\program files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 116224]
"UMonit"="c:\windows\system32\UMonit.exe" [2006-11-16 200704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-06-01 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-06-01 18944]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-05-01 1657376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 7:59 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 7:59 AM 20560]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [9/2/2006 2:06 PM 3712]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [7/31/2006 8:52 PM 70016]
S2 yuiovfyw;yuiovfyw;\??\c:\windows\system32\drivers\yejlru.sys –> c:\windows\system32\drivers\yejlru.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [1/12/2009 4:45 PM 79360]
S3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [1/4/2008 4:38 PM 12672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vuiovf REG_MULTI_SZ vuiovf

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2007-09-16 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2100 series272A572217594EBCF1CEE215E352B92AD073FDE4181011518.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-10 00:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: Send to &Bluetooth Device… - c:\program files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 19:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\nvappfilter.dll

- - - - - - - > 'explorer.exe'(2352)
c:\windows\system32\ctagent.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IOGEAR\Bluetooth Software\bin\btwdins.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\LxrSII1s.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\CF21956.exe
c:\windows\system32\CTXFISPI.EXE
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\program files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
c:\program files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
c:\program files\Logitech\G-series Software\Applets\LCDMedia.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-16 19:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-16 02:55

Pre-Run: 284,465,844,224 bytes free
Post-Run: 284,355,973,120 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
245 — E O F — 2009-03-18 08:33
Looks like just one more to get, how is your computer running ?

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\system32\drivers\yejlru.sys

Driver::
yuiovfyw

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
The system seems much cleaner, and is booting faster. I haven't really checked anything else out yet. I'm just thrilled to get rid of those freeloading apps, really annoys me :)

Thanks again for your awsome help!
-Bliss


ComboFix 09-06-15.07 - MISSY's GAMER 06/16/2009 11:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2874 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090616-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *enabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}

FILE ::
"c:\windows\system32\drivers\yejlru.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_YUIOVFYW
——-\Service_yuiovfyw


((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 00:50 . 2009-06-16 00:50 ——– d—–w- C:\_OTS
2009-06-15 19:19 . 2009-06-15 19:19 ——– d—–w- c:\program files\ieSpell
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Malwarebytes
2009-06-15 18:03 . 2009-05-26 20:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 18:03 . 2009-06-15 18:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-06-15 18:03 . 2009-05-26 20:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 07:52 . 2009-06-15 07:52 ——– d—–w- c:\program files\TweakCoH
2009-06-15 01:07 . 2009-06-15 01:10 19558 —-a-w- c:\windows\hpoins01.dat
2009-06-15 01:07 . 2003-04-22 17:24 16606 ——w- c:\windows\hpomdl01.dat
2009-06-15 00:30 . 2009-06-15 00:30 ——– d—–w- c:\program files\Driver Sweeper
2009-06-14 18:28 . 2009-06-14 18:28 ——– d—–w- c:\program files\Trend Micro
2009-06-14 14:59 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-14 14:59 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-14 14:59 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-14 14:59 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-14 14:59 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-14 14:59 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-06-14 14:59 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-14 14:59 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-14 14:59 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-06-13 07:16 . 2009-06-13 07:16 ——– d—–w- c:\program files\TweetDeck
2009-06-12 04:22 . 2009-06-12 04:22 ——– d-sh–w- c:\documents and settings\Default User.WINDOWS\IETldCache
2009-06-12 04:19 . 2009-06-12 04:19 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-12 03:48 . 2009-06-12 03:48 ——– d—–w- c:\program files\SystemRequirementsLab
2009-06-10 07:34 . 2009-06-10 07:34 ——– d—–w- c:\program files\iPod
2009-06-10 07:34 . 2009-06-10 07:34 ——– d—–w- c:\program files\iTunes
2009-06-10 07:32 . 2009-06-10 07:33 ——– d—–w- c:\program files\QuickTime
2009-06-10 07:28 . 2009-06-10 07:28 75048 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-28 14:09 . 2009-05-28 14:09 ——– d—–w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Google
2009-05-22 03:12 . 2009-05-22 03:13 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\vlc
2009-05-22 03:10 . 2009-05-22 03:10 ——– d—–w- c:\program files\VideoLAN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 06:07 . 2006-07-29 00:00 ——– d—–w- c:\program files\SpeedFan
2009-06-16 03:24 . 2006-07-31 19:19 ——– d—–w- c:\program files\City of Heroes
2009-06-15 09:32 . 2009-01-20 18:34 ——– d—–w- c:\program files\Glycerine
2009-06-15 07:03 . 2006-08-15 01:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-06-15 06:47 . 2006-07-31 18:56 ——– d—–w- c:\program files\City Game Tracker
2009-06-15 02:17 . 2009-03-15 09:51 ——– d—–w- c:\program files\NOS
2009-06-15 02:17 . 2009-03-15 09:51 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2009-06-15 02:05 . 2007-02-23 04:57 ——– d—–w- c:\program files\Google
2009-06-15 01:59 . 2006-07-28 18:13 ——– d—–w- c:\program files\Logitech
2009-06-15 01:44 . 2009-04-23 02:06 ——– d—–w- c:\program files\Fstcv101
2009-06-15 01:39 . 2008-01-06 03:46 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Yahoo!
2009-06-15 01:39 . 2008-01-06 03:45 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2009-06-15 01:38 . 2009-04-22 03:19 ——– d—–w- c:\program files\Poker Pages Odds Calculator
2009-06-15 01:37 . 2006-08-11 20:29 ——– d—–w- c:\program files\Java
2009-06-15 01:30 . 2008-03-08 05:56 ——– d—–w- c:\program files\Real
2009-06-15 01:28 . 2008-03-08 05:56 ——– d—–w- c:\program files\Common Files\Real
2009-06-15 01:28 . 2008-01-02 23:44 ——– d—–w- c:\program files\Poker Tracker V2
2009-06-12 03:52 . 2008-02-09 19:31 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-12 03:52 . 2009-01-12 20:58 ——– d—–w- c:\program files\AGEIA Technologies
2009-06-10 07:34 . 2008-05-07 01:31 ——– d—–w- c:\program files\Common Files\Apple
2009-05-21 18:33 . 2008-12-06 21:11 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 19:52 . 2007-04-17 23:07 ——– d–h–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Move Networks
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-05-01 07:31 . 2009-05-01 07:31 1657376 —-a-w- c:\windows\system32\nwiz.exe
2009-05-01 07:31 . 2009-05-01 07:31 449056 —-a-w- c:\windows\system32\nvappbar.exe
2009-05-01 07:31 . 2009-05-01 07:31 436768 —-a-w- c:\windows\system32\keystone.exe
2009-05-01 07:31 . 2009-05-01 07:31 466944 —-a-w- c:\windows\system32\nvshell.dll
2009-05-01 07:31 . 2009-05-01 07:31 1724416 —-a-w- c:\windows\system32\nvwdmcpl.dll
2009-05-01 07:31 . 2009-05-01 07:31 1507328 —-a-w- c:\windows\system32\nview.dll
2009-05-01 07:31 . 2009-05-01 07:31 1101824 —-a-w- c:\windows\system32\nvwimg.dll
2009-05-01 05:02 . 2009-05-01 05:02 663552 —-a-w- c:\windows\system32\nvcuvid.dll
2009-05-01 05:02 . 2009-05-01 05:02 1579630 —-a-w- c:\windows\system32\nvdata.bin
2009-05-01 05:02 . 2009-05-01 05:02 1314816 —-a-w- c:\windows\system32\nvcuvenc.dll
2009-05-01 05:02 . 2008-12-26 08:08 9994240 —-a-w- c:\windows\system32\nvoglnt.dll
2009-05-01 05:02 . 2008-12-26 08:08 806912 —-a-w- c:\windows\system32\nvapi.dll
2009-05-01 05:02 . 2008-12-26 08:08 1720320 —-a-w- c:\windows\system32\nvcuda.dll
2009-05-01 05:02 . 2008-12-26 08:08 143360 —-a-w- c:\windows\system32\nvcodins.dll
2009-05-01 05:02 . 2008-12-26 08:08 143360 —-a-w- c:\windows\system32\nvcod.dll
2009-05-01 05:02 . 2006-07-31 18:17 457248 —-a-w- c:\windows\system32\nvudisp.exe
2009-05-01 05:02 . 2006-06-02 00:22 8055584 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-05-01 05:02 . 2006-06-02 00:22 5896320 —-a-w- c:\windows\system32\nv4_disp.dll
2009-04-27 07:42 . 2006-07-31 18:17 457248 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-04-27 06:40 . 2009-04-27 06:40 ——– d—–w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
2009-04-27 06:40 . 2009-04-27 06:40 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-04-27 06:39 . 2009-04-27 06:40 38208 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-04-03 19:39 . 2009-04-03 19:39 70936 —-a-w- c:\windows\system32\PhysXLoader.dll
2009-04-01 18:33 . 2009-04-01 18:33 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-23 13:29 . 2009-03-23 13:29 152576 —-a-w- c:\documents and settings\MISSY's GAMER.SHERRI-78C7B973\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 23:32 . 2008-01-29 19:01 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-03-08 10:39 . 2008-03-08 10:39 774144 —-a-w- c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-16_02.52.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-16 18:28 . 2009-06-16 18:28 16384 c:\windows\Temp\Perflib_Perfdata_65c.dat
+ 2009-06-16 18:28 . 2009-06-16 18:28 16384 c:\windows\Temp\Perflib_Perfdata_5b0.dat
+ 2009-06-16 18:23 . 2009-06-16 18:23 389120 c:\windows\system32\CF8982.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"eFax 4.3"="c:\program files\eFax Messenger 4.3\J2GDllCmd.exe" [2007-03-06 116224]
"UMonit"="c:\windows\system32\UMonit.exe" [2006-11-16 200704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-06-01 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-06-01 18944]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-05-01 1657376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 7:59 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 7:59 AM 20560]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [9/2/2006 2:06 PM 3712]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [7/31/2006 8:52 PM 70016]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [1/12/2009 4:45 PM 79360]
S3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [1/4/2008 4:38 PM 12672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vuiovf REG_MULTI_SZ vuiovf

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2007-09-16 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2100 series272A572217594EBCF1CEE215E352B92AD073FDE4181011518.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-10 00:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ieSpell; Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling; - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: Send to &Bluetooth; Device… - c:\program files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 11:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(844)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\nvappfilter.dll

- - - - - - - > 'explorer.exe'(3376)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\CF8982.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IOGEAR\Bluetooth Software\bin\btwdins.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\LxrSII1s.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\program files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
c:\windows\system32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-16 11:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-16 18:31
ComboFix2.txt 2009-06-16 02:55

Pre-Run: 284,592,803,840 bytes free
Post-Run: 284,589,719,552 bytes free

Current=6 Default=6 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
242 — E O F — 2009-03-18 08:33
Nice ;) I will remove my tools now - if you could monitor for 24 hours and let me know how it is running

Now the best part of the day —– Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..Run OTS and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 14.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


SPRING CLEAN

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

THEN

Download and run Auslogics Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update


To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:
Hi Essexboy,
I'm doing the cleanup, and trying to update Java. I can't seem to find the link which provides jre-6u13-windows-i586-p.exe.

Which link is correct?
Thanks!
Aaargh I am a numpty it is update 14 now (must change my canned )

Java SE Runtime Environment (JRE)
JRE 6 Update 14
This release is Windows 7 support-ready and includes support for Internet Explorer 8, Windows Server 2008 SP2, and Windows Vista SP2. New features include the G1 garbage collector, plus performance and security enhancements. Learn more

This is the one on the page in my link
Thanks again, Essexboy! I am done with everything put forth, and everything is running super! I really appreciate your time and patient help. Wonderful! -Bliss
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI