This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help! Got the system is infected with spyware desktop&#

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I NEED HELP!!! I'm running Windows XP SP 2 and I got the message that lots of people are getting. I got a green background with the warning message, and it seems like "Windows Internet security or whatever has attached to my taskbar and I can't access task manager!! HELP ME PLEASE!!! I'm running malwarebytes and AVG as we speak.
HELP PLEASE!!! I'm getting very nervous about this and i've been getting numerous pop-ups on my taskbar asking if I want to do certain things, which I have rejected all of them.
Hi,


Open a run box (windows key + R) > copy/paste the following command into the run box > OK

reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t Reg_dword /d 0 /f

This should enable your Task Manager.

Re-run this command as often as you need to if the malware disables it again.

This should enable your task manager for you:

Next go into task manger and end process on any of the following processes if you find them:

smss32.exe
winlogon32.exe
winupdate86.exe
msa.exe
a.exe
b.exe
c.exe
notepad.exe
41.exe
logon.exe
critical_warning.html
lsm32.sys
opeia.exe
IS2010.exe
xxxsysguard.exe


then run the following:

Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy the text inside of the code box, Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Now paste the copied text into the open notepad, press CTRL+V (or right click and choose 'paste')

Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\windows\\system32\\userinit.exe,"
"Shell"="explorer.exe"

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You should now see a file on your desktop that looks like this:

[external image: Posted Image]

Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.

Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.


NEXT


Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I did what the other topic said to do and I was able to remove nearly everything with Malwarebytes, and I restarted my computer and now everything is back to normal. However, smss32.exe is still running on my task manager and I cannot end this process. Seems like my computer is running a bit slower since I restarted it and also, something is weird with my desktop because all of the icon's names are highlighted in blue (the icons itself aren't highlighted) so I was wondering if there is a fix to that. Seems like 99% of the spyware is gone though, but my computer isn't fully back to normal yet. I don't want to try a system restore cause I fear that that will bring everything back. Also, when I restarted, I clicked on my name at start up and it gave me a weird error after the desktop came up saying something how logon.exe doesn't work or something like that. EDIT: I take that back, I don't have smss32.exe running (smss.exe itself is running though) but is there a way to check to see if it's still on my computer?
Well this is great, I downloaded the two files, but I also downloaded the windows update files before that, and also an AVG update while I was running gmer and it caused my computer to freeze. Even worse, I tried restarting and now I keep getting the BSOD (I've had this type of BSOD before where it would flash for a second and go into a constant loop) so now I'm using the recover repair for it as we speak. *sighs* Today has really sucked.
this infection is known to infect the legitimate userinit - hence the regfix I gave you in my prior instructions

however, you have continued to try and fix this issue on your own, downloading programs that I did not suggest you do.

I can try and help you with this, but you must do exactly as I say.

first of all - lets try Last Know Good Configuration.

As your computer boots up > tap F8 repeatedly until an option menu appears

arrow up to last know good configuration

If that is successful let me know…


If it is not successful

then follow the following instructions:


You will need access to another PC capable of burning CD's


We will need to make a BOOT CD

Print these instruction out so that you know what you are doing.

Two programs to download

First

Please downloadISOBurner and save it to your desktop. This program will allow you to burn OTLPE.ISO to make a bootable CD. 
  •  
  • Double click the ISOBurner set up icon to install the program, from there on in it is fairly automatic.
  • There are Instructions for the iso burner here if you need them.

Second

  • Download OTLPE.iso save it to your desktop. Now burn OTLPE.iso to a CD using ISO Burner. {NOTE: This file is 292Mb in size so it may take some time to download.)
  • When downloaded double click OTLPE.iso > this will then open ISOBurner to burn the file to CD

  • Reboot the infected system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • you will find an icon on the desktop called OTLPE > Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to SafeList
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the C:\OTL.txt file in your reply.
Actually I've already done the repair install since it's the same type of BSOD that I have had before where I did a repair install of XP and it worked fine. Seems like everything is working again, though once everything officially loads properly then I'll run those programs you told me to run without running anything else. Is that what you think I should do?
If you are doing a repair install, then you should be OK, but run the DDS and GMER programs and I can check and make sure nothing survived
I've tried to run DDS but it really slows down the computer to the point that everything is insanely slow. Am I supposed to just double click it and let it run?
Yes,

A black box should pop up with some dialogue on it.

If it wont run, try this program:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Ok that is running right now. I'm guessing after it's finished I should still run GMER?

The only thing about GMER is that it still slowed down my computer severely when I tried to run it before, but the OTI program is running smoothly now so should I try to run GMER again after OTI is finished?

Edit: OTI is finished. Here's the extras.txt log:

OTL Extras logfile created on: 1/16/2010 10:05:28 PM - Run 1
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Mike\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 7.75 Gb Free Space | 10.40% Space Free | Partition Type: NTFS
Drive D: | 596.02 Gb Total Space | 211.74 Gb Free Space | 35.53% Space Free | Partition Type: FAT32
Drive E: | 465.76 Gb Total Space | 175.96 Gb Free Space | 37.78% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIKE-A25D958F62
Current User Name: Mike
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"9322:TCP" = 9322:TCP:*:Enabled:EKDiscovery

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Pinnacle\MediaCenter\PMC.exe" = C:\Program Files\Pinnacle\MediaCenter\PMC.exe:LocalSubNet:Enabled:Pmc.exe – ( )
"C:\Program Files\Pinnacle\MediaCenter\PSST.exe" = C:\Program Files\Pinnacle\MediaCenter\PSST.exe:LocalSubNet:Enabled:PSST.exe – (Pinnacle Systems)
"C:\Program Files\Pinnacle\MediaCenter\PMSInstallInit.exe" = C:\Program Files\Pinnacle\MediaCenter\PMSInstallInit.exe:LocalSubNet:Enabled:PMSInstallInit.exe – ( )
"C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe" = C:\Program Files\Pinnacle\Shared Files\Programs\MediaManager\PMSManager.exe:LocalSubNet:Enabled:PMSManager.exe – (Pinnacle Systems)
"C:\Program Files\BitLord\BitLord.exe" = C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord – (www.BitLord.com)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule – (http://www.verycd.com)
"C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSInstallInit.exe" = C:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSInstallInit.exe:LocalSubNet:Enabled:PMSInstallInit.exe – ( )
"C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe" = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe:*:Enabled:CLI Application (Command Line Interface) – (ATI Technologies Inc.)
"C:\Program Files\Steam\steamapps\coolforever\half-life\hl.exe" = C:\Program Files\Steam\steamapps\coolforever\half-life\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Incredible Technologies\Golden Tee Golf\gtgolf.exe" = C:\Program Files\Incredible Technologies\Golden Tee Golf\gtgolf.exe:*:Enabled:gtgolf – (Incredible Technologies, Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager – (Pinnacle Systems, Inc.)
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio – (Pinnacle Systems)
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile – ( )
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi – (Pinnacle Systems, Inc.)
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\KeyHoleTV\KeyHoleTV.exe" = C:\Program Files\KeyHoleTV\KeyHoleTV.exe:*:Enabled:KeyHole TV Main Application – (OISEYER Inc.)
"C:\Program Files\TVAnts\Tvants.exe" = C:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts – (Zhejiang University)
"C:\Program Files\Winamp Remote\bin\Orb.exe" = C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb – (Orb Networks, Inc.)
"C:\Program Files\Winamp Remote\bin\OrbTray.exe" = C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray – (Orb Networks)
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe" = C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client – (Orb Networks)
"C:\Program Files\Steam\steamapps\coolforever\day of defeat\hl.exe" = C:\Program Files\Steam\steamapps\coolforever\day of defeat\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\StepMania CVS\Program\StepMania.exe" = C:\Program Files\StepMania CVS\Program\StepMania.exe:*:Enabled:StepMania – (http://www.stepmania.com)
"C:\Program Files\PFPortChecker\PFPortChecker.exe" = C:\Program Files\PFPortChecker\PFPortChecker.exe:*:Enabled:PFPortchecker by portforward.com helps check if your ports are properly forwarded. – (portforward.com)
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"C:\Program Files\Steam\steamapps\coolforever\team fortress 2\hl2.exe" = C:\Program Files\Steam\steamapps\coolforever\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Steam\steamapps\coolforever\counter-strike\hl.exe" = C:\Program Files\Steam\steamapps\coolforever\counter-strike\hl.exe:*:Enabled:Half-Life Launcher – (Valve)
"C:\Program Files\FileZilla FTP Client\filezilla.exe" = C:\Program Files\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla – (FileZilla Project)
"C:\Program Files\Steam\steam.exe" = C:\Program Files\Steam\steam.exe:*:Enabled:Steam – (Valve Corporation)
"C:\Program Files\Steam\steamapps\coolforever\synergy\hl2.exe" = C:\Program Files\Steam\steamapps\coolforever\synergy\hl2.exe:*:Enabled:hl2 – ()
"C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe" = C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe:*:Enabled:Kodak Printer Network Setup Utility – (Eastman Kodak Company)
"C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" = C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe:*:Enabled:Kodak AiO Home Center – (Eastman Kodak Company)
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe" = C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe:LocalSubNet:Disabled:PMCService – (Pinnacle Systems)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{048DB60B-5AD7-40D3-ACDA-6E8B233829FA}" = Logitech Harmony Remote Software 7
"{074AED0D-DD1C-432A-B38D-F8733604033F}" = aioscnnr
"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{2C0CD17D-0B06-4700-83FA-7344B868B0A2}" = Opera 9.63
"{2D6ED011-055B-4041-B198-BB903827EBFB}" = Safari
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{460CE8B9-6EC2-458A-90D4-691631ECE9D9}" = Pinnacle MediaServer
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{5546F2F4-236B-4E96-8D5C-7447BBC3C0B0}" = PS TO PC CONVERTER
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{59B73DDC-593A-4D02-B9CA-1D8C9F912324}" = aioprnt
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{612B9183-67A9-4B44-9877-2F059E35B86A}" = Broadcom 440x 10/100 Integrated Controller
"{6350DFD0-01B0-11DE-87AF-0800200C9A66}" = Livestation
"{66ED8E01-C915-41F5-B33E-C5C31F27B885}" = USB Network Driver
"{66F49D6A-E999-4DB0-ADB6-EE546806E340}" = Antares Auto-Tune Evo VST
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{95CC887F-91B2-45E9-AE29-0D51995192CB}" = USB Game Controller
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A02ED372-22FA-448B-AB6A-1B0FC23B7D08}" = ATI Catalyst Control Center
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A77F3C2D-50CC-4A29-A1FB-1E018BE4DCA2}" = DiscAPI (Studio 10)
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B96D2269-568B-4CBF-9332-12FAE8B158F7}" = Medieval CUE Splitter
"{BC2FE771-EDBE-3087-A676-2B6C45A2BF7E}" = Google Gears
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C26D7EF1-A5AD-4B46-9F49-535E9255A669}" = BlackBerry Desktop Software 4.7
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CA567AD5-33A4-403D-86D1-EE2D38251951}_is1" = VDownloader 1.0
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D87E2087-5EED-42A7-8B73-487714556C8D}" = BlackBerry v4.2.2 for the 8320 Series Wireless Handheld
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (PINNACLESYS)
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK All-in-One Printer Software
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EEECE229-49F6-4851-A73A-99B058221F8C}" = RAPID
"{EF6C4600-306D-4F6A-A119-C2A877D25B4A}" = iTunes
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F38ADCA4-AF7C-4C73-9021-6F1EA15D15EA}" = Pinnacle MediaCenter
"{F6B2ED65-7378-4065-802D-F2E5689F3A4E}" = Photo Viewer
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD025150-EEA0-4CAC-BED1-B9837783FCC8}" = ActivePerl 5.10.0 Build 1005
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"AC Tool" = AC Tool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Port Scanner v1.3" = Advanced Port Scanner v1.3
"Afraid of Monsters: Director's Cut" = Afraid of Monsters: Director's Cut v1.0
"AI RoboForm" = AI RoboForm (All Users)
"All ATI Software" = ATI - Software Uninstall Utility
"AMX Mod X Installer" = AMX Mod X Installer 1.8.1
"Antares Autotune VST RTAS TDM_is1" = Antares Autotune VST RTAS TDM v5.08
"AOL Instant Messenger" = AOL Instant Messenger
"ASIO4ALL" = ASIO4ALL
"ATI Display Driver" = ATI Display Driver
"Audacity_is1" = Audacity 1.2.6
"AVG8Uninstall" = AVG Free 8.5
"AviSynth" = AviSynth 2.5
"BitLord" = BitLord 1.1
"BlackBerry_{C26D7EF1-A5AD-4B46-9F49-535E9255A669}" = BlackBerry Desktop Software 4.7
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"Collab" = Collab
"CopyTrans Suite" = CopyTrans Suite Remove Only
"DancingGorilla_is1" = DancingGorilla 1.2/1.06
"DVD Decrypter" = DVD Decrypter (Remove Only)
"eMule VeryCD " = eMule VeryCD
"eMule VeryCD°æ" = eMule VeryCD°æ
"FileZilla Client" = FileZilla Client [removed]
"FL Studio 8" = FL Studio 8
"GCFScape_is1" = GCFScape 1.3.1
"HLSW_is1" = HLSW v1.3.1
"IL Download Manager" = IL Download Manager
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InterActual Player" = InterActual Player
"KeyHoleTV" = KeyHoleTV
"LastFM_is1" = Last.fm 1.5.4.24567
"LimeWire" = LimeWire PRO 4.17.0
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Monkey's Audio_is1" = Monkey's Audio
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"MP3 WAV WMA Converter" = MP3 WAV WMA Converter
"Notepad++" = Notepad++
"OpenAL" = OpenAL
"Orb" = Winamp Remote
"PFPortChecker" = PFPortChecker 1.0.28
"PoiZone" = PoiZone
"PolderbitSRecorder" = PolderbitS Sound Recorder and Editor
"PS3 Video 9" = PS3 Video 9 4.08
"RealPlayer 6.0" = RealPlayer
"Sandboxie" = Sandboxie 3.38
"Steam App 10" = Counter-Strike
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 5" = Dedicated Server
"Steam App 70" = Half-Life
"StepMania" = StepMania (remove only)
"StepMania CVS" = StepMania CVS (remove only)
"SuiteII3.7" = SuiteII
"SUPER ©" = SUPER © Version 2009.bld.35 (Jan 5, 2009)
"SvenCoop" = Sven Co-op 4.0B
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Toxic Biohazard" = Toxic Biohazard
"TVAnts 1.0" = TVAnts 1.0
"Veetle TV" = Veetle TV 0.9.15
"ViewpointMediaPlayer" = Viewpoint Media Player
"Virtual Astronomy Laboratory" = Virtual Astronomy Laboratory
"VLC media player" = VLC media player 1.0.3
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"winscp3_is1" = WinSCP 4.2.4 beta
"YouTube Downloader App" = YouTube Downloader App 1.03

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/12/2010 3:59:54 AM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application cldl.exe, version 1.0.48.3, faulting module unknown,
version 0.0.0.0, fault address 0x3e2c443a.

Error - 1/12/2010 4:24:16 AM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application cldl.exe, version 1.0.48.3, faulting module unknown,
version 0.0.0.0, fault address 0x3e2e6bb6.

Error - 1/12/2010 2:33:24 PM | Computer Name = MIKE-A25D958F62 | Source = WindowsLiveMessenger | ID = 15728647
Description =

Error - 1/12/2010 2:33:25 PM | Computer Name = MIKE-A25D958F62 | Source = WindowsLiveMessenger | ID = 15728647
Description =

Error - 1/14/2010 2:10:35 PM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application cldl.exe, version 1.0.48.3, faulting module unknown,
version 0.0.0.0, fault address 0x636f2c6d.

Error - 1/14/2010 7:11:48 PM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application cldl.exe, version 1.0.48.3, faulting module unknown,
version 0.0.0.0, fault address 0x3e2c443a.

Error - 1/14/2010 7:12:22 PM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application cldl.exe, version 1.0.48.3, faulting module unknown,
version 0.0.0.0, fault address 0x3e2e6bb6.

Error - 1/16/2010 7:57:35 PM | Computer Name = MIKE-A25D958F62 | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.41.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 1/16/2010 10:32:22 PM | Computer Name = MIKE-A25D958F62 | Source = Windows Live Messenger | ID = 1000
Description =

Error - 1/16/2010 10:34:32 PM | Computer Name = MIKE-A25D958F62 | Source = Application Error | ID = 1000
Description = Faulting application firefox.exe, version 1.9.1.3642, faulting module
msvcr80.dll, version 8.0.50727.3053, fault address 0x0004f029.

[ System Events ]
Error - 1/15/2010 2:59:57 PM | Computer Name = MIKE-A25D958F62 | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.

Error - 1/16/2010 8:26:47 PM | Computer Name = MIKE-A25D958F62 | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 1/16/2010 8:26:47 PM | Computer Name = MIKE-A25D958F62 | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 1/16/2010 8:28:04 PM | Computer Name = MIKE-A25D958F62 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pinnacle Systems Media
Service service to connect.

Error - 1/16/2010 8:28:04 PM | Computer Name = MIKE-A25D958F62 | Source = Service Control Manager | ID = 7000
Description = The Pinnacle Systems Media Service service failed to start due to
the following error: %%1053

Error - 1/16/2010 9:49:39 PM | Computer Name = MIKE-A25D958F62 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/16/2010 9:49:39 PM | Computer Name = MIKE-A25D958F62 | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service SENS with arguments
"" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}

Error - 1/16/2010 10:24:39 PM | Computer Name = MIKE-A25D958F62 | Source = Setup | ID = 60055
Description = Windows Setup encountered non-fatal errors during installation. Please
check the setuperr.log found in your Windows directory for more informatio

Error - 1/16/2010 10:48:24 PM | Computer Name = MIKE-A25D958F62 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Pinnacle Systems Media
Service service to connect.

Error - 1/16/2010 10:48:24 PM | Computer Name = MIKE-A25D958F62 | Source = Service Control Manager | ID = 7000
Description = The Pinnacle Systems Media Service service failed to start due to
the following error: %%1053


< End of report >



















Now here is the OTL.txt log:

OTL logfile created on: 1/16/2010 10:05:28 PM - Run 1
OTL by OldTimer - Version 3.1.25.2 Folder = C:\Documents and Settings\Mike\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 7.75 Gb Free Space | 10.40% Space Free | Partition Type: NTFS
Drive D: | 596.02 Gb Total Space | 211.74 Gb Free Space | 35.53% Space Free | Partition Type: FAT32
Drive E: | 465.76 Gb Total Space | 175.96 Gb Free Space | 37.78% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MIKE-A25D958F62
Current User Name: Mike
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mike\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\PolderbitS\Recorder\Driver\PBDriverMonitor_uk.exe (PolderbitS Software)
PRC - C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (tzuk)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (Microsoft Corporation)
PRC - C:\Program Files\Kodak\AiO\Center\KodakSvc.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe (Eastman Kodak Company)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
PRC - C:\WINDOWS\system32\WLTRYSVC.EXE ()
PRC - C:\WINDOWS\system32\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Program Files\AIM\aim.exe (America Online, Inc.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Mike\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Real\RealPlayer\rpchromebrowserrecordhelper.dll ()
MOD - C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll (Logitech Inc.)
MOD - C:\WINDOWS\system32\MSVCR71.DLL (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (ACDaemon) – File not found
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (tzuk)
SRV - (gupdate1c98743b396f746) Google Update Service (gupdate1c98743b396f746) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (MSSQL$PINNACLESYS) – C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (KodakSvc) – C:\Program Files\Kodak\AiO\center\KodakSvc.exe (Eastman Kodak Company)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Kodak AiO Network Discovery Service) – C:\Program Files\Kodak\AiO\Center\EKDiscovery.exe (Eastman Kodak Company)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (wltrysvc) – C:\WINDOWS\System32\WLTRYSVC.EXE ()
SRV - (Ati HotKey Poller) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (PinnacleSys.MediaServer) – c:\Program Files\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe (Pinnacle Systems)
SRV - (SQLAgent$PINNACLESYS) – C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 22 2F EB 3C 3D 87 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "swagbucks.com"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.97
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.6
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.32.0
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090123.1
FF - prefs.js..extensions.enabledItems: [removed]:3.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:10.1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/26 12:41:12 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2009/02/18 00:49:09 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/04/02 21:04:48 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/11/03 19:44:02 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/01/06 20:03:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/14 01:27:06 | 00,000,000 | —D | M]

[2009/02/03 22:45:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Extensions
[2010/01/15 17:56:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions
[2010/01/01 14:26:52 | 00,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/08/05 22:42:10 | 00,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2009/03/06 17:03:37 | 00,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}(2)
[2009/08/20 22:48:35 | 00,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/07/14 22:40:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\[removed]
[2009/02/05 21:27:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\[removed]
[2009/11/22 21:00:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\[removed]
[2009/03/19 23:57:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\[removed]
[2009/07/14 22:40:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\extensions\[removed]
[2010/01/16 17:40:08 | 00,001,183 | —- | M] () – C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\ldrityj8.default\searchplugins\swagbuckscom.xml
[2010/01/15 15:30:00 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 07:00:00 | 00,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [Conime] C:\WINDOWS\system32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE File not found
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE File not found
O4 - HKLM..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\\PSDrvCheck.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PolderbitS Audio Driver Monitor.lnk = C:\Program Files\PolderbitS\Recorder\Driver\PBDriverMonitor_uk.exe (PolderbitS Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {038E2507-7A48-41E2-94AD-7F23D199AF4E} http://www.worldwinner.com/games/v54/zengems/zengems.cab (ZenGems Control)
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://www.worldwinner.com/games/v47/share…GamesLoader.cab (FunGamesLoader Object)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control)
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} http://www.worldwinner.com/games/v50/pool/pool.cab (Pool Control)
O16 - DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} http://www.worldwinner.com/games/v45/moneylist/moneylist.cab (MoneyList Control)
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} http://www.worldwinner.com/games/v51/bejeweled/bejeweled.cab (Bejeweled Control)
O16 - DPF: {64CD313F-F079-4D93-959F-4D28B5519449} http://www.worldwinner.com/games/v50/jeopardy/jeopardy.cab (Jeopardy Control)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} http://www.worldwinner.com/games/v57/wof/wof.cab (WoF Control)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} http://www.worldwinner.com/games/v47/famil…/familyfeud.cab (FamilyFeud Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} http://www.worldwinner.com/games/v44/golfsol/golfsol.cab (GolfSol Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Desktop Background.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/22 18:15:17 | 00,000,095 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/04/01 13:53:24 | 00,000,071 | -H– | M] () - D:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2008/08/14 14:28:04 | 00,000,000 | —D | M] - D:\AUTORUN – [ FAT32 ]
O32 - AutoRun File - [2007/05/10 07:48:26 | 00,000,032 | —- | M] () - E:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{1723136c-ba06-11de-b42f-0019b965807f}\Shell\AutoRun\command - "" = I:\MI.exe – File not found
O33 - MountPoints2\{17231372-ba06-11de-b42f-0019b965807f}\Shell - "" = AutoRun
O33 - MountPoints2\{17231372-ba06-11de-b42f-0019b965807f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{17231372-ba06-11de-b42f-0019b965807f}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O33 - MountPoints2\{17231811-ba06-11de-b42f-0019b965807f}\Shell\AutoRun\command - "" = .\Encryption Tool\MaxtorEncryption.exe
O33 - MountPoints2\{afb5c852-f2f9-11dd-b78a-0019b965807f}\Shell - "" = AutoRun
O33 - MountPoints2\{afb5c852-f2f9-11dd-b78a-0019b965807f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{afb5c852-f2f9-11dd-b78a-0019b965807f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe – File not found
O33 - MountPoints2\{c796748a-12a4-11de-b40e-0019b965807f}\Shell - "" = AutoRun
O33 - MountPoints2\{c796748a-12a4-11de-b40e-0019b965807f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c796748a-12a4-11de-b40e-0019b965807f}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{f9011403-d9e3-11de-b436-0019b965807f}\Shell\AutoRun\command - "" = G:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2010/01/16 15:18:46 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55172488459452416)

========== Files/Folders - Created Within 14 Days ==========

[2010/01/16 21:58:39 | 00,547,328 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mike\Desktop\OTL.exe
[2010/01/16 21:26:14 | 00,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2010/01/16 21:22:16 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia330.dll
[2010/01/16 21:22:16 | 00,079,872 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rwia001.dll
[2010/01/16 21:22:16 | 00,026,624 | —- | C] (Ricoh Co., Ltd.) – C:\WINDOWS\System32\dllcache\rw330ext.dll
[2010/01/16 21:21:10 | 00,057,856 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esuimgd.dll
[2010/01/16 21:21:10 | 00,045,056 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esunid.dll
[2010/01/16 21:21:10 | 00,031,744 | —- | C] (SEIKO EPSON CORP.) – C:\WINDOWS\System32\dllcache\esucmd.dll
[2010/01/16 21:20:54 | 00,054,528 | —- | C] (Philips Semiconductors GmbH) – C:\WINDOWS\System32\dllcache\cap7146.sys
[2010/01/16 21:20:02 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/01/16 19:55:52 | 00,000,000 | —D | C] – C:\Documents and Settings\Mike\Application Data\AVG8
[2010/01/04 13:22:21 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2009/11/22 11:48:34 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/11/22 11:48:34 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/05/09 15:20:01 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Eastman Kodak Company
[2009/04/10 12:46:01 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/02/11 00:50:03 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/02/10 01:12:09 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/02/07 13:46:48 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/02/05 15:38:27 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[3 C:\Documents and Settings\Mike\My Documents\*.tmp files -> C:\Documents and Settings\Mike\My Documents\*.tmp -> ]
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/01/16 21:58:40 | 00,547,328 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mike\Desktop\OTL.exe
[2010/01/16 21:46:44 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/01/16 21:46:30 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/16 21:46:10 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/16 21:30:39 | 00,459,522 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/01/16 21:30:39 | 00,079,078 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/01/16 21:30:36 | 00,548,144 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/01/16 21:30:31 | 00,000,974 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1454471165-725345543-1004UA.job
[2010/01/16 21:29:26 | 00,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2010/01/16 21:29:24 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/01/16 21:29:24 | 00,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/01/16 21:29:13 | 00,004,161 | —- | M] () – C:\WINDOWS\ODBCINST.INI
[2010/01/16 21:26:03 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/01/16 21:24:39 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/01/16 20:48:48 | 00,000,488 | RH– | M] () – C:\WINDOWS\System32\WindowsLogon.manifest
[2010/01/16 20:48:48 | 00,000,488 | RH– | M] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\WindowsShell.Manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\System32\nwc.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | M] () – C:\WINDOWS\System32\cdplayer.exe.manifest
[2010/01/16 20:48:25 | 00,000,548 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/16 20:47:47 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/01/16 20:45:05 | 00,000,211 | -HS- | M] () – C:\boot.ini
[2010/01/16 20:30:48 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/16 19:57:10 | 00,502,366 | —- | M] () – C:\WINDOWS\setupapi.old
[2010/01/16 19:57:10 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/01/16 19:56:53 | 00,091,136 | —- | M] () – C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/16 19:56:52 | 11,796,480 | —- | M] () – C:\Documents and Settings\Mike\ntuser.dat
[2010/01/16 19:35:01 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/01/16 19:24:59 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Mike\ntuser.ini
[2010/01/16 19:03:53 | 00,203,264 | —- | M] () – C:\WINDOWS\System32\6334.exe
[2010/01/16 18:43:40 | 00,203,264 | —- | M] () – C:\WINDOWS\System32\18467.exe
[2010/01/16 18:14:48 | 06,291,456 | -H– | M] () – C:\Documents and Settings\Mike\Local Settings\Application Data\IconCache.db
[2010/01/16 18:12:59 | 00,000,756 | —- | M] () – C:\Documents and Settings\Mike\Desktop\Internet Security 2010.lnk
[2010/01/16 18:02:51 | 00,000,001 | —- | M] () – C:\s
[2010/01/16 09:21:32 | 47,897,727 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/16 09:21:32 | 00,140,770 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/16 01:50:00 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/01/15 17:23:15 | 00,023,552 | —- | M] () – C:\Documents and Settings\Mike\My Documents\paper records.xls
[2010/01/15 14:30:00 | 00,000,922 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1454471165-725345543-1004Core.job
[2010/01/15 00:39:31 | 00,000,349 | —- | M] () – C:\Documents and Settings\All Users\Documents\PCLECHAL.INI
[2010/01/14 01:15:07 | 00,000,008 | —- | M] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2010/01/12 21:58:20 | 00,001,208 | —- | M] () – C:\WINDOWS\VFO.INI
[2010/01/07 16:07:14 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/01/07 16:07:04 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/01/02 23:50:08 | 00,049,152 | —- | M] ( ) – C:\Documents and Settings\Mike\CompiledAdapter
[2010/01/02 23:43:37 | 00,274,968 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/01/02 22:47:28 | 21,453,86496 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[3 C:\Documents and Settings\Mike\My Documents\*.tmp files -> C:\Documents and Settings\Mike\My Documents\*.tmp -> ]
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/16 21:21:32 | 00,059,392 | —- | C] () – C:\WINDOWS\System32\dllcache\imscinst.exe
[2010/01/16 21:21:13 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\dllcache\fpencode.dll
[2010/01/16 21:20:56 | 00,173,568 | —- | C] () – C:\WINDOWS\System32\dllcache\chtskf.dll
[2010/01/16 21:20:53 | 00,066,594 | —- | C] () – C:\WINDOWS\System32\dllcache\c_858.nls
[2010/01/16 21:20:53 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_870.nls
[2010/01/16 21:20:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_21025.nls
[2010/01/16 21:20:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20924.nls
[2010/01/16 21:20:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20880.nls
[2010/01/16 21:20:52 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20871.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20838.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20833.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20424.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20423.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20420.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20297.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20285.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20284.nls
[2010/01/16 21:20:51 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20280.nls
[2010/01/16 21:20:50 | 00,187,938 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20005.nls
[2010/01/16 21:20:50 | 00,180,258 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20004.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20278.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20277.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20273.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20269.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20108.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20107.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20106.nls
[2010/01/16 21:20:50 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20105.nls
[2010/01/16 21:20:49 | 00,186,402 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20001.nls
[2010/01/16 21:20:49 | 00,185,378 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20003.nls
[2010/01/16 21:20:49 | 00,173,602 | —- | C] () – C:\WINDOWS\System32\dllcache\c_20002.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1149.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1148.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1147.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1146.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1145.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1144.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1143.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1142.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1141.nls
[2010/01/16 21:20:48 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1140.nls
[2010/01/16 21:20:47 | 00,066,082 | —- | C] () – C:\WINDOWS\System32\dllcache\c_1047.nls
[2010/01/16 20:48:48 | 00,000,488 | RH– | C] () – C:\WINDOWS\System32\logonui.exe.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | C] () – C:\WINDOWS\System32\wuaucpl.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | C] () – C:\WINDOWS\WindowsShell.Manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | C] () – C:\WINDOWS\System32\sapi.cpl.manifest
[2010/01/16 20:48:41 | 00,000,749 | RH– | C] () – C:\WINDOWS\System32\ncpa.cpl.manifest
[2010/01/16 20:30:25 | 00,168,806 | —- | C] () – C:\WINDOWS\System32\dllcache\startoc.cat
[2010/01/16 20:30:25 | 00,024,209 | —- | C] () – C:\WINDOWS\System32\dllcache\msn7.cat
[2010/01/16 20:30:25 | 00,011,651 | —- | C] () – C:\WINDOWS\System32\dllcache\msn9.cat
[2010/01/16 20:30:25 | 00,007,710 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2010/01/16 20:30:25 | 00,007,245 | —- | C] () – C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2010/01/16 20:30:24 | 01,042,903 | —- | C] () – C:\WINDOWS\System32\dllcache\SP2.CAT
[2010/01/16 20:30:24 | 00,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2010/01/16 20:30:24 | 00,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2010/01/16 20:30:24 | 00,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2010/01/16 20:30:24 | 00,031,281 | —- | C] () – C:\WINDOWS\System32\dllcache\FP4.CAT
[2010/01/16 20:30:24 | 00,013,753 | —- | C] () – C:\WINDOWS\System32\dllcache\IMS.CAT
[2010/01/16 20:30:24 | 00,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2010/01/16 20:30:24 | 00,009,581 | —- | C] () – C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2010/01/16 20:30:24 | 00,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2010/01/16 20:30:23 | 02,012,670 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5.CAT
[2010/01/16 20:30:23 | 00,382,952 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2010/01/16 19:03:51 | 00,203,264 | —- | C] () – C:\WINDOWS\System32\6334.exe
[2010/01/16 18:43:38 | 00,203,264 | —- | C] () – C:\WINDOWS\System32\18467.exe
[2010/01/16 18:11:53 | 00,000,756 | —- | C] () – C:\Documents and Settings\Mike\Desktop\Internet Security 2010.lnk
[2010/01/16 18:02:51 | 00,000,001 | —- | C] () – C:\s
[2010/01/14 01:15:07 | 00,000,008 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sysReserve.ini
[2009/12/14 22:40:44 | 00,000,600 | —- | C] () – C:\Documents and Settings\Mike\Application Data\winscp.rnd
[2009/12/14 22:15:39 | 00,000,600 | —- | C] () – C:\Documents and Settings\Mike\Local Settings\Application Data\PUTTY.RND
[2009/11/04 00:11:47 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/09/17 11:27:02 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2009/08/20 15:17:05 | 00,001,562 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2009/07/14 00:21:50 | 00,177,664 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/06/23 23:54:58 | 00,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/05/21 23:25:55 | 00,000,024 | —- | C] () – C:\WINDOWS\System32\sysmwwod.dll
[2009/05/09 15:18:36 | 00,012,800 | —- | C] () – C:\WINDOWS\System32\EKDeviceServices.dll
[2009/05/09 15:05:22 | 00,174,516 | —- | C] () – C:\Documents and Settings\Mike\Local Settings\Application Data\installer.log
[2009/04/03 00:57:23 | 00,012,208 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/03/22 18:19:23 | 00,194,248 | —- | C] () – C:\WINDOWS\System32\LTRFD13n.DLL
[2009/03/22 18:15:17 | 00,001,208 | —- | C] () – C:\WINDOWS\VFO.INI
[2009/02/08 21:43:08 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/02/08 19:39:42 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2009/02/07 13:42:36 | 00,000,127 | —- | C] () – C:\Documents and Settings\Mike\Local Settings\Application Data\fusioncache.dat
[2009/02/07 13:42:34 | 00,196,096 | —- | C] () – C:\WINDOWS\System32\macd32.dll
[2009/02/07 13:42:34 | 00,138,752 | —- | C] () – C:\WINDOWS\System32\mase32.dll
[2009/02/07 13:42:34 | 00,136,192 | —- | C] () – C:\WINDOWS\System32\mamc32.dll
[2009/02/07 13:42:34 | 00,057,856 | —- | C] () – C:\WINDOWS\System32\masd32.dll
[2009/02/07 13:42:34 | 00,027,648 | —- | C] () – C:\WINDOWS\System32\ma32.dll
[2009/02/07 13:42:00 | 00,166,912 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2009/02/04 22:33:26 | 00,066,482 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/02/03 22:40:54 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2009/02/03 22:40:52 | 00,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2009/02/03 21:38:29 | 00,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2009/02/03 21:19:48 | 00,091,136 | —- | C] () – C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2005/08/09 17:13:31 | 00,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/08/09 17:13:31 | 00,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2005/08/09 17:12:28 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/29 13:38:24 | 03,375,104 | —- | C] () – C:\WINDOWS\System32\qt-mt331.dll
[2004/08/04 07:00:00 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\ieencode.dll
[2004/08/04 07:00:00 | 00,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys

========== LOP Check ==========

[2009/05/09 15:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Eastman Kodak Company
[2009/03/02 00:28:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FunGames
[2009/10/19 13:19:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\kds_kodak
[2009/02/04 00:32:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Last.fm
[2009/12/26 15:57:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/03/30 21:42:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OrbNetworks
[2009/05/22 21:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
[2009/03/22 18:29:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/03/22 18:29:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2009/08/21 23:10:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/03/22 18:17:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2009/02/03 23:29:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/07/26 13:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WindSolutions
[2009/02/03 23:29:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Aim
[2009/05/20 11:16:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Antares
[2009/07/26 14:05:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\CopyTrans
[2010/01/03 23:52:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\FileZilla
[2009/06/18 19:29:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\HLSW
[2009/02/04 22:33:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Leadertech
[2010/01/04 21:46:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\LimeWire
[2009/03/29 18:07:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Livestation
[2009/09/23 00:30:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Mchid
[2009/12/26 15:57:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\NCH Swift Sound
[2009/06/18 19:18:39 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Notepad++
[2009/09/08 21:53:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\OpenCandy
[2009/02/10 14:32:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Opera
[2009/05/22 21:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\PACE Anti-Piracy
[2009/09/08 22:01:26 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Red Kawa
[2009/03/01 11:42:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Research In Motion
[2009/10/19 13:18:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Temp
[2009/02/28 19:17:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\Viewpoint
[2009/07/26 13:19:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Mike\Application Data\WindSolutions
[2010/01/16 01:50:00 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/06/16 20:14:35 | 00,274,944 | —- | M] () – C:\Curl.exe
[2009/07/12 19:37:39 | 00,187,489 | —- | M] () – C:\VenomEnergy.exe


< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\agp440.sys
[2004/08/04 07:00:00 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 18,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\atapi.sys
[2004/08/04 07:00:00 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
[2009/05/24 12:21:06 | 00,028,797 | R— | M] () MD5=B892CA7A130D249704E61391C4948073 – C:\Perl\lib\auto\Win32\EventLog\EventLog.dll

< MD5 for: IASTOR.SYS >
[2005/04/25 10:28:14 | 00,871,040 | —- | M] (Intel Corporation) MD5=D593517879E65167DF35F6015814AC59 – C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\sp2qfe\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2005/05/17 17:45:08 | 00,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys
[2005/05/17 17:45:08 | 00,092,800 | —- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F – C:\WINDOWS\system32\drivers\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/04 07:00:00 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

========== Alternate Data Streams ==========

@Alternate Data Stream - 1283 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:qZdoo9C3pT8hH7VM4zizrAPdq
@Alternate Data Stream - 1233 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:wd3ugtyxtbF7PEuwJPwxrxaa6w
< End of report >
Again I tried to run GMER and once again my computer pretty much froze up on me X_X. Seems like when I open the program, I can't get into task manager after that and then everything just pretty much stops working. I had to reset again now. I don't want to run that program anymore. EDIT: I tried it again and it seems to be scanning now, I'll update with the results after.
X_X I got a blue screen of death while it was scanning. luckily nothing serious happened and I restarted. But I need to run a different program now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI