This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] New system infected, need help

98 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just bought this computer 2 weeks ago, I'm sure that something has infected it because many things including e-mail no onger run correctly, Here is a hijack this log to help determine what is wrong.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:42:56 AM, on 5/15/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files (x86)\Tall Emu\Online Armor\oaui.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\Windows\System32\oem\SetEvent.exe
C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe
C:\Program Files (x86)\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Bryan\PSI\psi.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…28v1j5w45j1t539
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…28v1j5w45j1t539
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…28v1j5w45j1t539
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [OpenDNS Updater] "C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DriverMax] "C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe" -agent
O4 - HKCU\..\Run: [DriverMax_RESTART] "C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe" -RESTART
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_93C8148BBB233F43.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://oas.support.microsoft.com/ActiveX/MSDcode.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.com.s…ri_4.1.71.0.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{473F86ED-FB55-42E5-8A1F-9FC700C929D6}: NameServer = 208.67.222.222,208.67.220.220
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Encrypting File System (EFS) (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files (x86)\Tall Emu\Online Armor\OAcat.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files (x86)\Tall Emu\Online Armor\oasrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 12870 bytes
If it's only two weeks old - any chance of returning it? It may be a lemon.

why do you suspect an infection - have you been downloading dodgy files/programs?

Have you considered a restore - being that it's only two weeks old, you can't have that much data loaded that it would be a huge inconvenience to start again?

http://www.sevenforums.com/tutorials/668-s…ry-options.html


(there are no obvious signs of malware in the log, but we would need to do a much more in depth analysis to try and figure out what was wrong)
I have caught a couple of virus' with Malwarebytes and deleted them. Unfortunately I can't locate the log files to show you. But now all the scans I run come up clean. Except that I get kicked off the internet for no reason about 3-4 times a day. I have Online Armor windows7 64 bit beta version running and it just doesn't act like it did when I had my xp/32 system. For one I can't get my hosts file to work, I've tried to reset it and then add the mv file to update and although it shows the file in the correct path the hosts system isn't blocking anything and in my Online Armor folder it doesn't appear as it did under the old XP 32 system. Something is definately off but since I'm testing the OA beta and also just learning the 64bit operating system and Windows 7 is also brand new I can't seem to narrow things down to find out where the errors are occurring or why. I know this sounds rather mixed up but I'm not a computer savvy person. I do know how to use several resources though. One big mistake I made when I brought the computer home and set it up was that I didn't know I was supposed to create the recovery disks immediately upon getting up and running. I didn't do it until after I had made a few changes to the appearance and I think added in my hotmail account and a couple of other minor things. All told I was only on the computer about a half hour before I realized I should make the back up disks. I hope that they will work if I ever really need them, do you think because I didn't make them asap that they might not function correctly? I've also made a back up with Paragon back up program but that was done a couple of days later. I worry about trying any of them out because my wife and son would kill me if I messed this up. What i'm going to try is to isolate each program as much as possible to see if I can locate why I'm having these glitches. I looked into the beta forum of OA and didn't find any others having the same symptoms I'm having but there are a few problems with software not running correctly. I will keep you informed of anything I find. I'm so tempted to just try and reset everything with the recover disks I made except that I don't know if they will work OK because I didn't make them right away. That of course is my last recourse. Hopefully you will have some advice or know how I should proceed. Thanks much for the help.
Hi,


I'm not certain about the way the backup disks were created whether they will work correctly or not, I will have to ask the techs about that,


You might want to try a system restore to a point before you started experiencing these issues.


http://www.sevenforums.com/tutorials/700-system-restore.html

If that doesn't work, then run the following scan and we'll have a look at what could be causing some of the issues.

Please do the following:

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi Catbyte, I did everything instructed but in the middle of the scan an error message came . Cannot create the language script. So it never finished. Is there anything I should do? I remember that there was a problem with vbs scripts last week, this is hte first time that it has shown again.
Hello Catbyte, I've located the Mbam logs that showed what infectionswere detected by it.I will post both here in a moment. As for system restore i've done it but the furthest I can go back is just a couple of days and that didn't fix anything. i'm now concerned about why the OTL scan could not complete because of a langauge script problem. Here are the 2 logs: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4084 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 5/10/2010 8:25:01 AM mbam-log-2010-05-10 (08-25-01).txt Scan type: Quick scan Objects scanned: 18812 Time elapsed: 6 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Daniel.Family\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5QTF2ONR\setup_lib_srl[1].exe (Spyware.Zbot) -> Quarantined and deleted successfully. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4097 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 5/13/2010 12:51:21 PM mbam-log-2010-05-13 (12-51-21).txt Scan type: Quick scan Objects scanned: 148109 Time elapsed: 3 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Users\Daniel.Family\AppData\Roaming\My Security Engine (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. Files Infected: C:\Users\Daniel.Family\Documents\downloads\Flash.HD.v12.exe (Trojan.Fraudpack) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\AppData\Roaming\My Security Engine\Instructions.ini (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\AppData\Roaming\My Security Engine\winupdate.exe (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\Desktop\My Security Engine.lnk (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\My Security Engine.lnk (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\AppData\Roaming\Microsoft\Windows\Start Menu\My Security Engine.lnk (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. C:\Users\Daniel.Family\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Security Engine.lnk (Rogue.MySecurityEngine) -> Quarantined and deleted successfully. I'm afraid of trying to restore from the 3 disks I created when I bought the computer because I didn't make them right away and I do have the one image backup made under paragon Backup and recovery program. i'm just gun shy about doing something that may not be reversible.
Hi

You may want to contact the computer manufacturer and ask them to send you a set of recovery disks.

they will usually do it for a nominal fee.


Please run this following program, delete the copy of OTL from your desktop, then download a fresh copy of OTL and try it again.

Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean
I ran the TFC program and it went as it should, after the reboot I downloaded OTL again and did as previously instructed unfortunatley it still stopped and brought up this error message: Script file for specified langauge could not be created. At this point i don't know what to do, I'm not even sure if any of the problems are still here and I hate just waiting to see if anything comes up but I guess theres nothing else to be done. If you have any suggestions please let me know what they are, otherwise I know how busy you volunteers are and there have got to be many others who need the help right now. If anthing happens i'll repost and ask for help again. I want to thank you again for your help.
what language is your OS?

Try this program:


Download OTSto your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Check the box that says 64 bit
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Under custom scans copy and paste the following:
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.
Wow Cat don't you ever sleep? lol.

I did as you asked and here is the log you wanted, I see that the restore point could not be created due to an error. When you asked me about using system restore one of the problems was that I only had 2 days worth of settings to restore to. Even though I had 10x the amount of space compared to my old system.

By the way I use English in all my functions. I'm hoping that you can deduce what the problems are that this computer is having and why. Please let me know what you need next. I hope that all the log fits in here.

OTS logfile created on: 5/20/2010 1:14:51 AM - Run 1
OTS by OldTimer - Version 3.1.31.0	 Folder = C:\Users\Bryan\Desktop
64bit- Home Premium Edition  (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 70.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 684.87 Gb Total Space | 607.75 Gb Free Space | 88.74% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
 
Computer Name: FAMILY
Current User Name: Bryan
Logged in as Administrator.
 
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
 
[Processes - Safe List]
setevent.exe -> C:\Windows\SysWow64\oem\SetEvent.exe -> File not found
ots.exe -> C:\Users\Bryan\Desktop\OTS.exe -> [2010/05/20 01:11:05 | 000,640,000 | —- | M] (OldTimer Tools)
oaui.exe -> C:\Program Files (x86)\Tall Emu\Online Armor\oaui.exe -> [2010/05/08 07:54:50 | 006,785,808 | —- | M] (Tall Emu)
avgate.exe -> C:\Program Files (x86)\Tall Emu\Online Armor\a2\avgate.exe -> [2010/04/20 04:27:48 | 002,823,672 | —- | M] (Tall Emu)
oahlp.exe -> C:\Program Files (x86)\Tall Emu\Online Armor\oahlp.exe -> [2010/04/20 04:27:46 | 003,075,576 | —- | M] (Tall Emu)
oasrv.exe -> C:\Program Files (x86)\Tall Emu\Online Armor\oasrv.exe -> [2010/04/20 04:27:44 | 003,506,680 | —- | M] (Tall Emu)
oacat.exe -> C:\Program Files (x86)\Tall Emu\Online Armor\oacat.exe -> [2010/04/20 04:27:44 | 001,284,600 | —- | M] (Tall Emu)
msnmsgr.exe -> C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe -> [2010/04/16 22:12:38 | 003,872,080 | —- | M] (Microsoft Corporation)
devices.exe -> C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe -> [2010/03/01 14:00:34 | 009,216,928 | —- | M] (Innovative Solutions)
opendnsupdater.exe -> C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe -> [2009/11/16 12:58:38 | 000,839,168 | —- | M] ()
googletoolbarnotifier.exe -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> [2009/10/27 23:10:50 | 000,039,408 | —- | M] (Google Inc.)
mwldaemon.exe -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe -> [2009/09/10 06:42:30 | 000,349,480 | —- | M] (Egis Technology Inc.)
greghsrw.exe -> C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -> [2009/08/28 02:38:58 | 001,150,496 | —- | M] (Acer Incorporated)
psi.exe -> C:\Users\Bryan\PSI\psi.exe -> [2009/08/21 01:15:32 | 000,900,816 | —- | M] (Secunia)
ischedulesvc.exe -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -> [2009/08/12 15:04:44 | 000,062,208 | —- | M] (NewTech Infosystems, Inc.)
backupmanagertray.exe -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe -> [2009/08/12 14:58:28 | 000,261,888 | —- | M] (NewTech Infosystems, Inc.)
egisupdate.exe -> C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe -> [2009/08/03 22:09:34 | 000,199,464 | —- | M] (Egis Technology Inc.)
updaterservice.exe -> C:\Program Files\Acer\Acer Updater\UpdaterService.exe -> [2009/07/03 18:47:12 | 000,240,160 | —- | M] (Acer)
seaport.exe -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation)
 
[Modules - Safe List]
ots.exe -> C:\Users\Bryan\Desktop\OTS.exe -> [2010/05/20 01:11:05 | 000,640,000 | —- | M] (OldTimer Tools)
comdlg32.dll -> C:\Windows\SysWOW64\comdlg32.dll -> [2009/07/13 18:15:07 | 000,486,912 | —- | M] (Microsoft Corporation)
msscript.ocx -> C:\Windows\SysWOW64\msscript.ocx -> [2009/07/13 18:14:10 | 000,095,232 | —- | M] (Microsoft Corporation)
comctl32.dll -> C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll -> [2009/07/13 18:03:50 | 001,680,896 | —- | M] (Microsoft Corporation)
 
[Win32 Services - Safe List]
64bit-(WatAdminSvc)  [Unknown | Stopped] -> C:\Windows\SysNative\Wat\WatAdminSvc.exe -> [2010/05/03 00:56:51 | 001,255,736 | —- | M] (Microsoft Corporation)
64bit-(MsMpSvc)  [Auto | Running] -> c:\Program Files\Microsoft Security Essentials\MsMpEng.exe -> [2009/12/09 20:30:34 | 000,017,416 | —- | M] (Microsoft Corporation)
64bit-(WwanSvc)  [On_Demand | Stopped] -> C:\Windows\SysNative\wwansvc.dll -> [2009/07/13 18:41:59 | 000,229,888 | —- | M] (Microsoft Corporation)
64bit-(WbioSrvc)  [On_Demand | Stopped] -> C:\Windows\SysNative\wbiosrvc.dll -> [2009/07/13 18:41:56 | 000,202,240 | —- | M] (Microsoft Corporation)
64bit-(Power)  [Auto | Running] -> C:\Windows\SysNative\umpo.dll -> [2009/07/13 18:41:56 | 000,163,840 | —- | M] (Microsoft Corporation)
64bit-(Themes)  [Auto | Running] -> C:\Windows\SysNative\themeservice.dll -> [2009/07/13 18:41:55 | 000,044,544 | —- | M] (Microsoft Corporation)
64bit-(sppuinotify)  [On_Demand | Stopped] -> C:\Windows\SysNative\sppuinotify.dll -> [2009/07/13 18:41:54 | 000,065,536 | —- | M] (Microsoft Corporation)
64bit-(SensrSvc)  [On_Demand | Stopped] -> C:\Windows\SysNative\sensrsvc.dll -> [2009/07/13 18:41:54 | 000,029,184 | —- | M] (Microsoft Corporation)
64bit-(PNRPsvc)  [On_Demand | Running] -> C:\Windows\SysNative\pnrpsvc.dll -> [2009/07/13 18:41:53 | 000,327,168 | —- | M] (Microsoft Corporation)
64bit-(p2pimsvc)  [On_Demand | Running] -> C:\Windows\SysNative\pnrpsvc.dll -> [2009/07/13 18:41:53 | 000,327,168 | —- | M] (Microsoft Corporation)
64bit-(HomeGroupProvider)  [On_Demand | Running] -> C:\Windows\SysNative\provsvc.dll -> [2009/07/13 18:41:53 | 000,187,904 | —- | M] (Microsoft Corporation)
64bit-(RpcEptMapper)  [Unknown | Running] -> C:\Windows\SysNative\RpcEpMap.dll -> [2009/07/13 18:41:53 | 000,067,072 | —- | M] (Microsoft Corporation)
64bit-(PNRPAutoReg)  [On_Demand | Stopped] -> C:\Windows\SysNative\pnrpauto.dll -> [2009/07/13 18:41:53 | 000,025,088 | —- | M] (Microsoft Corporation)
64bit-(WinDefend)  [On_Demand | Stopped] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation)
64bit-(HomeGroupListener)  [On_Demand | Running] -> C:\Windows\SysNative\ListSvc.dll -> [2009/07/13 18:41:18 | 000,231,936 | —- | M] (Microsoft Corporation)
64bit-(FontCache)  [On_Demand | Stopped] -> C:\Windows\SysNative\FntCache.dll -> [2009/07/13 18:40:54 | 001,127,936 | —- | M] (Microsoft Corporation)
64bit-(Dhcp)  [Auto | Running] -> C:\Windows\SysNative\dhcpcore.dll -> [2009/07/13 18:40:28 | 000,314,368 | —- | M] (Microsoft Corporation)
64bit-(defragsvc)  [On_Demand | Stopped] -> C:\Windows\SysNative\defragsvc.dll -> [2009/07/13 18:40:28 | 000,291,328 | —- | M] (Microsoft Corporation)
64bit-(bthserv)  [Disabled | Stopped] -> C:\Windows\SysNative\bthserv.dll -> [2009/07/13 18:40:13 | 000,083,968 | —- | M] (Microsoft Corporation)
64bit-(BDESVC)  [Unknown | Stopped] -> C:\Windows\SysNative\bdesvc.dll -> [2009/07/13 18:40:10 | 000,100,864 | —- | M] (Microsoft Corporation)
64bit-(AxInstSV)  [On_Demand | Stopped] -> C:\Windows\SysNative\AxInstSv.dll -> [2009/07/13 18:40:05 | 000,114,688 | —- | M] (Microsoft Corporation)
64bit-(AppIDSvc)  [On_Demand | Stopped] -> C:\Windows\SysNative\appidsvc.dll -> [2009/07/13 18:40:01 | 000,032,256 | —- | M] (Microsoft Corporation)
64bit-(wbengine)  [On_Demand | Stopped] -> C:\Windows\SysNative\wbengine.exe -> [2009/07/13 18:39:51 | 001,503,744 | —- | M] (Microsoft Corporation)
64bit-(sppsvc)  [Auto | Stopped] -> C:\Windows\SysNative\sppsvc.exe -> [2009/07/13 18:39:28 | 003,524,608 | —- | M] (Microsoft Corporation)
64bit-(Fax)  [On_Demand | Stopped] -> C:\Windows\SysNative\FXSSVC.exe -> [2009/07/13 18:39:11 | 000,689,152 | —- | M] (Microsoft Corporation)
64bit-(Updater Service)  [Auto | Running] -> C:\Program Files\Acer\Acer Updater\UpdaterService.exe -> [2009/07/03 18:47:12 | 000,240,160 | —- | M] (Acer)
64bit-(ForceWare Intelligent Application Manager (IAM))  [Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -> [2009/04/19 08:34:48 | 000,625,184 | —- | M] ()
64bit-(nSvcIp)  [Auto | Running] -> C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -> [2009/04/19 08:34:48 | 000,207,904 | —- | M] ()
64bit-(wlidsvc)  [Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009/03/30 17:19:56 | 002,297,216 | —- | M] (Microsoft Corporation)
(PnkBstrA) PnkBstrA [On_Demand | Stopped] -> C:\Windows\SysWOW64\PnkBstrA.exe -> [2010/05/13 12:43:24 | 000,066,872 | —- | M] ()
(GoogleDesktopManager-110309-193829) Google Desktop Manager 5.9.911.3589 [On_Demand | Stopped] -> C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe -> [2010/05/03 22:27:12 | 000,030,192 | —- | M] (Google)
(fsssvc) Windows Live Family Safety Service [On_Demand | Stopped] -> C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe -> [2010/04/28 07:44:02 | 000,704,872 | —- | M] (Microsoft Corporation)
(SvcOnlineArmor) Online Armor [Auto | Running] -> C:\Program Files (x86)\Tall Emu\Online Armor\oasrv.exe -> [2010/04/20 04:27:44 | 003,506,680 | —- | M] (Tall Emu)
(OAcat) Online Armor Helper Service [Auto | Running] -> C:\Program Files (x86)\Tall Emu\Online Armor\OAcat.exe -> [2010/04/20 04:27:44 | 001,284,600 | —- | M] (Tall Emu)
(GameConsoleService) GameConsoleService [On_Demand | Stopped] -> C:\Program Files (x86)\Acer Games\Acer Game Console\GameConsoleService.exe -> [2010/04/16 16:09:06 | 000,246,520 | —- | M] (WildTangent, Inc.)
(Partner Service) Partner Service [On_Demand | Stopped] -> C:\ProgramData\Partner\Partner.exe -> [2009/10/27 23:10:54 | 000,332,272 | —- | M] (Google Inc.)
(MWLService) MyWinLocker Service [On_Demand | Stopped] -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe -> [2009/09/10 06:42:46 | 000,305,448 | —- | M] ()
(Greg_Service) GRegService [Auto | Running] -> C:\Program Files (x86)\Acer\Registration\GregHSRW.exe -> [2009/08/28 02:38:58 | 001,150,496 | —- | M] (Acer Incorporated)
(Nero BackItUp Scheduler 4.0) Nero BackItUp Scheduler 4.0 [Disabled | Stopped] -> C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -> [2009/08/25 10:38:06 | 000,935,208 | —- | M] (Nero AG)
(NTI IScheduleSvc) NTI IScheduleSvc [Auto | Running] -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe -> [2009/08/12 15:04:44 | 000,062,208 | —- | M] (NewTech Infosystems, Inc.)
(VSS) Volume Shadow Copy [On_Demand | Stopped] -> C:\Windows\Vss -> [2009/07/13 20:20:14 | 000,000,000 | —D | M]
(MSDTC) Distributed Transaction Coordinator [Unknown | Stopped] -> C:\Windows\SysWOW64\Msdtc -> [2009/07/13 20:20:14 | 000,000,000 | —D | M]
(HomeGroupProvider) HomeGroup Provider [On_Demand | Running] -> C:\Windows\SysWOW64\provsvc.dll -> [2009/07/13 18:16:12 | 000,165,376 | —- | M] (Microsoft Corporation)
(Dhcp) DHCP Client [Auto | Running] -> C:\Windows\SysWOW64\dhcpcore.dll -> [2009/07/13 18:15:11 | 000,253,440 | —- | M] (Microsoft Corporation)
(vds) Virtual Disk [On_Demand | Stopped] -> C:\Windows\SysWOW64\wbem\vds.mof -> [2009/07/13 13:30:11 | 000,061,056 | —- | M] ()
(clr_optimization_v2.0.50727_64) Microsoft .NET Framework NGEN v2.0.50727_X64 [On_Demand | Stopped] -> C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -> [2009/06/10 13:39:58 | 000,089,920 | —- | M] (Microsoft Corporation)
(SeaPort) SeaPort [Auto | Running] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/05/19 11:36:18 | 000,240,512 | —- | M] (Microsoft Corporation)
 
[Driver Services - Safe List]
64bit-(fssfltr) fssfltr [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\fssfltr.sys -> [2010/04/28 08:57:50 | 000,061,288 | —- | M] (Microsoft Corporation)
64bit-(OAnet) OnlineArmor Service [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\OAnet.sys -> [2010/04/20 04:13:20 | 000,046,456 | —- | M] (Tall Emu Pty Ltd)
64bit-(pwdrvio) pwdrvio [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\pwdrvio.sys -> [2010/04/09 13:17:04 | 000,019,936 | —- | M] ()
64bit-(pwdspio) pwdspio [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\pwdspio.sys -> [2010/04/09 13:16:58 | 000,013,280 | —- | M] ()
64bit-(hotcore3) hc3ServiceName [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\hotcore3.sys -> [2010/01/15 12:21:16 | 000,037,392 | —- | M] (Paragon Software Group)
64bit-(KSecPkg) KSecPkg [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\ksecpkg.sys -> [2009/12/11 03:29:27 | 000,153,160 | —- | M] (Microsoft Corporation)
64bit-(fvevol) Bitlocker Drive Encryption Filter Driver [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\fvevol.sys -> [2009/09/25 23:20:38 | 000,223,448 | —- | M] (Microsoft Corporation)
64bit-(amdsata) amdsata [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsata.sys -> [2009/07/13 18:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices)
64bit-(amdxata) amdxata [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\amdxata.sys -> [2009/07/13 18:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices)
64bit-(amdsbs) amdsbs [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\amdsbs.sys -> [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.)
64bit-(LSI_SAS2) LSI_SAS2 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\lsi_sas2.sys -> [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation)
64bit-(hwpolicy) Hardware Policy Driver [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\hwpolicy.sys -> [2009/07/13 18:48:04 | 000,014,416 | —- | M] (Microsoft Corporation)
64bit-(FsDepends) File System Dependency Minifilter [File_System | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\fsdepends.sys -> [2009/07/13 18:47:49 | 000,055,376 | —- | M] (Microsoft Corporation)
64bit-(HpSAMD) HpSAMD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HpSAMD.sys -> [2009/07/13 18:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company)
64bit-(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\wimmount.sys -> [2009/07/13 18:45:56 | 000,022,096 | —- | M] (Microsoft Corporation)
64bit-(vhdmp) vhdmp [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\vhdmp.sys -> [2009/07/13 18:45:55 | 000,217,680 | —- | M] (Microsoft Corporation)
64bit-(vdrvroot) Microsoft Virtual Drive Enumerator Driver [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\vdrvroot.sys -> [2009/07/13 18:45:55 | 000,036,432 | —- | M] (Microsoft Corporation)
64bit-(stexstor) stexstor [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\stexstor.sys -> [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology)
64bit-(rdyboost) ReadyBoost [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\rdyboost.sys -> [2009/07/13 18:45:46 | 000,214,096 | —- | M] (Microsoft Corporation)
64bit-(pcw) Performance Counters for Windows Driver [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\pcw.sys -> [2009/07/13 18:45:45 | 000,050,768 | —- | M] (Microsoft Corporation)
64bit-(CNG) CNG [Kernel | Boot | Running] -> C:\Windows\SysNative\drivers\cng.sys -> [2009/07/13 18:43:14 | 000,460,504 | —- | M] (Microsoft Corporation)
64bit-(rdpbus) Remote Desktop Device Redirector Bus Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\rdpbus.sys -> [2009/07/13 17:17:46 | 000,024,064 | —- | M] (Microsoft Corporation)
64bit-(RDPREFMP) Reflector Display Driver used to gain access to graphics data [Kernel | System | Running] -> C:\Windows\SysNative\drivers\RDPREFMP.sys -> [2009/07/13 17:16:35 | 000,008,192 | —- | M] (Microsoft Corporation)
64bit-(RasAgileVpn) WAN Miniport (IKEv2) [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\agilevpn.sys -> [2009/07/13 17:10:24 | 000,060,416 | —- | M] (Microsoft Corporation)
64bit-(WfpLwf) WFP Lightweight Filter [Kernel | System | Running] -> C:\Windows\SysNative\drivers\wfplwf.sys -> [2009/07/13 17:09:26 | 000,012,800 | —- | M] (Microsoft Corporation)
64bit-(NdisCap) NDIS Capture LightWeight Filter [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\ndiscap.sys -> [2009/07/13 17:08:13 | 000,035,328 | —- | M] (Microsoft Corporation)
64bit-(vwifibus) Virtual WiFi Bus Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\vwifibus.sys -> [2009/07/13 17:07:21 | 000,024,576 | —- | M] (Microsoft Corporation)
64bit-(1394ohci) 1394 OHCI Compliant Host Controller [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\1394ohci.sys -> [2009/07/13 17:07:13 | 000,227,840 | —- | M] (Microsoft Corporation)
64bit-(HdAudAddService) Microsoft 1.1 UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\HdAudio.sys -> [2009/07/13 17:07:00 | 000,350,208 | —- | M] (Microsoft Corporation)
64bit-(UmPass) Microsoft UMPass Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\umpass.sys -> [2009/07/13 17:06:52 | 000,009,728 | —- | M] (Microsoft Corporation)
64bit-(WinUsb) WinUsb [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\winusb.sys -> [2009/07/13 17:06:28 | 000,040,448 | —- | M] (Microsoft Corporation)
64bit-(mshidkmdf) Pass-through HID to KMDF Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\mshidkmdf.sys -> [2009/07/13 17:06:24 | 000,008,192 | —- | M] (Microsoft Corporation)
64bit-(WudfPf) User Mode Driver Frameworks Platform Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\WUDFPf.sys -> [2009/07/13 17:05:37 | 000,112,128 | —- | M] (Microsoft Corporation)
64bit-(MTConfig) Microsoft Input Configuration Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\MTConfig.sys -> [2009/07/13 17:02:08 | 000,015,360 | —- | M] (Microsoft Corporation)
64bit-(CompositeBus) Composite Bus Enumerator Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\CompositeBus.sys -> [2009/07/13 17:00:34 | 000,038,912 | —- | M] (Microsoft Corporation)
64bit-(Beep) Beep [Kernel | System | Running] -> C:\Windows\SysNative\drivers\beep.sys -> [2009/07/13 17:00:13 | 000,006,656 | —- | M] (Microsoft Corporation)
64bit-(AppID) AppID Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\appid.sys -> [2009/07/13 16:52:39 | 000,061,440 | —- | M] (Microsoft Corporation)
64bit-(scfilter) Smart card PnP Class Filter Driver [Kernel | Unknown | Stopped] -> C:\Windows\SysNative\drivers\scfilter.sys -> [2009/07/13 16:50:17 | 000,029,696 | —- | M] (Microsoft Corporation)
64bit-(discache) System Attribute Cache [Kernel | System | Running] -> C:\Windows\SysNative\drivers\discache.sys -> [2009/07/13 16:37:18 | 000,040,448 | —- | M] (Microsoft Corporation)
64bit-(HidBatt) HID UPS Battery Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\hidbatt.sys -> [2009/07/13 16:31:06 | 000,026,624 | —- | M] (Microsoft Corporation)
64bit-(CmBatt) Microsoft ACPI Control Method Battery Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\CmBatt.sys -> [2009/07/13 16:31:03 | 000,017,664 | —- | M] (Microsoft Corporation)
64bit-(AcpiPmi) ACPI Power Meter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\acpipmi.sys -> [2009/07/13 16:27:17 | 000,012,288 | —- | M] (Microsoft Corporation)
64bit-(AmdPPM) AMD Processor Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\amdppm.sys -> [2009/07/13 16:19:25 | 000,060,928 | —- | M] (Microsoft Corporation)
64bit-(NVHDA) Service for NVIDIA High Definition Audio Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\nvhda64v.sys -> [2009/06/26 00:55:10 | 000,083,488 | —- | M] (NVIDIA Corporation)
64bit-(PSI) PSI [File_System | On_Demand | Running] -> C:\Windows\SysNative\drivers\psi_mf.sys -> [2009/06/17 05:19:14 | 000,015,208 | —- | M] (Secunia)
64bit-(NVENETFD) NVIDIA nForce Networking Controller Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\nvm62x64.sys -> [2009/06/10 13:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation)
64bit-(ebdrv) Broadcom NetXtreme II 10 GigE VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\evbda.sys -> [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation)
64bit-(b06bdrv) Broadcom NetXtreme II VBD [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\bxvbda.sys -> [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation)
64bit-(b57nd60a) Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0 [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\b57nd60a.sys -> [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation)
64bit-(hcw85cir) Hauppauge Consumer Infrared Receiver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\drivers\hcw85cir.sys -> [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.)
64bit-(mwlPSDVDisk) mwlPSDVDisk [Kernel | System | Running] -> C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -> [2009/06/02 04:15:30 | 000,060,464 | —- | M] (Egis Technology Inc.)
64bit-(mwlPSDFilter) mwlPSDFilter [File_System | System | Running] -> C:\Windows\SysNative\drivers\mwlPSDFilter.sys -> [2009/06/02 04:15:30 | 000,022,576 | —- | M] (Egis Technology Inc.)
64bit-(mwlPSDNServ) mwlPSDNServ [Kernel | System | Running] -> C:\Windows\SysNative\drivers\mwlPSDNserv.sys -> [2009/06/02 04:15:30 | 000,020,016 | —- | M] (Egis Technology Inc.)
64bit-(NTIDrvr) NTIDrvr [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\NTIDrvr.sys -> [2009/05/05 16:46:08 | 000,018,432 | —- | M] (NewTech Infosystems, Inc.)
64bit-(UBHelper) UBHelper [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\UBHelper.sys -> [2009/05/05 16:46:08 | 000,016,896 | —- | M] (NewTech Infosystems Corporation)
64bit-(NVNET) NVIDIA nForce 10/100/1000 Mbps Ethernet  [Kernel | On_Demand | Running] -> C:\Windows\SysNative\drivers\nvmf6264.sys -> [2009/04/29 22:06:58 | 000,339,360 | —- | M] (NVIDIA Corporation)
(OADevice) OADriver [File_System | System | Running] -> C:\Windows\SysWOW64\drivers\OADriver.sys -> [2010/04/20 04:13:26 | 000,055,160 | —- | M] ()
(OAmon) OAmon [Kernel | System | Running] -> C:\Windows\SysWOW64\drivers\OAmon.sys -> [2010/04/20 04:13:24 | 000,038,776 | —- | M] (Tall Emu)
(WIMMount) WIMMount [File_System | On_Demand | Stopped] -> C:\Windows\SysWOW64\drivers\wimmount.sys -> [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation)
(WinUsb) WinUsb [Kernel | On_Demand | Stopped] -> C:\Windows\SysWOW64\winusb.dll -> [2009/07/13 18:16:19 | 000,016,896 | —- | M] (Microsoft Corporation)
(NetBIOS) NetBIOS Interface [File_System | System | Running] -> C:\Windows\SysWOW64\netbios.dll -> [2009/07/13 18:16:02 | 000,014,336 | —- | M] (Microsoft Corporation)
(mpsdrv) Windows Firewall Authorization Driver [Kernel | On_Demand | Running] -> C:\Windows\SysWOW64\wbem\mpsdrv.mof -> [2009/06/10 14:28:14 | 000,001,088 | —- | M] ()
(Tcpip) TCP/IP Protocol Driver [Kernel | System | Running] -> C:\Windows\SysWOW64\wbem\tcpip.mof -> [2009/06/10 14:15:18 | 000,003,066 | —- | M] ()
(mwlPSDVDisk) mwlPSDVDisk [Kernel | System | Running] -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\mwlPSDVdisk.sys -> [2009/06/02 04:15:30 | 000,060,464 | —- | M] (Egis Technology Inc.)
(mwlPSDFilter) mwlPSDFilter [File_System | System | Running] -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\mwlPSDFilter.sys -> [2009/06/02 04:15:30 | 000,022,576 | —- | M] (Egis Technology Inc.)
(mwlPSDNServ) mwlPSDNServ [Kernel | System | Running] -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\mwlPSDNServ.sys -> [2009/06/02 04:15:30 | 000,020,016 | —- | M] (Egis Technology Inc.)
 
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 -> 
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\Windows\SysWOW64\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: Main\\"Default_Page_URL" -> http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_x1301&r=17360510s707p0428v1j5w45j1t539 -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: Main\\"Start Page" -> http://google.com/ -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: Main\\"Start Page Redirect Cache" -> http://www.msn.com/ -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: Main\\"Start Page Redirect Cache AcceptLangs" -> en-us -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> 20 33 D2 BE EF F5 CA 01  [binary data] -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\: "ProxyEnable" -> 0 -> 
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions ->  -> 
< FireFox Extensions [User Folders] > -> 
< HOSTS File > ([2010/05/04 14:31:04 | 000,607,013 | —- | M] - 16089 lines) -> C:\Windows\SysNative\Drivers\etc\hosts -> 
First 25 entries…
Reset Hosts
127.0.0.1  localhost
127.0.0.1  fr.a2dfp.net
127.0.0.1  m.fr.a2dfp.net
127.0.0.1  ad.a8.net
127.0.0.1  asy.a8ww.net
127.0.0.1  adserver.abv.bg
127.0.0.1  adv.abv.bg
127.0.0.1  bimg.abv.bg
127.0.0.1  www2.a-counter.kiev.ua
127.0.0.1  track.acclaimnetwork.com
127.0.0.1  accuserveadsystem.com
127.0.0.1  www.accuserveadsystem.com
127.0.0.1  achmedia.com
127.0.0.1  aconti.net
127.0.0.1  secure.aconti.net
127.0.0.1  www.aconti.net #[Dialer.Aconti]
127.0.0.1  ads.active.com
127.0.0.1  am1.activemeter.com
127.0.0.1  www.activemeter.com #[Tracking.Cookie]
127.0.0.1  ads.activepower.net
127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
127.0.0.1  ad2games.com
127.0.0.1  cms.ad2click.nl
127.0.0.1  ads.ad2games.com
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} [HKLM] -> C:\Program Files\Windows Live\Family Safety\fssbho.dll [Windows Live Family Safety Browser Helper Class] -> [2010/04/28 08:57:50 | 000,132,456 | —- | M] (Microsoft Corporation)
{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} [HKLM] -> C:\ProgramData\Partner\Partner64.dll [Partner BHO Class] -> [2009/10/27 23:10:53 | 000,750,064 | —- | M] (Google Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live ID Sign-in Helper] -> [2009/03/30 17:23:30 | 000,531,840 | —- | M] (Microsoft Corporation)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar Helper] -> [2010/05/03 03:28:21 | 000,371,312 | —- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll [Google Toolbar Notifier BHO] -> [2010/05/03 03:28:05 | 000,319,984 | —- | M] (Google Inc.)
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} [HKLM] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [Search Helper] -> [2009/05/19 11:36:18 | 000,137,600 | —- | M] (Microsoft Corporation)
{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} [HKLM] -> C:\ProgramData\Partner\Partner.dll [Partner BHO Class] -> [2009/10/27 23:10:53 | 000,433,648 | —- | M] (Google Inc.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll [Windows Live ID Sign-in Helper] -> [2009/03/30 16:31:54 | 000,403,824 | —- | M] (Microsoft Corporation)
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar Helper] -> [2010/05/03 03:27:56 | 000,278,128 | —- | M] (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [Google Toolbar Notifier BHO] -> [2010/05/03 03:28:05 | 000,812,528 | —- | M] (Google Inc.)
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E} [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [Google Dictionary Compression sdch] -> File not found
{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [Windows Live Toolbar Helper] -> [2010/04/16 19:55:34 | 001,067,872 | —- | M] (Microsoft Corporation)
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2010/05/03 03:28:21 | 000,371,312 | —- | M] (Google Inc.)
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2010/04/16 19:55:34 | 001,067,872 | —- | M] (Microsoft Corporation)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010/05/03 03:27:56 | 000,278,128 | —- | M] (Google Inc.)
"Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll [&Windows Live Toolbar] -> [2010/04/16 19:55:34 | 001,067,872 | —- | M] (Microsoft Corporation)
64bit-WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [Google Toolbar] -> [2010/05/03 03:28:21 | 000,371,312 | —- | M] (Google Inc.)
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [Google Toolbar] -> [2010/05/03 03:27:56 | 000,278,128 | —- | M] (Google Inc.)
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"@OnlineArmor GUI" -> C:\Program Files (x86)\Tall Emu\Online Armor\oaui.exe ["C:\Program Files (x86)\Tall Emu\Online Armor\oaui.exe"] -> [2010/05/08 07:54:50 | 006,785,808 | —- | M] (Tall Emu)
"MSSE" -> c:\Program Files\Microsoft Security Essentials\msseces.exe ["c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey] -> [2010/02/21 05:08:48 | 001,446,496 | —- | M] (Microsoft Corporation)
"mwlDaemon" -> C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe] -> [2009/09/10 06:42:30 | 000,349,480 | —- | M] (Egis Technology Inc.)
"OOTag" -> C:\Windows\OOBEOffer\OOBEOffer\OOTag.exe [C:\windows\oobeoffer\oobeoffer\ootag.exe] -> [2009/09/27 20:33:24 | 000,023,072 | —- | M] (Microsoft)
"PLD_FrameworkRun" -> C:\Windows\SysNative\OEM\_NowIntoDT.vbs [c:\windows\system32\oem\_NowIntoDT.vbs] -> [2009/10/11 09:49:06 | 000,000,490 | —- | M] ()
"RtHDVCpl" -> C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s] -> [2010/04/06 17:59:40 | 010,144,288 | —- | M] (Realtek Semiconductor)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Acer Assist Launcher" -> C:\Program Files (x86)\Acer\Acer Assist\launcher.exe [C:\Program Files (x86)\Acer\Acer Assist\launcher.exe] -> [2007/11/19 15:17:40 | 001,261,568 | —- | M] ()
"BackupManagerTray" -> C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe ["C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k] -> [2009/08/12 14:58:28 | 000,261,888 | —- | M] (NewTech Infosystems, Inc.)
"EgisTecLiveUpdate" -> C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe ["C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"] -> [2009/08/03 22:09:34 | 000,199,464 | —- | M] (Egis Technology Inc.)
"Google Desktop Search" -> C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe ["C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup] -> [2010/05/03 22:27:12 | 000,030,192 | —- | M] (Google)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun] -> [2009/07/13 18:14:38 | 001,173,504 | —- | M] (Microsoft Corporation)
< RunOnce [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> 
"mctadmin" -> C:\Windows\SysWow64\mctadmin.exe [C:\Windows\System32\mctadmin.exe] -> File not found
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun] -> [2009/07/13 18:14:38 | 001,173,504 | —- | M] (Microsoft Corporation)
< RunOnce [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce -> 
"mctadmin" -> C:\Windows\SysWow64\mctadmin.exe [C:\Windows\System32\mctadmin.exe] -> File not found
< Run [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
"DriverMax" -> C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe ["C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe" -agent] -> [2010/03/01 14:00:34 | 009,216,928 | —- | M] (Innovative Solutions)
"DriverMax_RESTART" -> C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe ["C:\Program Files (x86)\Innovative Solutions\DriverMax\devices.exe" -RESTART] -> [2010/03/01 14:00:34 | 009,216,928 | —- | M] (Innovative Solutions)
"msnmsgr" -> C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe ["C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background] -> [2010/04/16 22:12:38 | 003,872,080 | —- | M] (Microsoft Corporation)
"OpenDNS Updater" -> C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ["C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart] -> [2009/11/16 12:58:38 | 000,839,168 | —- | M] ()
"swg" -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ["C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"] -> [2009/10/27 23:10:50 | 000,039,408 | —- | M] (Google Inc.)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" ->  [1] -> File not found
\\"NoActiveDesktopChanges" ->  [1] -> File not found
\\"EnableShellExecuteHooks" ->  [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"ConsentPromptBehaviorAdmin" ->  [0] -> File not found
\\"ConsentPromptBehaviorUser" ->  [3] -> File not found
\\"EnableLUA" ->  [0] -> File not found
\\"PromptOnSecureDesktop" ->  [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" ->  [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"LogonHoursAction" ->  [2] -> File not found
\\"DontDisplayLogonHoursWarnings" ->  [1] -> File not found
< 64bit-Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Google Sidewiki… -> C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_93C8148BBB233F43.dll [res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_93C8148BBB233F43.dll/cmsidewiki.html] -> [2010/05/03 03:27:56 | 001,694,320 | —- | M] (Google Inc.)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\Software\Microsoft\Internet Explorer\MenuExt\ -> 
Google Sidewiki… -> C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_93C8148BBB233F43.dll [res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_93C8148BBB233F43.dll/cmsidewiki.html] -> [2010/05/03 03:27:56 | 001,694,320 | —- | M] (Google Inc.)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [Button: Blog This] -> [2009/07/26 20:17:14 | 000,186,192 | —- | M] (Microsoft Corporation)
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600}:{5F7B1267-94A9-47F5-98DB-E99415F33AEC} [HKLM] -> C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll [Menu: &Blog This in Windows Live Writer] -> [2009/07/26 20:17:14 | 000,186,192 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2009/02/26 19:45:52 | 000,603,040 | —- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2009/02/26 19:45:52 | 000,603,040 | —- | M] (Microsoft Corporation)
{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF}:Exec [HKLM] -> C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe [Button: PokerStars] -> [2010/05/02 23:59:59 | 000,562,968 | —- | M] (PokerStars)
< 64bit-Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
localhost .[http] -> Local intranet -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\] > -> HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-3488347447-2488368954-518346416-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 1 range(s) found. -> 
GD [:Range = 127.0.0.1] -> http = Local intranet |  -> 
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{0742B9EF-8C83-41CA-BFBA-830A59E23533} [HKLM] -> https://oas.support.microsoft.com/ActiveX/MSDcode.cab [Microsoft Data Collection Control] -> 
{0E5F0222-96B9-11D3-8997-00104BD12D94} [HKLM] -> http://www.pcpitstop.com/betapit/PCPitStop.CAB [PCPitstop Utility] -> 
{140E4DF8-9E14-4A34-9577-C77561ED7883} [HKLM] -> http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab [SysInfo Class] -> 
{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} [HKLM] -> http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab [BDSCANONLINE Control] -> 
{7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [OnlineScanner Control] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab [Java Plug-in 1.6.0_20] -> 
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab [Java Plug-in 1.6.0_20] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab [Java Plug-in 1.6.0_20] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ -> 
DhcpNameServer -> [removed] [removed] -> 
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{473F86ED-FB55-42E5-8A1F-9FC700C929D6}\\DhcpNameServer -> [removed] [removed]   (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> 
{473F86ED-FB55-42E5-8A1F-9FC700C929D6}\\NameServer -> 208.67.222.222,208.67.220.220   (NVIDIA nForce 10/100/1000 Mbps Ethernet ) -> 
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> 
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> 
C:\PROGRA~2\Google\GOOGLE~3\GO36F4~1.DLL -> C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> [2010/05/03 22:27:17 | 000,123,392 | —- | M] (Google)
*MultiFile Done* -> -> 
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\explorer.exe -> [2009/10/30 23:34:59 | 002,870,272 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
64bit-*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet -> 
SystemPropertiesPerformance.exe -> C:\Windows\SysNative\SystemPropertiesPerformance.exe -> [2009/07/13 18:39:47 | 000,082,432 | —- | M] (Microsoft Corporation)
/pagefile ->  -> File not found
*MultiFile Done* -> -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> 
explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2009/10/30 22:45:39 | 002,614,272 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet -> 
SystemPropertiesPerformance.exe -> C:\Windows\SysWow64\SystemPropertiesPerformance.exe -> [2009/07/13 18:14:42 | 000,081,920 | —- | M] (Microsoft Corporation)
/pagefile ->  -> File not found
*MultiFile Done* -> -> 
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> 
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> 
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck] -> File not found
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
"{4F07DA45-8170-4859-9B5F-037EF2970034}" [HKLM] -> C:\Program Files (x86)\Tall Emu\Online Armor\oaevent.dll [OA Shell Helper] -> [2010/04/20 04:27:46 | 000,925,688 | —- | M] (Tall Emu)
< LSA Security Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
64bit-*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
pku2u -> C:\Windows\SysNative\pku2u.dll -> [2009/07/13 18:41:53 | 000,240,640 | —- | M] (Microsoft Corporation)
livessp -> C:\Windows\SysNative\livessp.dll -> [2009/03/30 17:19:58 | 000,243,072 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
*LSA Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
pku2u -> C:\Windows\SysWow64\pku2u.dll -> [2009/07/13 18:16:12 | 000,186,880 | —- | M] (Microsoft Corporation)
livessp -> C:\Windows\SysWow64\livessp.dll -> [2009/03/30 16:28:36 | 000,195,440 | —- | M] (Microsoft Corporation)
*MultiFile Done* -> -> 
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{065ABD98-F5B7-4A5E-9F32-C470E8CFE382} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system | 
{09C3AD09-2DE4-43FE-8960-6B5672570DFC} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{13661FAA-49B2-42E0-875A-599ED504E92F} -> lport=1900 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
{1A52733A-27F1-497E-8319-75C23620B1F6} -> lport=139 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system | 
{1F6D207D-AAC9-4F8F-B7CB-24712CE1AF9B} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{1FD35719-8649-4DD6-95AC-0B62A9D193AB} -> lport=5355 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28548 | app=%systemroot%\system32\svchost.exe | svc=dnscache | 
{531ED8DA-0EEC-426D-A57F-A60BEE904626} -> lport=1900 | protocol=17 | dir=in | action=allow | name=windows live messenger (ssdp-in) | app=svchost.exe | svc=ssdpsrv | 
{584774FE-733B-498A-B235-2CFA9EA05DFA} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{683C4E01-A4CC-41EC-9A81-2FF4A864D6EB} -> lport=138 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system | 
{6D0D193C-12FB-48C1-AF5F-FB53BC34500B} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave | 
{6EC57AFE-CAF4-461B-B793-DE2BE4D5934E} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system | 
{82314B2C-F18A-4E5E-838D-0381DFBC1A36} -> rport=1900 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv | 
{90F7B26B-35C5-4734-806D-62D2F1DA0CA0} -> rport=138 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system | 
{98318391-E3BE-4D8F-AA65-7A453BD3AD18} -> lport=2869 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system | 
{9A8D74D3-7169-43E0-A350-6EB48B66E505} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler | 
{BC629E68-C9CD-47D1-BAFE-BD8F83BBE697} -> lport=2869 | protocol=6 | dir=in | action=allow | name=windows live messenger (upnp-in) | app=system | 
{C058D27F-27BF-4BDB-B400-05627DE0B792} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss | 
{DDF5C05B-D1E0-4247-A25D-73B4661B82A2} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system | 
{DE6F0476-F00A-4AFE-9821-0C1504851E51} -> lport=137 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system | 
{E08385CC-CA86-4090-BB2E-486CC00A5E1F} -> rport=5355 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28550 | app=%systemroot%\system32\svchost.exe | svc=dnscache | 
{E1FDE63C-4A1F-4CBF-B104-63EC256602A1} -> rport=137 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system | 
{F5C7536A-A119-4B89-A912-D80700252437} -> rport=445 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system | 
{F80A712E-97E0-47DD-AE8D-D177F2ED184C} -> rport=139 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system | 
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules -> 
{027F670E-DA28-4121-8644-C5BF657B9744} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe | 
{068EC1BA-5E90-4CEF-96F7-DD0FDE893812} -> profile=public | protocol=17 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{0C114551-01ED-4C60-A695-1735D5AEF686} -> profile=private | protocol=17 | dir=in | action=allow | name=call of duty(r) 4 - modern warfare™ | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | 
{13B5C18E-46D6-4465-A5C6-CBD122BD9068} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe | 
{16B64EE6-7938-462E-940D-41A6339B55E6} -> dir=in | action=allow | name=windows live messenger | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
{1F6BB7AA-A4FF-4F07-AAF1-4144CC3AF382} -> profile=private | protocol=6 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe | 
{250FA4EE-2370-46AF-BB1C-EB2FFA5F6E0D} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{26D8E0C9-5B0A-4335-B5B9-79B6DEB80CF4} -> profile=private | protocol=17 | dir=in | action=allow | name=steam | app=c:\program files (x86)\steam\steam.exe | 
{2D76D381-BF79-4C06-8931-57204966F73E} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system | 
{31007B4D-5B6D-41DA-A744-041F0710615C} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{3F22A01A-0239-41B2-B4CD-154E99EBF045} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe | 
{3F847FBD-B9E6-48ED-A80B-6FADA8072270} -> dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
{4099F175-2B40-4EE1-85E2-9E5BCC740D8E} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe | 
{4E676CAA-E3F9-4A4B-BB8A-66DE14AEBD85} -> profile=private | protocol=17 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
{5715D280-6046-4F27-9B89-583D23F9E8B0} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost | 
{5862F66F-9D2A-4E83-BBF3-78DDB1C950F0} -> profile=private | protocol=6 | dir=in | action=allow | name=pnkbstrb | app=c:\windows\syswow64\pnkbstrb.exe | 
{5E6F8420-7457-4F95-936E-37DCF29C0701} -> profile=private | protocol=17 | dir=in | action=allow | name=pnkbstra | app=c:\windows\syswow64\pnkbstra.exe | 
{5FC80437-14B8-4AF2-8DD6-55D937C3767F} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{6C613935-5B49-4398-95CB-A46500153830} -> profile=private | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 | 
{6DE3D17B-179B-4ACC-8F52-147089FADB33} -> profile=private | protocol=6 | dir=in | action=allow | name=pnkbstra | app=c:\windows\syswow64\pnkbstra.exe | 
{76AA9813-0155-4CF3-BE93-C071C283CBC6} -> profile=private | protocol=6 | dir=in | action=allow | name=call of duty(r) 4 - modern warfare™ | app=c:\program files (x86)\activision\call of duty 4 - modern warfare\iw3mp.exe | 
{780095B7-9AA0-42F3-9762-77EF830EEC50} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{8DEB4056-33BE-4031-806D-662922D8732B} -> profile=private | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 | 
{92D6D63C-55CD-4940-B2B3-25CFA19EB05B} -> profile=private | protocol=6 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
{94BEE832-F459-4CEA-BF0E-98B1162925E7} -> profile=domain | protocol=6 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
{B8AF4B8A-1A3B-48CF-AFB4-0AF70DAF3B12} -> profile=private | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 | 
{BB9FDE1A-3F42-46D5-A98D-F01209D0C412} -> profile=domain | protocol=17 | dir=in | action=allow | name=pando media booster | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
{BEE511C4-9B46-4C73-9DB7-41D04FC3A008} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe | 
{C384D863-4D35-484D-B8D7-4020E27DF58A} -> dir=in | action=allow | name=windows live sync | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
{C698EEDD-0187-4CEA-8672-AFEB1DB1BE73} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe | 
{D242DAD3-E042-407C-8337-1DEE83881CB7} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
{D3A41F92-4DBB-4688-8EE1-FF0EF37465E8} -> profile=public | protocol=6 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
{E36F2CDD-33F3-4109-80E1-33829E2112EA} -> profile=private | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 | 
{E95EA788-82BF-4F23-B701-0E00A2E891D3} -> profile=private | protocol=17 | dir=in | action=allow | name=pnkbstrb | app=c:\windows\syswow64\pnkbstrb.exe | 
{F74540C2-915A-4ECD-BD14-F57B4F67B18C} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe | 
{FC98856A-4506-4762-9F47-D018171FADC5} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot -> 
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 -> 
"DisplayName" -> CD-ROM Driver -> 
"ImagePath" -> C:\Windows\SysNative\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2009/07/13 16:19:54 | 000,147,456 | —- | M] (Microsoft Corporation)
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 -> 
\{05b36f1a-56d5-11df-ad58-00262d289fc4}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell
\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\\"" ->  [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command
\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command\\"" -> G:\LaunchU3.exe [G:\LaunchU3.exe -a] -> File not found
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command -> 
64bit-comfile [open] -> "%1" %* -> File not found
64bit-exefile [open] -> "%1" %* -> File not found
comfile [open] -> "%1" %* -> 
exefile [open] -> "%1" %* -> 
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> 
.com [@ = comfile] -> "%1" %* -> 
.exe [@ = exefile] -> "%1" %* -> 
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> 
.com [@ = comfile] -> "%1" %* -> 
.exe [@ = exefile] -> "%1" %* -> 
 
[Registry - Additional Scans - Safe List]
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 5/14/2010 11:27:01 AM Computer Name = Family | Source = SideBySide | ID = 16842815 -> Description = Activation context generation failed for "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3.  The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid.
Application [ Error ] 5/14/2010 11:27:01 AM Computer Name = Family | Source = SideBySide | ID = 16842785 -> Description = Activation context generation failed for "c:\program files (x86)\innovative solutions\drivermax\DPInst\ia64\dpinst.exe".  Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="ia64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 11:27:14 AM Computer Name = Family | Source = SideBySide | ID = 16842787 -> Description = Activation context generation failed for "c:\program files (x86)\windows live\photo gallery\MovieMaker.Exe".Error in manifest or policy file "c:\program files (x86)\windows live\photo gallery\WLMFDS.DLL" on line 8.  Component identity found in manifest does not match the identity of the component requested.  Reference is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".  Definition is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 11:27:21 AM Computer Name = Family | Source = SideBySide | ID = 16842785 -> Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksCal.exe".  Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 11:27:21 AM Computer Name = Family | Source = SideBySide | ID = 16842785 -> Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe".  Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 11:27:21 AM Computer Name = Family | Source = SideBySide | ID = 16842785 -> Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe".  Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 11:27:21 AM Computer Name = Family | Source = SideBySide | ID = 16842785 -> Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".  Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.  Please use sxstrace.exe for detailed diagnosis.
Application [ Error ] 5/14/2010 7:25:26 PM Computer Name = Family | Source = Application Hang | ID = 1002 -> Description = The program demo32.exe version 7.51.100.2019 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.	Process ID: 1288	Start Time: 01caf3bc55c94740	Termination Time: 0	Application Path: D:\Bin\demo32.exe	Report Id: eb9b9de1-5faf-11df-8b74-00262d289fc4  
Application [ Error ] 5/14/2010 10:46:38 PM Computer Name = Family | Source = Application Hang | ID = 1002 -> Description = The program mbam.exe version 1.46.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.	Process ID: 1884	Start Time: 01caf3d8028cc590	Termination Time: 0	Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe	Report Id: 0f8fbe91-5fcc-11df-8b74-00262d289fc4  
Application [ Error ] 5/14/2010 11:08:09 PM Computer Name = Family | Source = Application Hang | ID = 1002 -> Description = The program mbam.exe version 1.46.0.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.	Process ID: 1b3c	Start Time: 01caf3daebbb01d0	Termination Time: 16	Application Path: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe	Report Id: 10f12b91-5fcf-11df-8b74-00262d289fc4  
System [ Error ] 5/16/2010 10:35:29 AM Computer Name = Family | Source = Application Popup | ID = 1060 -> Description = \??\C:\Windows\system32\9119.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
System [ Error ] 5/16/2010 10:35:29 AM Computer Name = Family | Source = Service Control Manager | ID = 7000 -> Description = The MEMSWEEP2 service failed to start due to the following error:   %%1275
System [ Error ] 5/16/2010 10:35:29 AM Computer Name = Family | Source = Application Popup | ID = 1060 -> Description = \??\C:\Windows\system32\9119.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
System [ Error ] 5/16/2010 10:35:29 AM Computer Name = Family | Source = Service Control Manager | ID = 7000 -> Description = The MEMSWEEP2 service failed to start due to the following error:   %%1275
System [ Error ] 5/16/2010 12:32:51 PM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
System [ Error ] 5/17/2010 12:55:25 AM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
System [ Error ] 5/17/2010 1:04:13 AM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
System [ Error ] 5/17/2010 1:04:14 AM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
System [ Error ] 5/17/2010 1:04:14 AM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
System [ Error ] 5/17/2010 1:04:25 AM Computer Name = Family | Source = Microsoft-Windows-DNS-Client | ID = 1012 -> Description = There was an error while attempting to read the local hosts file.
 
[Files/Folders - Created Within 30 Days]
 OTS.exe -> C:\Users\Bryan\Desktop\OTS.exe -> [2010/05/20 01:10:58 | 000,640,000 | —- | C] (OldTimer Tools)
 OTL.exe -> C:\Users\Bryan\Desktop\OTL.exe -> [2010/05/19 15:38:19 | 000,571,904 | —- | C] (OldTimer Tools)
 TFC.exe -> C:\Users\Bryan\Desktop\TFC.exe -> [2010/05/19 15:37:40 | 000,444,416 | —- | C] (OldTimer Tools)
 BDOSCAN8 -> C:\Windows\BDOSCAN8 -> [2010/05/19 13:05:25 | 000,000,000 | —D | C]
 md5[1] -> C:\Users\Bryan\Documents\md5[1] -> [2010/05/19 11:51:08 | 000,000,000 | —D | C]
 Microsoft Antimalware -> C:\Program Files (x86)\Microsoft Antimalware -> [2010/05/18 15:39:53 | 000,000,000 | —D | C]
 Microsoft Security Essentials -> C:\Program Files\Microsoft Security Essentials -> [2010/05/18 15:39:48 | 000,000,000 | —D | C]
 U3 -> C:\Users\Bryan\AppData\Roaming\U3 -> [2010/05/17 13:05:00 | 000,000,000 | —D | C]
 fssfltr.sys -> C:\Windows\SysNative\drivers\fssfltr.sys -> [2010/05/17 11:32:30 | 000,061,288 | —- | C] (Microsoft Corporation)
 Windows Live -> C:\Program Files\Windows Live -> [2010/05/17 11:32:30 | 000,000,000 | —D | C]
 Microsoft Sync Framework -> C:\Program Files (x86)\Microsoft Sync Framework -> [2010/05/17 11:31:51 | 000,000,000 | —D | C]
 My Stationery -> C:\Users\Bryan\Documents\My Stationery -> [2010/05/17 10:57:41 | 000,000,000 | R-SD | C]
 vlc -> C:\Users\Bryan\AppData\Roaming\vlc -> [2010/05/16 23:31:32 | 000,000,000 | —D | C]
 Graboid_Inc -> C:\Users\Bryan\AppData\Local\Graboid_Inc -> [2010/05/16 23:25:21 | 000,000,000 | —D | C]
 Graboid -> C:\Users\Bryan\AppData\Local\Graboid -> [2010/05/16 23:25:20 | 000,000,000 | —D | C]
 MozillaControl -> C:\Users\Bryan\AppData\Roaming\MozillaControl -> [2010/05/16 23:25:19 | 000,000,000 | —D | C]
 Mozilla -> C:\Users\Bryan\AppData\Roaming\Mozilla -> [2010/05/16 23:25:19 | 000,000,000 | —D | C]
 Mozilla ActiveX Control v1.7.12 -> C:\Program Files (x86)\Mozilla ActiveX Control v1.7.12 -> [2010/05/16 23:25:08 | 000,000,000 | —D | C]
 VideoLAN -> C:\Program Files (x86)\VideoLAN -> [2010/05/16 23:24:53 | 000,000,000 | —D | C]
 hosts[1] -> C:\Users\Bryan\Documents\hosts[1] -> [2010/05/16 22:17:36 | 000,000,000 | —D | C]
 WavesGUILib.dll -> C:\Windows\SysNative\WavesGUILib.dll -> [2010/05/16 13:35:50 | 002,719,504 | —- | C] (Waves Audio Ltd.)
 SRSWOW64.dll -> C:\Windows\SysNative\SRSWOW64.dll -> [2010/05/16 13:35:50 | 000,155,888 | —- | C] (SRS Labs, Inc.)
 RtPgEx64.dll -> C:\Windows\SysNative\RtPgEx64.dll -> [2010/05/16 13:35:49 | 001,943,584 | —- | C] (Realtek Semiconductor Corp.)
 RTSnMg64.cpl -> C:\Windows\SysNative\RTSnMg64.cpl -> [2010/05/16 13:35:49 | 000,612,384 | —- | C] (Realtek Semiconductor Corp.)
 SRSTSX64.dll -> C:\Windows\SysNative\SRSTSX64.dll -> [2010/05/16 13:35:49 | 000,518,896 | —- | C] (SRS Labs, Inc.)
 SRSTSH64.dll -> C:\Windows\SysNative\SRSTSH64.dll -> [2010/05/16 13:35:49 | 000,211,184 | —- | C] (SRS Labs, Inc.)
 SRSHP64.dll -> C:\Windows\SysNative\SRSHP64.dll -> [2010/05/16 13:35:49 | 000,198,896 | —- | C] (SRS Labs, Inc.)
 RtlCPAPI64.dll -> C:\Windows\SysNative\RtlCPAPI64.dll -> [2010/05/16 13:35:48 | 000,332,320 | —- | C] (Realtek Semiconductor Corp.)
 RtkCfg64.dll -> C:\Windows\SysNative\RtkCfg64.dll -> [2010/05/16 13:35:48 | 000,149,536 | —- | C] (Realtek Semiconductor Corp.)
 RtkAPO64.dll -> C:\Windows\SysNative\RtkAPO64.dll -> [2010/05/16 13:35:47 | 001,660,960 | —- | C] (Realtek Semiconductor Corp.)
 RtkApi64.dll -> C:\Windows\SysNative\RtkApi64.dll -> [2010/05/16 13:35:47 | 000,476,192 | —- | C] (Realtek Semiconductor Corp.)
 RTEEP64A.dll -> C:\Windows\SysNative\RTEEP64A.dll -> [2010/05/16 13:35:47 | 000,372,936 | —- | C] (Dolby Laboratories, Inc.)
 RTEED64A.dll -> C:\Windows\SysNative\RTEED64A.dll -> [2010/05/16 13:35:47 | 000,201,928 | —- | C] (Dolby Laboratories, Inc.)
 RTEEL64A.dll -> C:\Windows\SysNative\RTEEL64A.dll -> [2010/05/16 13:35:47 | 000,099,016 | —- | C] (Dolby Laboratories, Inc.)
 RTEEG64A.dll -> C:\Windows\SysNative\RTEEG64A.dll -> [2010/05/16 13:35:47 | 000,076,488 | —- | C] (Dolby Laboratories, Inc.)
 RTCOM64.dll -> C:\Windows\SysNative\RTCOM64.dll -> [2010/05/16 13:35:46 | 001,210,912 | —- | C] (Realtek Semiconductor Corp.)
 RP3DHT64.dll -> C:\Windows\SysNative\RP3DHT64.dll -> [2010/05/16 13:35:46 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.)
 RP3DAA64.dll -> C:\Windows\SysNative\RP3DAA64.dll -> [2010/05/16 13:35:46 | 000,307,920 | —- | C] (Dolby Laboratories, Inc.)
 RCoInst64.dll -> C:\Windows\SysNative\RCoInst64.dll -> [2010/05/16 13:35:46 | 000,069,664 | —- | C] (Realtek Semiconductor Corp.)
 MaxxAudioEQ.dll -> C:\Windows\SysNative\MaxxAudioEQ.dll -> [2010/05/16 13:35:44 | 002,197,264 | —- | C] (Waves Audio Ltd.)
 MaxxAudioAPO20.dll -> C:\Windows\SysNative\MaxxAudioAPO20.dll -> [2010/05/16 13:35:44 | 000,325,904 | —- | C] (Waves Audio Ltd.)
 DTSS2SpeakerDLL64.dll -> C:\Windows\SysNative\DTSS2SpeakerDLL64.dll -> [2010/05/16 13:35:43 | 001,325,328 | —- | C] (DTS)
 DTSS2HeadphoneDLL64.dll -> C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll -> [2010/05/16 13:35:43 | 001,178,384 | —- | C] (DTS)
 DTSSymmetryDLL64.dll -> C:\Windows\SysNative\DTSSymmetryDLL64.dll -> [2010/05/16 13:35:43 | 000,489,744 | —- | C] (DTS)
 DTSVoiceClarityDLL64.dll -> C:\Windows\SysNative\DTSVoiceClarityDLL64.dll -> [2010/05/16 13:35:43 | 000,474,896 | —- | C] (DTS)
 FMAPO64.dll -> C:\Windows\SysNative\FMAPO64.dll -> [2010/05/16 13:35:43 | 000,331,168 | —- | C] (Fortemedia Corporation)
 DTSBoostDLL64.dll -> C:\Windows\SysNative\DTSBoostDLL64.dll -> [2010/05/16 13:35:42 | 001,110,800 | —- | C] (DTS)
 DTSNeoPCDLL64.dll -> C:\Windows\SysNative\DTSNeoPCDLL64.dll -> [2010/05/16 13:35:42 | 000,315,152 | —- | C] (DTS)
 DTSLimiterDLL64.dll -> C:\Windows\SysNative\DTSLimiterDLL64.dll -> [2010/05/16 13:35:42 | 000,268,560 | —- | C] (DTS)
 DTSGainCompensatorDLL64.dll -> C:\Windows\SysNative\DTSGainCompensatorDLL64.dll -> [2010/05/16 13:35:42 | 000,265,488 | —- | C] (DTS)
 DTSLFXAPO64.dll -> C:\Windows\SysNative\DTSLFXAPO64.dll -> [2010/05/16 13:35:42 | 000,123,664 | —- | C] (DTS)
 DTSGFXAPO64.dll -> C:\Windows\SysNative\DTSGFXAPO64.dll -> [2010/05/16 13:35:42 | 000,123,152 | —- | C] (DTS)
 DTSGFXAPONS64.dll -> C:\Windows\SysNative\DTSGFXAPONS64.dll -> [2010/05/16 13:35:42 | 000,122,128 | —- | C] (DTS)
 DTSBassEnhancementDLL64.dll -> C:\Windows\SysNative\DTSBassEnhancementDLL64.dll -> [2010/05/16 13:35:41 | 000,504,592 | —- | C] (DTS)
 AERTAC64.dll -> C:\Windows\SysNative\AERTAC64.dll -> [2010/05/16 13:35:41 | 000,168,288 | —- | C] (Andrea Electronics Corporation)
 AERTAR64.dll -> C:\Windows\SysNative\AERTAR64.dll -> [2010/05/16 13:35:41 | 000,108,960 | —- | C] (Andrea Electronics Corporation)
 Minidump -> C:\Windows\Minidump -> [2010/05/15 16:03:45 | 000,000,000 | —D | C]
 Belarc -> C:\Program Files (x86)\Belarc -> [2010/05/15 11:47:25 | 000,000,000 | —D | C]
 ESET -> C:\Program Files (x86)\ESET -> [2010/05/15 09:26:07 | 000,000,000 | —D | C]
 Trend Micro -> C:\Program Files (x86)\Trend Micro -> [2010/05/14 21:58:30 | 000,000,000 | —D | C]
 Max Payne 2 Savegames -> C:\Users\Bryan\Documents\Max Payne 2 Savegames -> [2010/05/14 16:30:53 | 000,000,000 | —D | C]
 Rockstar Games -> C:\Program Files (x86)\Rockstar Games -> [2010/05/14 16:16:33 | 000,000,000 | —D | C]
 Registrar Registry Manager -> C:\Program Files\Registrar Registry Manager -> [2010/05/14 16:00:35 | 000,000,000 | —D | C]
 CCleaner -> C:\Program Files (x86)\CCleaner -> [2010/05/14 15:44:25 | 000,000,000 | —D | C]
 PCPitstop -> C:\ProgramData\PCPitstop -> [2010/05/14 14:28:01 | 000,000,000 | —D | C]
 PCPitstop -> C:\Program Files (x86)\PCPitstop -> [2010/05/14 14:28:00 | 000,000,000 | —D | C]
 ubuntu -> C:\ubuntu -> [2010/05/13 21:03:26 | 000,000,000 | —D | C]
 nvusmu.exe -> C:\Windows\SysNative\nvusmu.exe -> [2010/05/13 11:12:11 | 000,539,680 | —- | C] (NVIDIA Corporation)
 NVCOSMU.DLL -> C:\Windows\SysNative\NVCOSMU.DLL -> [2010/05/13 11:12:10 | 000,167,936 | —- | C] (NVIDIA Corporation)
 NvRCoPtb.dll -> C:\Windows\SysNative\NvRCoPtb.dll -> [2010/05/13 11:12:10 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoIt.dll -> C:\Windows\SysNative\NvRCoIt.dll -> [2010/05/13 11:12:10 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoFr.dll -> C:\Windows\SysNative\NvRCoFr.dll -> [2010/05/13 11:12:10 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoEsm.dll -> C:\Windows\SysNative\NvRCoEsm.dll -> [2010/05/13 11:12:10 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoEs.dll -> C:\Windows\SysNative\NvRCoEs.dll -> [2010/05/13 11:12:10 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoSv.dll -> C:\Windows\SysNative\NvRCoSv.dll -> [2010/05/13 11:12:10 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoRu.dll -> C:\Windows\SysNative\NvRCoRu.dll -> [2010/05/13 11:12:10 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoNo.dll -> C:\Windows\SysNative\NvRCoNo.dll -> [2010/05/13 11:12:10 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoNl.dll -> C:\Windows\SysNative\NvRCoNl.dll -> [2010/05/13 11:12:10 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoFi.dll -> C:\Windows\SysNative\NvRCoFi.dll -> [2010/05/13 11:12:10 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoENU.dll -> C:\Windows\SysNative\NvRCoENU.dll -> [2010/05/13 11:12:10 | 000,017,952 | —- | C] (NVIDIA Corporation)
 NvRCoKo.dll -> C:\Windows\SysNative\NvRCoKo.dll -> [2010/05/13 11:12:10 | 000,016,416 | —- | C] (NVIDIA Corporation)
 NvRCoJa.dll -> C:\Windows\SysNative\NvRCoJa.dll -> [2010/05/13 11:12:10 | 000,016,416 | —- | C] (NVIDIA Corporation)
 NvRCoZht.dll -> C:\Windows\SysNative\NvRCoZht.dll -> [2010/05/13 11:12:10 | 000,015,904 | —- | C] (NVIDIA Corporation)
 NvRCoZhc.dll -> C:\Windows\SysNative\NvRCoZhc.dll -> [2010/05/13 11:12:10 | 000,015,904 | —- | C] (NVIDIA Corporation)
 nvraiins.dll -> C:\Windows\SysNative\nvraiins.dll -> [2010/05/13 11:12:09 | 000,402,976 | —- | C] (NVIDIA Corporation)
 nvraidco.dll -> C:\Windows\SysNative\nvraidco.dll -> [2010/05/13 11:12:09 | 000,402,976 | —- | C] (NVIDIA Corporation)
 NvRCoDe.dll -> C:\Windows\SysNative\NvRCoDe.dll -> [2010/05/13 11:12:09 | 000,018,976 | —- | C] (NVIDIA Corporation)
 NvRCoDa.dll -> C:\Windows\SysNative\NvRCoDa.dll -> [2010/05/13 11:12:09 | 000,018,464 | —- | C] (NVIDIA Corporation)
 NvRCoEng.dll -> C:\Windows\SysNative\NvRCoEng.dll -> [2010/05/13 11:12:09 | 000,017,952 | —- | C] (NVIDIA Corporation)
 My Drivers -> C:\Users\Bryan\Documents\My Drivers -> [2010/05/13 10:59:13 | 000,000,000 | —D | C]
 Innovative Solutions -> C:\Users\Bryan\AppData\Local\Innovative Solutions -> [2010/05/13 10:59:13 | 000,000,000 | —D | C]
 Innovative Solutions -> C:\ProgramData\Innovative Solutions -> [2010/05/13 10:59:13 | 000,000,000 | —D | C]
 Innovative Solutions -> C:\Program Files (x86)\Innovative Solutions -> [2010/05/13 10:59:07 | 000,000,000 | —D | C]
 61bed -> C:\ProgramData\61bed -> [2010/05/13 02:39:50 | 000,000,000 | —D | C]
 MSZNHANLRRE -> C:\ProgramData\MSZNHANLRRE -> [2010/05/13 02:39:48 | 000,000,000 | -HSD | C]
 f5f4dad -> C:\f5f4dad -> [2010/05/13 02:38:14 | 000,000,000 | -HSD | C]
 ImgBurn -> C:\Users\Bryan\AppData\Roaming\ImgBurn -> [2010/05/12 22:10:54 | 000,000,000 | —D | C]
 ImgBurn -> C:\Program Files (x86)\ImgBurn -> [2010/05/12 22:09:42 | 000,000,000 | —D | C]
 Partition Wizard Home Edition 5.0 -> C:\Program Files (x86)\Partition Wizard Home Edition 5.0 -> [2010/05/12 21:32:17 | 000,000,000 | —D | C]
 Locate32 -> C:\Users\Bryan\AppData\Roaming\Locate32 -> [2010/05/12 11:46:15 | 000,000,000 | —D | C]
 locate32_x64-3.1.9.06070[1] -> C:\Users\Bryan\Documents\locate32_x64-3.1.9.06070[1] -> [2010/05/12 11:45:51 | 000,000,000 | —D | C]
 Apps -> C:\Users\Bryan\AppData\Local\Apps -> [2010/05/12 11:35:40 | 000,000,000 | —D | C]
 VS Revo Group -> C:\Program Files (x86)\VS Revo Group -> [2010/05/12 10:18:34 | 000,000,000 | —D | C]
 Notes -> C:\Users\Bryan\Documents\Notes -> [2010/05/11 18:55:15 | 000,000,000 | R–D | C]
 PunkBuster -> C:\Users\Bryan\AppData\Local\PunkBuster -> [2010/05/10 16:15:36 | 000,000,000 | —D | C]
 xactengine2_8.dll -> C:\Windows\SysNative\xactengine2_8.dll -> [2010/05/10 12:54:04 | 000,409,960 | —- | C] (Microsoft Corporation)
 xactengine2_8.dll -> C:\Windows\SysWow64\xactengine2_8.dll -> [2010/05/10 12:54:04 | 000,266,088 | —- | C] (Microsoft Corporation)
 x3daudio1_2.dll -> C:\Windows\SysNative\x3daudio1_2.dll -> [2010/05/10 12:54:04 | 000,021,352 | —- | C] (Microsoft Corporation)
 x3daudio1_2.dll -> C:\Windows\SysWow64\x3daudio1_2.dll -> [2010/05/10 12:54:04 | 000,018,280 | —- | C] (Microsoft Corporation)
 d3dx9_34.dll -> C:\Windows\SysNative\d3dx9_34.dll -> [2010/05/10 12:54:03 | 004,496,232 | —- | C] (Microsoft Corporation)
 d3dx9_34.dll -> C:\Windows\SysWow64\d3dx9_34.dll -> [2010/05/10 12:54:03 | 003,497,832 | —- | C] (Microsoft Corporation)
 D3DCompiler_34.dll -> C:\Windows\SysNative\D3DCompiler_34.dll -> [2010/05/10 12:54:03 | 001,401,200 | —- | C] (Microsoft Corporation)
 D3DCompiler_34.dll -> C:\Windows\SysWow64\D3DCompiler_34.dll -> [2010/05/10 12:54:03 | 001,124,720 | —- | C] (Microsoft Corporation)
 d3dx10_34.dll -> C:\Windows\SysNative\d3dx10_34.dll -> [2010/05/10 12:54:03 | 000,506,728 | —- | C] (Microsoft Corporation)
 d3dx10_34.dll -> C:\Windows\SysWow64\d3dx10_34.dll -> [2010/05/10 12:54:03 | 000,443,752 | —- | C] (Microsoft Corporation)
 xinput1_3.dll -> C:\Windows\SysNative\xinput1_3.dll -> [2010/05/10 12:54:02 | 000,107,368 | —- | C] (Microsoft Corporation)
 xactengine2_7.dll -> C:\Windows\SysNative\xactengine2_7.dll -> [2010/05/10 12:54:01 | 000,403,304 | —- | C] (Microsoft Corporation)
 xactengine2_7.dll -> C:\Windows\SysWow64\xactengine2_7.dll -> [2010/05/10 12:54:01 | 000,261,480 | —- | C] (Microsoft Corporation)
 d3dx9_33.dll -> C:\Windows\SysNative\d3dx9_33.dll -> [2010/05/10 12:54:00 | 004,494,184 | —- | C] (Microsoft Corporation)
 d3dx9_33.dll -> C:\Windows\SysWow64\d3dx9_33.dll -> [2010/05/10 12:54:00 | 003,495,784 | —- | C] (Microsoft Corporation)
 D3DCompiler_33.dll -> C:\Windows\SysNative\D3DCompiler_33.dll -> [2010/05/10 12:54:00 | 001,400,176 | —- | C] (Microsoft Corporation)
 D3DCompiler_33.dll -> C:\Windows\SysWow64\D3DCompiler_33.dll -> [2010/05/10 12:54:00 | 001,123,696 | —- | C] (Microsoft Corporation)
 d3dx10_33.dll -> C:\Windows\SysNative\d3dx10_33.dll -> [2010/05/10 12:54:00 | 000,506,728 | —- | C] (Microsoft Corporation)
 d3dx10_33.dll -> C:\Windows\SysWow64\d3dx10_33.dll -> [2010/05/10 12:54:00 | 000,443,752 | —- | C] (Microsoft Corporation)
 xactengine2_6.dll -> C:\Windows\SysNative\xactengine2_6.dll -> [2010/05/10 12:53:59 | 000,393,576 | —- | C] (Microsoft Corporation)
 xactengine2_6.dll -> C:\Windows\SysWow64\xactengine2_6.dll -> [2010/05/10 12:53:59 | 000,255,848 | —- | C] (Microsoft Corporation)
 d3dx10.dll -> C:\Windows\SysNative\d3dx10.dll -> [2010/05/10 12:53:58 | 000,469,264 | —- | C] (Microsoft Corporation)
 d3dx10.dll -> C:\Windows\SysWow64\d3dx10.dll -> [2010/05/10 12:53:58 | 000,440,080 | —- | C] (Microsoft Corporation)
 xactengine2_5.dll -> C:\Windows\SysNative\xactengine2_5.dll -> [2010/05/10 12:53:58 | 000,390,424 | —- | C] (Microsoft Corporation)
 xactengine2_5.dll -> C:\Windows\SysWow64\xactengine2_5.dll -> [2010/05/10 12:53:58 | 000,251,672 | —- | C] (Microsoft Corporation)
 xactengine2_4.dll -> C:\Windows\SysNative\xactengine2_4.dll -> [2010/05/10 12:53:56 | 000,364,824 | —- | C] (Microsoft Corporation)
 xactengine2_4.dll -> C:\Windows\SysWow64\xactengine2_4.dll -> [2010/05/10 12:53:56 | 000,237,848 | —- | C] (Microsoft Corporation)
 x3daudio1_1.dll -> C:\Windows\SysNative\x3daudio1_1.dll -> [2010/05/10 12:53:56 | 000,017,688 | —- | C] (Microsoft Corporation)
 x3daudio1_1.dll -> C:\Windows\SysWow64\x3daudio1_1.dll -> [2010/05/10 12:53:56 | 000,015,128 | —- | C] (Microsoft Corporation)
 d3dx9_31.dll -> C:\Windows\SysNative\d3dx9_31.dll -> [2010/05/10 12:53:55 | 003,977,496 | —- | C] (Microsoft Corporation)
 d3dx9_31.dll -> C:\Windows\SysWow64\d3dx9_31.dll -> [2010/05/10 12:53:55 | 002,414,360 | —- | C] (Microsoft Corporation)
 xactengine2_3.dll -> C:\Windows\SysNative\xactengine2_3.dll -> [2010/05/10 12:53:54 | 000,363,288 | —- | C] (Microsoft Corporation)
 xactengine2_3.dll -> C:\Windows\SysWow64\xactengine2_3.dll -> [2010/05/10 12:53:54 | 000,236,824 | —- | C] (Microsoft Corporation)
 xinput1_2.dll -> C:\Windows\SysNative\xinput1_2.dll -> [2010/05/10 12:53:54 | 000,083,736 | —- | C] (Microsoft Corporation)
 xinput1_2.dll -> C:\Windows\SysWow64\xinput1_2.dll -> [2010/05/10 12:53:54 | 000,062,744 | —- | C] (Microsoft Corporation)
 xactengine2_2.dll -> C:\Windows\SysNative\xactengine2_2.dll -> [2010/05/10 12:53:53 | 000,354,072 | —- | C] (Microsoft Corporation)
 xactengine2_2.dll -> C:\Windows\SysWow64\xactengine2_2.dll -> [2010/05/10 12:53:53 | 000,230,168 | —- | C] (Microsoft Corporation)
 xinput1_1.dll -> C:\Windows\SysNative\xinput1_1.dll -> [2010/05/10 12:53:52 | 000,083,664 | —- | C] (Microsoft Corporation)
 xinput1_1.dll -> C:\Windows\SysWow64\xinput1_1.dll -> [2010/05/10 12:53:52 | 000,062,672 | —- | C] (Microsoft Corporation)
 xactengine2_1.dll -> C:\Windows\SysNative\xactengine2_1.dll -> [2010/05/10 12:53:51 | 000,352,464 | —- | C] (Microsoft Corporation)
 xactengine2_1.dll -> C:\Windows\SysWow64\xactengine2_1.dll -> [2010/05/10 12:53:51 | 000,229,584 | —- | C] (Microsoft Corporation)
 d3dx9_30.dll -> C:\Windows\SysNative\d3dx9_30.dll -> [2010/05/10 12:53:46 | 003,927,248 | —- | C] (Microsoft Corporation)
 d3dx9_30.dll -> C:\Windows\SysWow64\d3dx9_30.dll -> [2010/05/10 12:53:46 | 002,388,176 | —- | C] (Microsoft Corporation)
 xactengine2_0.dll -> C:\Windows\SysNative\xactengine2_0.dll -> [2010/05/10 12:53:45 | 000,355,536 | —- | C] (Microsoft Corporation)
 xactengine2_0.dll -> C:\Windows\SysWow64\xactengine2_0.dll -> [2010/05/10 12:53:45 | 000,230,096 | —- | C] (Microsoft Corporation)
 x3daudio1_0.dll -> C:\Windows\SysNative\x3daudio1_0.dll -> [2010/05/10 12:53:45 | 000,016,592 | —- | C] (Microsoft Corporation)
 x3daudio1_0.dll -> C:\Windows\SysWow64\x3daudio1_0.dll -> [2010/05/10 12:53:45 | 000,014,032 | —- | C] (Microsoft Corporation)
 d3dx9_29.dll -> C:\Windows\SysNative\d3dx9_29.dll -> [2010/05/10 12:53:44 | 003,830,992 | —- | C] (Microsoft Corporation)
 d3dx9_28.dll -> C:\Windows\SysNative\d3dx9_28.dll -> [2010/05/10 12:53:44 | 003,815,120 | —- | C] (Microsoft Corporation)
 d3dx9_29.dll -> C:\Windows\SysWow64\d3dx9_29.dll -> [2010/05/10 12:53:44 | 002,332,368 | —- | C] (Microsoft Corporation)
 d3dx9_28.dll -> C:\Windows\SysWow64\d3dx9_28.dll -> [2010/05/10 12:53:44 | 002,323,664 | —- | C] (Microsoft Corporation)
 d3dx9_27.dll -> C:\Windows\SysNative\d3dx9_27.dll -> [2010/05/10 12:53:43 | 003,807,440 | —- | C] (Microsoft Corporation)
 d3dx9_26.dll -> C:\Windows\SysNative\d3dx9_26.dll -> [2010/05/10 12:53:43 | 003,767,504 | —- | C] (Microsoft Corporation)
 d3dx9_27.dll -> C:\Windows\SysWow64\d3dx9_27.dll -> [2010/05/10 12:53:43 | 002,319,568 | —- | C] (Microsoft Corporation)
 d3dx9_26.dll -> C:\Windows\SysWow64\d3dx9_26.dll -> [2010/05/10 12:53:43 | 002,297,552 | —- | C] (Microsoft Corporation)
 d3dx9_25.dll -> C:\Windows\SysNative\d3dx9_25.dll -> [2010/05/10 12:53:42 | 003,823,312 | —- | C] (Microsoft Corporation)
 d3dx9_25.dll -> C:\Windows\SysWow64\d3dx9_25.dll -> [2010/05/10 12:53:42 | 002,337,488 | —- | C] (Microsoft Corporation)
 d3dx9_24.dll -> C:\Windows\SysNative\d3dx9_24.dll -> [2010/05/10 12:53:41 | 003,544,272 | —- | C] (Microsoft Corporation)
 d3dx9_24.dll -> C:\Windows\SysWow64\d3dx9_24.dll -> [2010/05/10 12:53:41 | 002,222,800 | —- | C] (Microsoft Corporation)
 Activision -> C:\Program Files (x86)\Activision -> [2010/05/10 12:17:19 | 000,000,000 | —D | C]
 ftpcache -> C:\Windows\ftpcache -> [2010/05/10 12:14:57 | 000,000,000 | -HSD | C]
 Masque -> C:\Users\Bryan\AppData\Roaming\Masque -> [2010/05/10 11:58:23 | 000,000,000 | —D | C]
 Masque -> C:\ProgramData\Masque -> [2010/05/10 11:58:23 | 000,000,000 | —D | C]
 Masque IGT Slots Little Green Men -> C:\Program Files (x86)\Masque IGT Slots Little Green Men -> [2010/05/10 11:56:20 | 000,000,000 | —D | C]
 Sophos -> C:\Program Files (x86)\Sophos -> [2010/05/09 13:36:14 | 000,000,000 | —D | C]
 mbamswissarmy.sys -> C:\Windows\SysWow64\drivers\mbamswissarmy.sys -> [2010/05/09 13:26:03 | 000,038,224 | —- | C] (Malwarebytes Corporation)
 mbam.sys -> C:\Windows\SysNative\drivers\mbam.sys -> [2010/05/09 13:26:01 | 000,024,664 | —- | C] (Malwarebytes Corporation)
 Eraser 6 -> C:\Users\Bryan\AppData\Local\Eraser 6 -> [2010/05/08 22:57:16 | 000,000,000 | —D | C]
 Microsoft Games -> C:\Users\Bryan\AppData\Local\Microsoft Games -> [2010/05/08 21:39:39 | 000,000,000 | —D | C]
 Eraser -> C:\Program Files\Eraser -> [2010/05/08 10:22:27 | 000,000,000 | —D | C]
 MyDefragScreenSaver_v4.2.9.exe -> C:\Windows\SysNative\MyDefragScreenSaver_v4.2.9.exe -> [2010/05/08 10:11:45 | 001,114,112 | —- | C] (J.C. Kessels)
 MyDefragScreenSaver_v4.2.9.scr -> C:\Windows\SysNative\MyDefragScreenSaver_v4.2.9.scr -> [2010/05/08 10:11:45 | 000,442,880 | —- | C] (J.C. Kessels)
 MyDefrag v4.2.9 -> C:\Program Files\MyDefrag v4.2.9 -> [2010/05/08 10:11:45 | 000,000,000 | —D | C]
 7-Zip -> C:\Program Files\7-Zip -> [2010/05/07 22:04:54 | 000,000,000 | —D | C]
 Yahoo! Companion -> C:\ProgramData\Yahoo! Companion -> [2010/05/07 13:19:54 | 000,000,000 | —D | C]
 Yahoo! -> C:\Users\Bryan\AppData\Roaming\Yahoo! -> [2010/05/07 13:19:54 | 000,000,000 | —D | C]
 Yahoo! -> C:\Program Files (x86)\Yahoo! -> [2010/05/07 13:19:53 | 000,000,000 | —D | C]
 Recuva -> C:\Program Files\Recuva -> [2010/05/07 13:19:49 | 000,000,000 | —D | C]
 ElevatedDiagnostics -> C:\Users\Bryan\AppData\Local\ElevatedDiagnostics -> [2010/05/07 01:00:16 | 000,000,000 | —D | C]
 Diagnostics -> C:\Users\Bryan\AppData\Local\Diagnostics -> [2010/05/06 22:44:36 | 000,000,000 | —D | C]
 NVIDIA -> C:\Users\Bryan\AppData\Roaming\NVIDIA -> [2010/05/06 21:20:07 | 000,000,000 | —D | C]
 d3dx10_42.dll -> C:\Windows\SysWow64\d3dx10_42.dll -> [2010/05/06 20:43:48 | 000,453,456 | —- | C] (Microsoft Corporation)
 xinput1_3.dll -> C:\Windows\SysWow64\xinput1_3.dll -> [2010/05/06 20:43:48 | 000,081,768 | —- | C] (Microsoft Corporation)
 Perfect Uninstaller -> C:\Program Files\Perfect Uninstaller -> [2010/05/06 19:41:49 | 000,000,000 | —D | C]
 S.T.A.L.K.E.R. - Call of Pripyat -> C:\Users\Public\Documents\S.T.A.L.K.E.R. - Call of Pripyat -> [2010/05/06 15:06:37 | 000,000,000 | —D | C]
 MyWinLockerData -> C:\MyWinLockerData -> [2010/05/06 11:52:56 | 000,000,000 | -H-D | C]
 Malwarebytes -> C:\Users\Bryan\AppData\Roaming\Malwarebytes -> [2010/05/06 10:22:22 | 000,000,000 | —D | C]
 Malwarebytes -> C:\ProgramData\Malwarebytes -> [2010/05/06 10:22:13 | 000,000,000 | —D | C]
 Malwarebytes' Anti-Malware -> C:\Program Files (x86)\Malwarebytes' Anti-Malware -> [2010/05/06 10:22:12 | 000,000,000 | —D | C]
 Nexon -> C:\ProgramData\Nexon -> [2010/05/06 02:02:47 | 000,000,000 | —D | C]
 PMB Files -> C:\Users\Bryan\AppData\Local\PMB Files -> [2010/05/05 20:25:30 | 000,000,000 | —D | C]
 SystemRequirementsLab -> C:\Program Files (x86)\SystemRequirementsLab -> [2010/05/05 01:49:45 | 000,000,000 | —D | C]
 PMB Files -> C:\ProgramData\PMB Files -> [2010/05/05 01:26:30 | 000,000,000 | —D | C]
 Pando Networks -> C:\Program Files (x86)\Pando Networks -> [2010/05/05 01:26:09 | 000,000,000 | —D | C]
 OnlineArmor -> C:\Users\Bryan\AppData\Roaming\OnlineArmor -> [2010/05/04 21:52:30 | 000,000,000 | —D | C]
 OnlineArmor -> C:\ProgramData\OnlineArmor -> [2010/05/04 21:52:30 | 000,000,000 | —D | C]
 OAnet.sys -> C:\Windows\SysNative\drivers\OAnet.sys -> [2010/05/04 21:44:13 | 000,046,456 | —- | C] (Tall Emu Pty Ltd)
 OAmon.sys -> C:\Windows\SysWow64\drivers\OAmon.sys -> [2010/05/04 21:44:13 | 000,038,776 | —- | C] (Tall Emu)
 Tall Emu -> C:\Program Files (x86)\Tall Emu -> [2010/05/04 21:44:11 | 000,000,000 | —D | C]
 archive_db -> C:\archive_db -> [2010/05/03 19:50:29 | 000,000,000 | —D | C]
 Paragon -> C:\ProgramData\Paragon -> [2010/05/03 19:50:10 | 000,000,000 | —D | C]
 explauncher -> C:\ProgramData\explauncher -> [2010/05/03 19:43:05 | 000,000,000 | —D | C]
 hotcore3.sys -> C:\Windows\SysNative\drivers\hotcore3.sys -> [2010/05/03 19:16:20 | 000,037,392 | —- | C] (Paragon Software Group)
 DRVSTORE -> C:\Windows\SysNative\DRVSTORE -> [2010/05/03 19:16:20 | 000,000,000 | —D | C]
 Paragon Software -> C:\Program Files (x86)\Paragon Software -> [2010/05/03 19:16:01 | 000,000,000 | —D | C]
 CheckSur -> C:\Windows\CheckSur -> [2010/05/03 16:09:59 | 000,000,000 | —D | C]
 Downloads -> C:\Users\Bryan\Documents\Downloads -> [2010/05/03 15:53:06 | 000,000,000 | —D | C]
 Alwil Software -> C:\ProgramData\Alwil Software -> [2010/05/03 15:50:49 | 000,000,000 | —D | C]
 Alwil Software -> C:\Program Files\Alwil Software -> [2010/05/03 15:50:49 | 000,000,000 | —D | C]
 Nero -> C:\Users\Bryan\AppData\Roaming\Nero -> [2010/05/03 13:22:47 | 000,000,000 | —D | C]
 OpenDNS Updater -> C:\Users\Bryan\AppData\Roaming\OpenDNS Updater -> [2010/05/03 03:02:20 | 000,000,000 | —D | C]
 OpenDNS Updater -> C:\Program Files (x86)\OpenDNS Updater -> [2010/05/03 03:02:19 | 000,000,000 | —D | C]
 MSXML 4.0 -> C:\Program Files (x86)\MSXML 4.0 -> [2010/05/03 01:15:51 | 000,000,000 | —D | C]
 t2embed.dll -> C:\Windows\SysWow64\t2embed.dll -> [2010/05/03 01:07:07 | 000,108,544 | —- | C] (Microsoft Corporation)
 fontsub.dll -> C:\Windows\SysNative\fontsub.dll -> [2010/05/03 01:07:07 | 000,100,864 | —- | C] (Microsoft Corporation)
 fontsub.dll -> C:\Windows\SysWow64\fontsub.dll -> [2010/05/03 01:07:07 | 000,070,656 | —- | C] (Microsoft Corporation)
 t2embed.dll -> C:\Windows\SysNative\t2embed.dll -> [2010/05/03 01:07:06 | 000,148,480 | —- | C] (Microsoft Corporation)
 vbscript.dll -> C:\Windows\SysNative\vbscript.dll -> [2010/05/03 01:07:03 | 000,612,352 | —- | C] (Microsoft Corporation)
 vbscript.dll -> C:\Windows\SysWow64\vbscript.dll -> [2010/05/03 01:07:03 | 000,427,520 | —- | C] (Microsoft Corporation)
 wininet.dll -> C:\Windows\SysWow64\wininet.dll -> [2010/05/03 01:06:50 | 000,977,920 | —- | C] (Microsoft Corporation)
 iedkcs32.dll -> C:\Windows\SysWow64\iedkcs32.dll -> [2010/05/03 01:06:50 | 000,381,440 | —- | C] (Microsoft Corporation)
 msfeedsbs.dll -> C:\Windows\SysWow64\msfeedsbs.dll -> [2010/05/03 01:06:50 | 000,064,512 | —- | C] (Microsoft Corporation)
 mstime.dll -> C:\Windows\SysWow64\mstime.dll -> [2010/05/03 01:06:48 | 000,606,208 | —- | C] (Microsoft Corporation)
 wininet.dll -> C:\Windows\SysNative\wininet.dll -> [2010/05/03 01:06:46 | 001,192,960 | —- | C] (Microsoft Corporation)
 iedkcs32.dll -> C:\Windows\SysNative\iedkcs32.dll -> [2010/05/03 01:06:46 | 000,445,952 | —- | C] (Microsoft Corporation)
 msfeedsbs.dll -> C:\Windows\SysNative\msfeedsbs.dll -> [2010/05/03 01:06:46 | 000,082,944 | —- | C] (Microsoft Corporation)
 mstime.dll -> C:\Windows\SysNative\mstime.dll -> [2010/05/03 01:06:45 | 001,026,048 | —- | C] (Microsoft Corporation)
 ntkrnlpa.exe -> C:\Windows\SysWow64\ntkrnlpa.exe -> [2010/05/03 01:06:41 | 003,954,568 | —- | C] (Microsoft Corporation)
 ntoskrnl.exe -> C:\Windows\SysWow64\ntoskrnl.exe -> [2010/05/03 01:06:41 | 003,899,280 | —- | C] (Microsoft Corporation)
 ntoskrnl.exe -> C:\Windows\SysNative\ntoskrnl.exe -> [2010/05/03 01:06:40 | 005,509,008 | —- | C] (Microsoft Corporation)
 avifil32.dll -> C:\Windows\SysWow64\avifil32.dll -> [2010/05/03 01:06:29 | 000,091,648 | —- | C] (Microsoft Corporation)
 mciavi32.dll -> C:\Windows\SysWow64\mciavi32.dll -> [2010/05/03 01:06:29 | 000,084,480 | —- | C] (Microsoft Corporation)
 quartz.dll -> C:\Windows\SysNative\quartz.dll -> [2010/05/03 01:06:28 | 001,572,352 | —- | C] (Microsoft Corporation)
 quartz.dll -> C:\Windows\SysWow64\quartz.dll -> [2010/05/03 01:06:28 | 001,328,640 | —- | C] (Microsoft Corporation)
 msvidc32.dll -> C:\Windows\SysNative\msvidc32.dll -> [2010/05/03 01:06:28 | 000,038,912 | —- | C] (Microsoft Corporation)
 msrle32.dll -> C:\Windows\SysNative\msrle32.dll -> [2010/05/03 01:06:28 | 000,016,384 | —- | C] (Microsoft Corporation)
 iyuv_32.dll -> C:\Windows\SysNative\iyuv_32.dll -> [2010/05/03 01:06:27 | 000,054,272 | —- | C] (Microsoft Corporation)
 msyuv.dll -> C:\Windows\SysNative\msyuv.dll -> [2010/05/03 01:06:27 | 000,025,088 | —- | C] (Microsoft Corporation)
 tsbyuv.dll -> C:\Windows\SysNative\tsbyuv.dll -> [2010/05/03 01:06:27 | 000,014,848 | —- | C] (Microsoft Corporation)
 secproc.dll -> C:\Windows\SysWow64\secproc.dll -> [2010/05/03 01:06:22 | 000,369,152 | —- | C] (Microsoft Corporation)
 RMActivate.exe -> C:\Windows\SysWow64\RMActivate.exe -> [2010/05/03 01:06:22 | 000,320,512 | —- | C] (Microsoft Corporation)
 secproc_ssp.dll -> C:\Windows\SysWow64\secproc_ssp.dll -> [2010/05/03 01:06:22 | 000,085,504 | —- | C] (Microsoft Corporation)
 secproc_isv.dll -> C:\Windows\SysWow64\secproc_isv.dll -> [2010/05/03 01:06:21 | 000,365,568 | —- | C] (Microsoft Corporation)
 RMActivate_isv.exe -> C:\Windows\SysWow64\RMActivate_isv.exe -> [2010/05/03 01:06:21 | 000,324,608 | —- | C] (Microsoft Corporation)
 RMActivate_ssp.exe -> C:\Windows\SysWow64\RMActivate_ssp.exe -> [2010/05/03 01:06:21 | 000,280,064 | —- | C] (Microsoft Corporation)
 RMActivate_ssp_isv.exe -> C:\Windows\SysWow64\RMActivate_ssp_isv.exe -> [2010/05/03 01:06:21 | 000,277,504 | —- | C] (Microsoft Corporation)
 secproc_ssp_isv.dll -> C:\Windows\SysWow64\secproc_ssp_isv.dll -> [2010/05/03 01:06:21 | 000,085,504 | —- | C] (Microsoft Corporation)
 secproc.dll -> C:\Windows\SysNative\secproc.dll -> [2010/05/03 01:06:20 | 000,424,960 | —- | C] (Microsoft Corporation)
 RMActivate.exe -> C:\Windows\SysNative\RMActivate.exe -> [2010/05/03 01:06:20 | 000,356,352 | —- | C] (Microsoft Corporation)
 secproc_isv.dll -> C:\Windows\SysNative\secproc_isv.dll -> [2010/05/03 01:06:19 | 000,422,912 | —- | C] (Microsoft Corporation)
 RMActivate_isv.exe -> C:\Windows\SysNative\RMActivate_isv.exe -> [2010/05/03 01:06:19 | 000,357,888 | —- | C] (Microsoft Corporation)
 RMActivate_ssp.exe -> C:\Windows\SysNative\RMActivate_ssp.exe -> [2010/05/03 01:06:19 | 000,306,688 | —- | C] (Microsoft Corporation)
 secproc_ssp_isv.dll -> C:\Windows\SysNative\secproc_ssp_isv.dll -> [2010/05/03 01:06:19 | 000,121,856 | —- | C] (Microsoft Corporation)
 secproc_ssp.dll -> C:\Windows\SysNative\secproc_ssp.dll -> [2010/05/03 01:06:19 | 000,121,856 | —- | C] (Microsoft Corporation)
 RMActivate_ssp_isv.exe -> C:\Windows\SysNative\RMActivate_ssp_isv.exe -> [2010/05/03 01:06:18 | 000,305,152 | —- | C] (Microsoft Corporation)
 explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2010/05/03 01:06:15 | 002,614,272 | —- | C] (Microsoft Corporation)
 winlogon.exe -> C:\Windows\SysNative\winlogon.exe -> [2010/05/03 01:06:14 | 000,389,632 | —- | C] (Microsoft Corporation)
 explorer.exe -> C:\Windows\explorer.exe -> [2010/05/03 01:06:13 | 002,870,272 | —- | C] (Microsoft Corporation)
 setup16.exe -> C:\Windows\SysWow64\setup16.exe -> [2010/05/03 01:06:09 | 000,025,600 | —- | C] (Microsoft Corporation)
 ntvdm64.dll -> C:\Windows\SysWow64\ntvdm64.dll -> [2010/05/03 01:06:09 | 000,014,336 | —- | C] (Microsoft Corporation)
 instnm.exe -> C:\Windows\SysWow64\instnm.exe -> [2010/05/03 01:06:09 | 000,007,680 | —- | C] (Microsoft Corporation)
 wow32.dll -> C:\Windows\SysWow64\wow32.dll -> [2010/05/03 01:06:09 | 000,005,120 | —- | C] (Microsoft Corporation)
 user.exe -> C:\Windows\SysWow64\user.exe -> [2010/05/03 01:06:09 | 000,002,048 | —- | C] (Microsoft Corporation)
 wow64.dll -> C:\Windows\SysNative\wow64.dll -> [2010/05/03 01:06:08 | 000,243,200 | —- | C] (Microsoft Corporation)
 fvevol.sys -> C:\Windows\SysNative\drivers\fvevol.sys -> [2010/05/03 01:06:03 | 000,223,448 | —- | C] (Microsoft Corporation)
 Wat -> C:\Windows\SysWow64\Wat -> [2010/05/03 01:01:20 | 000,000,000 | —D | C]
 Wat -> C:\Windows\SysNative\Wat -> [2010/05/03 01:01:19 | 000,000,000 | —D | C]
 jscript.dll -> C:\Windows\SysNative\jscript.dll -> [2010/05/03 01:01:09 | 000,852,480 | —- | C] (Microsoft Corporation)
 jscript.dll -> C:\Windows\SysWow64\jscript.dll -> [2010/05/03 01:01:09 | 000,716,800 | —- | C] (Microsoft Corporation)
 lsasrv.dll -> C:\Windows\SysNative\lsasrv.dll -> [2010/05/03 01:01:00 | 001,446,912 | —- | C] (Microsoft Corporation)
 ksecpkg.sys -> C:\Windows\SysNative\drivers\ksecpkg.sys -> [2010/05/03 01:01:00 | 000,153,160 | —- | C] (Microsoft Corporation)
 CPFilters.dll -> C:\Windows\SysWow64\CPFilters.dll -> [2010/05/03 01:00:54 | 000,641,536 | —- | C] (Microsoft Corporation)
 psisdecd.dll -> C:\Windows\SysWow64\psisdecd.dll -> [2010/05/03 01:00:54 | 000,465,408 | —- | C] (Microsoft Corporation)
 MSNP.ax -> C:\Windows\SysWow64\MSNP.ax -> [2010/05/03 01:00:53 | 000,204,288 | —- | C] (Microsoft Corporation)
 psisdecd.dll -> C:\Windows\SysNative\psisdecd.dll -> [2010/05/03 01:00:52 | 000,613,888 | —- | C] (Microsoft Corporation)
 msdri.dll -> C:\Windows\SysNative\msdri.dll -> [2010/05/03 01:00:52 | 000,552,960 | —- | C] (Microsoft Corporation)
 MSNP.ax -> C:\Windows\SysNative\MSNP.ax -> [2010/05/03 01:00:52 | 000,288,256 | —- | C] (Microsoft Corporation)
 CPFilters.dll -> C:\Windows\SysNative\CPFilters.dll -> [2010/05/03 01:00:51 | 000,960,512 | —- | C] (Microsoft Corporation)
 Microsoft Help -> C:\Users\Bryan\AppData\Local\Microsoft Help -> [2010/05/03 00:55:56 | 000,000,000 | —D | C]
 Adobe -> C:\Program Files (x86)\Common Files\Adobe -> [2010/05/03 00:52:58 | 000,000,000 | —D | C]
 Adobe -> C:\Users\Bryan\AppData\Local\Adobe -> [2010/05/03 00:52:15 | 000,000,000 | —D | C]
 PSI -> C:\Users\Bryan\PSI -> [2010/05/03 00:44:56 | 000,000,000 | —D | C]
 PokerStars -> C:\Users\Bryan\AppData\Local\PokerStars -> [2010/05/03 00:00:05 | 000,000,000 | —D | C]
 PokerStars -> C:\Program Files (x86)\PokerStars -> [2010/05/02 23:59:53 | 000,000,000 | —D | C]
 Sun -> C:\Windows\Sun -> [2010/05/02 15:11:09 | 000,000,000 | —D | C]
 Sun -> C:\ProgramData\Sun -> [2010/05/02 15:10:58 | 000,000,000 | —D | C]
 Java -> C:\Program Files (x86)\Common Files\Java -> [2010/05/02 15:10:57 | 000,000,000 | —D | C]
 deployJava1.dll -> C:\Windows\SysWow64\deployJava1.dll -> [2010/05/02 15:10:44 | 000,411,368 | —- | C] (Sun Microsystems, Inc.)
 javaws.exe -> C:\Windows\SysWow64\javaws.exe -> [2010/05/02 15:10:44 | 000,153,376 | —- | C] (Sun Microsystems, Inc.)
 javaw.exe -> C:\Windows\SysWow64\javaw.exe -> [2010/05/02 15:10:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.)
 java.exe -> C:\Windows\SysWow64\java.exe -> [2010/05/02 15:10:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.)
 Java -> C:\Program Files (x86)\Java -> [2010/05/02 15:10:29 | 000,000,000 | —D | C]
 WildTangent -> C:\Users\Bryan\AppData\Roaming\WildTangent -> [2010/05/02 14:46:49 | 000,000,000 | —D | C]
 Template -> C:\Users\Bryan\AppData\Roaming\Template -> [2010/05/02 14:44:55 | 000,000,000 | —D | C]
 wintrust.dll -> C:\Windows\SysNative\wintrust.dll -> [2010/05/02 12:50:43 | 000,220,672 | —- | C] (Microsoft Corporation)
 wintrust.dll -> C:\Windows\SysWow64\wintrust.dll -> [2010/05/02 12:50:43 | 000,172,032 | —- | C] (Microsoft Corporation)
 cabview.dll -> C:\Windows\SysNative\cabview.dll -> [2010/05/02 12:50:41 | 000,139,264 | —- | C] (Microsoft Corporation)
 cabview.dll -> C:\Windows\SysWow64\cabview.dll -> [2010/05/02 12:50:41 | 000,132,608 | —- | C] (Microsoft Corporation)
 FarmFrenzy-PizzaParty -> C:\ProgramData\FarmFrenzy-PizzaParty -> [2010/05/02 11:31:01 | 000,000,000 | —D | C]
 Tracing -> C:\Users\Bryan\Tracing -> [2010/05/01 23:06:27 | 000,000,000 | —D | C]
 Google -> C:\Users\Bryan\AppData\Roaming\Google -> [2010/05/01 22:58:40 | 000,000,000 | —D | C]
 Google -> C:\Users\Bryan\AppData\Local\Google -> [2010/05/01 22:58:40 | 000,000,000 | —D | C]
 Adobe -> C:\Users\Bryan\AppData\Roaming\Adobe -> [2010/05/01 22:40:54 | 000,000,000 | —D | C]
 Acer -> C:\Users\Bryan\AppData\Roaming\Acer -> [2010/05/01 22:39:25 | 000,000,000 | —D | C]
 Leadertech -> C:\Users\Bryan\AppData\Roaming\Leadertech -> [2010/05/01 22:39:24 | 000,000,000 | —D | C]
 Macromedia -> C:\Users\Bryan\AppData\Roaming\Macromedia -> [2010/05/01 22:39:23 | 000,000,000 | —D | C]
 EgisTec -> C:\Users\Bryan\AppData\Local\EgisTec -> [2010/05/01 22:39:23 | 000,000,000 | —D | C]
 Searches -> C:\Users\Bryan\Searches -> [2010/05/01 22:39:04 | 000,000,000 | R–D | C]
 Identities -> C:\Users\Bryan\AppData\Roaming\Identities -> [2010/05/01 22:38:55 | 000,000,000 | —D | C]
 Contacts -> C:\Users\Bryan\Contacts -> [2010/05/01 22:38:52 | 000,000,000 | R–D | C]
 VirtualStore -> C:\Users\Bryan\AppData\Local\VirtualStore -> [2010/05/01 22:38:50 | 000,000,000 | —D | C]
 OEM_E471269A730D -> C:\ProgramData\OEM_E471269A730D -> [2010/05/01 22:35:59 | 000,000,000 | —D | C]
 OEM -> C:\Program Files (x86)\OEM -> [2010/05/01 22:35:56 | 000,000,000 | —D | C]
 Microsoft -> C:\Users\Bryan\AppData\Roaming\Microsoft -> [2010/05/01 22:35:47 | 000,000,000 | –SD | C]
 Videos -> C:\Users\Bryan\Videos -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Saved Games -> C:\Users\Bryan\Saved Games -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Pictures -> C:\Users\Bryan\Pictures -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Music -> C:\Users\Bryan\Music -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Links -> C:\Users\Bryan\Links -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Favorites -> C:\Users\Bryan\Favorites -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Downloads -> C:\Users\Bryan\Downloads -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Documents -> C:\Users\Bryan\My Documents -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Desktop -> C:\Users\Bryan\Desktop -> [2010/05/01 22:35:47 | 000,000,000 | R–D | C]
 Temporary Internet Files -> C:\Users\Bryan\AppData\Local\Temporary Internet Files -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Templates -> C:\Users\Bryan\Templates -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Start Menu -> C:\Users\Bryan\Start Menu -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 SendTo -> C:\Users\Bryan\SendTo -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Recent -> C:\Users\Bryan\Recent -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 PrintHood -> C:\Users\Bryan\PrintHood -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 NetHood -> C:\Users\Bryan\NetHood -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 My Videos -> C:\Users\Bryan\Documents\My Videos -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 My Pictures -> C:\Users\Bryan\Documents\My Pictures -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 My Music -> C:\Users\Bryan\Documents\My Music -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 My Documents -> C:\Users\Bryan\My Documents -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Local Settings -> C:\Users\Bryan\Local Settings -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 History -> C:\Users\Bryan\AppData\Local\History -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Cookies -> C:\Users\Bryan\Cookies -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Application Data -> C:\Users\Bryan\Application Data -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 Application Data -> C:\Users\Bryan\AppData\Local\Application Data -> [2010/05/01 22:35:47 | 000,000,000 | -HSD | C]
 AppData -> C:\Users\Bryan\AppData -> [2010/05/01 22:35:47 | 000,000,000 | -H-D | C]
 Temp -> C:\Users\Bryan\AppData\Local\Temp -> [2010/05/01 22:35:47 | 000,000,000 | —D | C]
 Microsoft -> C:\Users\Bryan\AppData\Local\Microsoft -> [2010/05/01 22:35:47 | 000,000,000 | —D | C]
 Media Center Programs -> C:\Users\Bryan\AppData\Roaming\Media Center Programs -> [2010/05/01 22:35:47 | 000,000,000 | —D | C]
 Templates -> C:\ProgramData\Templates -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Start Menu -> C:\ProgramData\Start Menu -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Recovery -> C:\Recovery -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 My Videos -> C:\Users\Public\Documents\My Videos -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 My Pictures -> C:\Users\Public\Documents\My Pictures -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 My Music -> C:\Users\Public\Documents\My Music -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Favorites -> C:\ProgramData\Favorites -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Documents and Settings -> C:\Documents and Settings -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Documents -> C:\ProgramData\Documents -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Desktop -> C:\ProgramData\Desktop -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 Application Data -> C:\ProgramData\Application Data -> [2010/05/01 22:34:42 | 000,000,000 | -HSD | C]
 
[Files/Folders - Modified Within 30 Days]
 ntuser.dat -> C:\Users\Bryan\ntuser.dat -> [2010/05/20 01:15:42 | 002,621,440 | -HS- | M] ()
 OTS.exe -> C:\Users\Bryan\Desktop\OTS.exe -> [2010/05/20 01:11:05 | 000,640,000 | —- | M] (OldTimer Tools)
 GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2010/05/20 00:33:00 | 000,000,896 | —- | M] ()
 GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2010/05/19 23:15:39 | 000,000,892 | —- | M] ()
 bootstat.dat -> C:\Windows\bootstat.dat -> [2010/05/19 23:02:45 | 000,067,584 | –S- | M] ()
 7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010/05/19 15:51:53 | 000,009,920 | -H– | M] ()
 7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010/05/19 15:51:53 | 000,009,920 | -H– | M] ()
 PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2010/05/19 15:48:58 | 000,713,888 | —- | M] ()
 perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2010/05/19 15:48:58 | 000,615,122 | —- | M] ()
 perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2010/05/19 15:48:58 | 000,103,496 | —- | M] ()
 IconCache.db -> C:\Users\Bryan\AppData\Local\IconCache.db -> [2010/05/19 15:46:32 | 003,130,706 | -H– | M] ()
 SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010/05/19 15:44:32 | 000,000,006 | -H– | M] ()
 hiberfil.sys -> C:\hiberfil.sys -> [2010/05/19 15:44:04 | 3018,756,096 | -HS- | M] ()
 OTL.exe -> C:\Users\Bryan\Desktop\OTL.exe -> [2010/05/19 15:38:26 | 000,571,904 | —- | M] (OldTimer Tools)
 TFC.exe -> C:\Users\Bryan\Desktop\TFC.exe -> [2010/05/19 15:37:45 | 000,444,416 | —- | M] (OldTimer Tools)
 Pictures - Shortcut.lnk -> C:\Users\Bryan\Desktop\Pictures - Shortcut.lnk -> [2010/05/18 18:55:05 | 000,001,127 | —- | M] ()
 Resmon.ResmonCfg -> C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg -> [2010/05/18 15:48:28 | 000,007,597 | —- | M] ()
 Microsoft Security Essentials.lnk -> C:\Users\Public\Desktop\Microsoft Security Essentials.lnk -> [2010/05/18 15:39:48 | 000,001,035 | —- | M] ()
 mdres.exe -> C:\Windows\SysWow64\mdres.exe -> [2010/05/17 13:27:24 | 000,000,000 | —- | M] ()
 MdSched.exe -> C:\Windows\SysWow64\MdSched.exe -> [2010/05/17 13:12:28 | 000,000,000 | —- | M] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/17 01:11:45 | 000,524,288 | -HS- | M] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/17 01:11:45 | 000,524,288 | -HS- | M] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TM.blf -> [2010/05/17 01:11:45 | 000,065,536 | -HS- | M] ()
 Recuva.lnk -> C:\Users\Bryan\Desktop\Recuva.lnk -> [2010/05/17 00:54:34 | 000,001,662 | —- | M] ()
 MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2010/05/15 16:03:42 | 433,216,774 | —- | M] ()
 DXPServer.exe -> C:\Windows\SysWow64\DXPServer.exe -> [2010/05/15 15:10:25 | 000,000,000 | —- | M] ()
 DeviceDisplayObjectProvider.exe -> C:\Windows\SysWow64\DeviceDisplayObjectProvider.exe -> [2010/05/15 15:10:18 | 000,000,000 | —- | M] ()
 Msft_User_WpdMtpDr_01_09_00.Wdf -> C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf -> [2010/05/15 15:10:16 | 000,000,000 | -H– | M] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/15 14:58:18 | 000,524,288 | -HS- | M] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/15 14:58:18 | 000,524,288 | -HS- | M] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TM.blf -> [2010/05/15 14:58:18 | 000,065,536 | -HS- | M] ()
 HiJackThis.lnk -> C:\Users\Bryan\Desktop\HiJackThis.lnk -> [2010/05/15 13:09:46 | 000,002,975 | —- | M] ()
 Belarc Advisor.lnk -> C:\Users\Public\Desktop\Belarc Advisor.lnk -> [2010/05/15 11:47:26 | 000,002,007 | —- | M] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/14 23:29:49 | 000,524,288 | -HS- | M] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/14 23:29:49 | 000,524,288 | -HS- | M] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TM.blf -> [2010/05/14 23:29:49 | 000,065,536 | -HS- | M] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/14 00:17:20 | 000,524,288 | -HS- | M] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/14 00:17:20 | 000,524,288 | -HS- | M] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TM.blf -> [2010/05/14 00:17:20 | 000,065,536 | -HS- | M] ()
 wubildr -> C:\wubildr -> [2010/05/14 00:16:58 | 000,088,813 | —- | M] ()
 wubildr.mbr -> C:\wubildr.mbr -> [2010/05/14 00:16:58 | 000,008,192 | —- | M] ()
 housecall.guid.cache -> C:\Users\Bryan\AppData\Local\housecall.guid.cache -> [2010/05/13 19:08:49 | 000,000,036 | —- | M] ()
 mvps.bat -> C:\Windows\SysNative\drivers\etc\mvps.bat -> [2010/05/13 18:12:02 | 000,001,615 | —- | M] ()
 hosts.zip.zip -> C:\Windows\SysNative\drivers\etc\hosts.zip.zip -> [2010/05/13 18:10:55 | 000,149,705 | —- | M] ()
 PnkBstrB.exe -> C:\Windows\SysWow64\PnkBstrB.exe -> [2010/05/13 12:43:29 | 000,103,736 | —- | M] ()
 PnkBstrA.exe -> C:\Windows\SysWow64\PnkBstrA.exe -> [2010/05/13 12:43:24 | 000,066,872 | —- | M] ()
 nvuSMU.exe -> C:\Windows\SysWow64\nvuSMU.exe -> [2010/05/13 11:13:07 | 000,000,000 | —- | M] ()
 DriverMax.lnk -> C:\Users\Bryan\Desktop\DriverMax.lnk -> [2010/05/13 10:59:10 | 000,001,118 | —- | M] ()
 ImgBurn.lnk -> C:\Users\Public\Desktop\ImgBurn.lnk -> [2010/05/12 22:09:42 | 000,001,869 | —- | M] ()
 Partition Wizard Home Edition.lnk -> C:\Users\Bryan\Desktop\Partition Wizard Home Edition.lnk -> [2010/05/12 21:40:30 | 000,001,127 | —- | M] ()
 PnkBstrB.xtr -> C:\Windows\SysWow64\PnkBstrB.xtr -> [2010/05/12 17:39:08 | 000,219,128 | —- | M] ()
 CompMgmtLauncher.exe -> C:\Windows\SysWow64\CompMgmtLauncher.exe -> [2010/05/12 13:52:21 | 000,000,000 | —- | M] ()
 Revo Uninstaller.lnk -> C:\Users\Bryan\Desktop\Revo Uninstaller.lnk -> [2010/05/12 10:18:34 | 000,001,268 | —- | M] ()
 MpSigStub.exe -> C:\Windows\SysWow64\MpSigStub.exe -> [2010/05/12 07:54:18 | 000,000,000 | —- | M] ()
 MRT.exe -> C:\Windows\SysWow64\MRT.exe -> [2010/05/12 07:53:03 | 000,000,000 | —- | M] ()
 lpremove.exe -> C:\Windows\SysWow64\lpremove.exe -> [2010/05/11 06:38:37 | 000,000,000 | —- | M] ()
 aitagent.EXE -> C:\Windows\SysWow64\aitagent.EXE -> [2010/05/11 06:31:36 | 000,000,000 | —- | M] ()
 Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk -> C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk -> [2010/05/10 12:45:48 | 000,002,010 | —- | M] ()
 Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk -> C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk -> [2010/05/10 12:45:48 | 000,002,010 | —- | M] ()
 game.ini -> C:\Windows\game.ini -> [2010/05/10 12:45:13 | 000,000,331 | —- | M] ()
 IGT Slots Little Green Men.lnk -> C:\Users\Public\Desktop\IGT Slots Little Green Men.lnk -> [2010/05/10 11:58:10 | 000,002,575 | —- | M] ()
 Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2010/05/09 13:26:06 | 000,001,013 | —- | M] ()
 Paragon Partition Manager™ 2010 Free Edition.lnk -> C:\Users\Bryan\Desktop\Paragon Partition Manager™ 2010 Free Edition.lnk -> [2010/05/08 21:03:54 | 000,002,519 | —- | M] ()
 Eraser.lnk -> C:\Users\Public\Desktop\Eraser.lnk -> [2010/05/08 10:22:34 | 000,001,751 | —- | M] ()
 MyDefrag.lnk -> C:\Users\Public\Desktop\MyDefrag.lnk -> [2010/05/08 10:11:46 | 000,000,867 | —- | M] ()
 Google Chrome.lnk -> C:\Users\Bryan\Desktop\Google Chrome.lnk -> [2010/05/07 20:40:11 | 000,002,198 | —- | M] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 17:43:37 | 000,524,288 | -HS- | M] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 17:43:37 | 000,524,288 | -HS- | M] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TM.blf -> [2010/05/07 17:43:37 | 000,065,536 | -HS- | M] ()
 pcwutl.dll -> C:\Windows\SysWow64\pcwutl.dll -> [2010/05/07 17:39:36 | 000,000,000 | —- | M] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 13:46:53 | 000,524,288 | -HS- | M] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 13:46:53 | 000,524,288 | -HS- | M] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TM.blf -> [2010/05/07 13:46:53 | 000,065,536 | -HS- | M] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 13:36:50 | 000,524,288 | -HS- | M] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 13:36:50 | 000,524,288 | -HS- | M] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TM.blf -> [2010/05/07 13:36:50 | 000,065,536 | -HS- | M] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 10:55:38 | 000,524,288 | -HS- | M] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 10:55:38 | 000,524,288 | -HS- | M] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TM.blf -> [2010/05/07 10:55:38 | 000,065,536 | -HS- | M] ()
 GoogleUpdateTaskUserS-1-5-21-3488347447-2488368954-518346416-1000Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3488347447-2488368954-518346416-1000Core.job -> [2010/05/07 10:03:00 | 000,000,856 | —- | M] ()
 StikyNot.exe -> C:\Windows\SysWow64\StikyNot.exe -> [2010/05/07 01:41:26 | 000,000,000 | —- | M] ()
 pcwrun.exe -> C:\Windows\SysWow64\pcwrun.exe -> [2010/05/06 22:43:50 | 000,000,000 | —- | M] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/06 20:34:34 | 000,524,288 | -HS- | M] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/06 20:34:34 | 000,524,288 | -HS- | M] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TM.blf -> [2010/05/06 20:34:34 | 000,065,536 | -HS- | M] ()
 s.t.a.l.k.e.r.ltx -> C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx -> [2010/05/06 15:33:22 | 000,006,593 | —- | M] ()
 WerConCpl.dll -> C:\Windows\SysWow64\WerConCpl.dll -> [2010/05/05 01:17:07 | 000,000,000 | —- | M] ()
 dinotify.exe -> C:\Windows\SysWow64\dinotify.exe -> [2010/05/05 01:16:23 | 000,000,000 | —- | M] ()
 pcalua.exe -> C:\Windows\SysWow64\pcalua.exe -> [2010/05/04 22:46:16 | 000,000,000 | —- | M] ()
 OASettings100504.OA -> C:\Users\Bryan\Documents\OASettings100504.OA -> [2010/05/04 22:10:00 | 000,992,229 | —- | M] ()
 OnlineArmor_Setup_PlusPlus - Shortcut.lnk -> C:\Users\Bryan\Desktop\OnlineArmor_Setup_PlusPlus - Shortcut.lnk -> [2010/05/04 21:33:29 | 000,001,069 | —- | M] ()
 HOSTS -> C:\Windows\SysNative\drivers\etc\hosts.zip\HOSTS -> [2010/05/04 14:31:04 | 000,607,013 | —- | M] ()
 HOSTS -> C:\Windows\SysNative\drivers\etc\HOSTS -> [2010/05/04 14:31:04 | 000,607,013 | —- | M] ()
 Google Chrome.lnk -> C:\Users\Public\Desktop\Google Chrome.lnk -> [2010/05/04 12:01:07 | 000,002,198 | —- | M] ()
 Paragon Backup & Recovery™ 10.1 Free Edition.lnk -> C:\Users\Bryan\Desktop\Paragon Backup & Recovery™ 10.1 Free Edition.lnk -> [2010/05/03 19:16:20 | 000,002,519 | —- | M] ()
 config.nt -> C:\Windows\SysWow64\config.nt -> [2010/05/03 15:51:31 | 000,000,000 | —- | M] ()
 ntuser.pol -> C:\Users\Bryan\ntuser.pol -> [2010/05/03 13:10:50 | 000,000,632 | RHS- | M] ()
 Adobe Reader 9.lnk -> C:\Users\Public\Desktop\Adobe Reader 9.lnk -> [2010/05/03 01:10:53 | 000,002,018 | —- | M] ()
 Microsoft Works.lnk -> C:\Users\Public\Desktop\Microsoft Works.lnk -> [2010/05/03 01:00:08 | 000,001,139 | —- | M] ()
 PokerStars.lnk -> C:\Users\Public\Desktop\PokerStars.lnk -> [2010/05/03 00:00:01 | 000,001,065 | —- | M] ()
 javaws.exe -> C:\Windows\SysWow64\javaws.exe -> [2010/05/02 15:10:31 | 000,153,376 | —- | M] (Sun Microsystems, Inc.)
 javaw.exe -> C:\Windows\SysWow64\javaw.exe -> [2010/05/02 15:10:31 | 000,145,184 | —- | M] (Sun Microsystems, Inc.)
 java.exe -> C:\Windows\SysWow64\java.exe -> [2010/05/02 15:10:31 | 000,145,184 | —- | M] (Sun Microsystems, Inc.)
 deployJava1.dll -> C:\Windows\SysWow64\deployJava1.dll -> [2010/05/02 15:10:30 | 000,411,368 | —- | M] (Sun Microsystems, Inc.)
 wklnhst.dat -> C:\Users\Bryan\AppData\Roaming\wklnhst.dat -> [2010/05/02 14:44:28 | 000,000,000 | —- | M] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/02 12:49:33 | 000,524,288 | -HS- | M] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/02 12:49:33 | 000,524,288 | -HS- | M] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TM.blf -> [2010/05/02 12:49:33 | 000,065,536 | -HS- | M] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/01 22:49:26 | 000,524,288 | -HS- | M] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/01 22:49:26 | 000,524,288 | -HS- | M] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf -> [2010/05/01 22:49:26 | 000,065,536 | -HS- | M] ()
 Internet Explorer.lnk -> C:\Users\Bryan\Desktop\Internet Explorer.lnk -> [2010/05/01 22:39:11 | 000,001,447 | —- | M] ()
 GDIPFONTCACHEV1.DAT -> C:\Users\Bryan\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010/05/01 22:36:07 | 000,079,152 | —- | M] ()
 Netflix.lnk -> C:\Users\Public\Desktop\Netflix.lnk -> [2010/05/01 22:35:59 | 000,002,102 | —- | M] ()
 eBay.lnk -> C:\Users\Public\Desktop\eBay.lnk -> [2010/05/01 22:35:56 | 000,002,609 | —- | M] ()
 ntuser.ini -> C:\Users\Bryan\ntuser.ini -> [2010/05/01 22:35:47 | 000,000,020 | -HS- | M] ()
 license.rtf -> C:\Windows\SysWow64\license.rtf -> [2010/05/01 21:28:16 | 000,039,252 | —- | M] ()
 license.rtf -> C:\Windows\SysNative\license.rtf -> [2010/05/01 21:28:16 | 000,039,252 | —- | M] ()
 mbamswissarmy.sys -> C:\Windows\SysWow64\drivers\mbamswissarmy.sys -> [2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation)
 mbam.sys -> C:\Windows\SysNative\drivers\mbam.sys -> [2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation)
 fssfltr.sys -> C:\Windows\SysNative\drivers\fssfltr.sys -> [2010/04/28 08:57:50 | 000,061,288 | —- | M] (Microsoft Corporation)
 OADriver.sys -> C:\Windows\SysWow64\drivers\OADriver.sys -> [2010/04/20 04:13:26 | 000,055,160 | —- | M] ()
 OAmon.sys -> C:\Windows\SysWow64\drivers\OAmon.sys -> [2010/04/20 04:13:24 | 000,038,776 | —- | M] (Tall Emu)
 OAnet.sys -> C:\Windows\SysNative\drivers\OAnet.sys -> [2010/04/20 04:13:20 | 000,046,456 | —- | M] (Tall Emu Pty Ltd)
 
[Files - No Company Name]
 Pictures - Shortcut.lnk -> C:\Users\Bryan\Desktop\Pictures - Shortcut.lnk -> [2010/05/18 18:55:05 | 000,001,127 | —- | C] ()
 Microsoft Security Essentials.lnk -> C:\Users\Public\Desktop\Microsoft Security Essentials.lnk -> [2010/05/18 15:39:48 | 000,001,035 | —- | C] ()
 mdres.exe -> C:\Windows\SysWow64\mdres.exe -> [2010/05/17 13:27:24 | 000,000,000 | —- | C] ()
 MdSched.exe -> C:\Windows\SysWow64\MdSched.exe -> [2010/05/17 13:12:28 | 000,000,000 | —- | C] ()
 Recuva.lnk -> C:\Users\Bryan\Desktop\Recuva.lnk -> [2010/05/17 00:54:34 | 000,001,662 | —- | C] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/16 22:21:07 | 000,524,288 | -HS- | C] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/16 22:21:07 | 000,524,288 | -HS- | C] ()
 ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{911b0d48-6171-11df-89fd-00262d289fc4}.TM.blf -> [2010/05/16 22:21:07 | 000,065,536 | -HS- | C] ()
 MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2010/05/15 16:03:42 | 433,216,774 | —- | C] ()
 DXPServer.exe -> C:\Windows\SysWow64\DXPServer.exe -> [2010/05/15 15:10:25 | 000,000,000 | —- | C] ()
 DeviceDisplayObjectProvider.exe -> C:\Windows\SysWow64\DeviceDisplayObjectProvider.exe -> [2010/05/15 15:10:18 | 000,000,000 | —- | C] ()
 Msft_User_WpdMtpDr_01_09_00.Wdf -> C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf -> [2010/05/15 15:10:16 | 000,000,000 | -H– | C] ()
 HiJackThis.lnk -> C:\Users\Bryan\Desktop\HiJackThis.lnk -> [2010/05/15 13:09:46 | 000,002,975 | —- | C] ()
 Belarc Advisor.lnk -> C:\Users\Public\Desktop\Belarc Advisor.lnk -> [2010/05/15 11:47:26 | 000,002,007 | —- | C] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/15 08:30:11 | 000,524,288 | -HS- | C] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/15 08:30:11 | 000,524,288 | -HS- | C] ()
 ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{e18fb18c-6035-11df-ad70-00262d289fc4}.TM.blf -> [2010/05/15 08:30:11 | 000,065,536 | -HS- | C] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/14 21:26:13 | 000,524,288 | -HS- | C] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/14 21:26:13 | 000,524,288 | -HS- | C] ()
 ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{3bb27f3f-5fd3-11df-ad2e-00262d289fc4}.TM.blf -> [2010/05/14 21:26:13 | 000,065,536 | -HS- | C] ()
 wubildr -> C:\wubildr -> [2010/05/14 00:16:58 | 000,088,813 | —- | C] ()
 wubildr.mbr -> C:\wubildr.mbr -> [2010/05/14 00:16:58 | 000,008,192 | —- | C] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/13 22:07:16 | 000,524,288 | -HS- | C] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/13 22:07:16 | 000,524,288 | -HS- | C] ()
 ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{133bfd4a-5ec9-11df-a441-00262d289fc4}.TM.blf -> [2010/05/13 22:07:16 | 000,065,536 | -HS- | C] ()
 housecall.guid.cache -> C:\Users\Bryan\AppData\Local\housecall.guid.cache -> [2010/05/13 19:08:49 | 000,000,036 | —- | C] ()
 nvuSMU.exe -> C:\Windows\SysWow64\nvuSMU.exe -> [2010/05/13 11:13:07 | 000,000,000 | —- | C] ()
 nvsmu.nvu -> C:\Windows\SysNative\nvsmu.nvu -> [2010/05/13 11:12:10 | 000,001,463 | —- | C] ()
 DriverMax.lnk -> C:\Users\Bryan\Desktop\DriverMax.lnk -> [2010/05/13 10:59:10 | 000,001,118 | —- | C] ()
 ImgBurn.lnk -> C:\Users\Public\Desktop\ImgBurn.lnk -> [2010/05/12 22:09:42 | 000,001,869 | —- | C] ()
 Partition Wizard Home Edition.lnk -> C:\Users\Bryan\Desktop\Partition Wizard Home Edition.lnk -> [2010/05/12 21:40:30 | 000,001,127 | —- | C] ()
 pwNative.exe -> C:\Windows\SysNative\pwNative.exe -> [2010/05/12 21:33:41 | 000,611,400 | —- | C] ()
 pwdrvio.sys -> C:\Windows\SysNative\pwdrvio.sys -> [2010/05/12 21:33:40 | 000,019,936 | —- | C] ()
 pwdspio.sys -> C:\Windows\SysNative\pwdspio.sys -> [2010/05/12 21:33:40 | 000,013,280 | —- | C] ()
 CompMgmtLauncher.exe -> C:\Windows\SysWow64\CompMgmtLauncher.exe -> [2010/05/12 13:52:21 | 000,000,000 | —- | C] ()
 Revo Uninstaller.lnk -> C:\Users\Bryan\Desktop\Revo Uninstaller.lnk -> [2010/05/12 10:18:34 | 000,001,268 | —- | C] ()
 MpSigStub.exe -> C:\Windows\SysWow64\MpSigStub.exe -> [2010/05/12 07:54:18 | 000,000,000 | —- | C] ()
 MRT.exe -> C:\Windows\SysWow64\MRT.exe -> [2010/05/12 07:53:03 | 000,000,000 | —- | C] ()
 lpremove.exe -> C:\Windows\SysWow64\lpremove.exe -> [2010/05/11 06:38:37 | 000,000,000 | —- | C] ()
 aitagent.EXE -> C:\Windows\SysWow64\aitagent.EXE -> [2010/05/11 06:31:36 | 000,000,000 | —- | C] ()
 IconCache.db -> C:\Users\Bryan\AppData\Local\IconCache.db -> [2010/05/11 00:32:05 | 003,130,706 | -H– | C] ()
 PnkBstrB.xtr -> C:\Windows\SysWow64\PnkBstrB.xtr -> [2010/05/10 16:23:07 | 000,219,128 | —- | C] ()
 Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk -> C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Singleplayer.lnk -> [2010/05/10 12:45:48 | 000,002,010 | —- | C] ()
 Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk -> C:\Users\Public\Desktop\Call of Duty(R) 4 - Modern Warfare(TM) Multiplayer.lnk -> [2010/05/10 12:45:48 | 000,002,010 | —- | C] ()
 PnkBstrB.exe -> C:\Windows\SysWow64\PnkBstrB.exe -> [2010/05/10 12:45:20 | 000,103,736 | —- | C] ()
 PnkBstrA.exe -> C:\Windows\SysWow64\PnkBstrA.exe -> [2010/05/10 12:45:17 | 000,066,872 | —- | C] ()
 game.ini -> C:\Windows\game.ini -> [2010/05/10 12:45:12 | 000,000,331 | —- | C] ()
 IGT Slots Little Green Men.lnk -> C:\Users\Public\Desktop\IGT Slots Little Green Men.lnk -> [2010/05/10 11:58:10 | 000,002,575 | —- | C] ()
 Malwarebytes' Anti-Malware.lnk -> C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk -> [2010/05/09 13:26:06 | 000,001,013 | —- | C] ()
 Paragon Partition Manager™ 2010 Free Edition.lnk -> C:\Users\Bryan\Desktop\Paragon Partition Manager™ 2010 Free Edition.lnk -> [2010/05/08 21:03:54 | 000,002,519 | —- | C] ()
 Eraser.lnk -> C:\Users\Public\Desktop\Eraser.lnk -> [2010/05/08 10:22:34 | 000,001,751 | —- | C] ()
 Resmon.ResmonCfg -> C:\Users\Bryan\AppData\Local\Resmon.ResmonCfg -> [2010/05/08 10:16:55 | 000,007,597 | —- | C] ()
 MyDefrag.lnk -> C:\Users\Public\Desktop\MyDefrag.lnk -> [2010/05/08 10:11:46 | 000,000,867 | —- | C] ()
 Google Chrome.lnk -> C:\Users\Bryan\Desktop\Google Chrome.lnk -> [2010/05/07 20:40:11 | 000,002,198 | —- | C] ()
 pcwutl.dll -> C:\Windows\SysWow64\pcwutl.dll -> [2010/05/07 17:39:36 | 000,000,000 | —- | C] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 17:22:51 | 000,524,288 | -HS- | C] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 17:22:51 | 000,524,288 | -HS- | C] ()
 ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{7e448a08-5a18-11df-9743-00262d289fc4}.TM.blf -> [2010/05/07 17:22:51 | 000,065,536 | -HS- | C] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 13:38:52 | 000,524,288 | -HS- | C] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 13:38:52 | 000,524,288 | -HS- | C] ()
 ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{05d6a49e-5a18-11df-ad29-00262d289fc4}.TM.blf -> [2010/05/07 13:38:52 | 000,065,536 | -HS- | C] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 13:35:44 | 000,524,288 | -HS- | C] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 13:35:44 | 000,524,288 | -HS- | C] ()
 ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{db79ecf5-5a01-11df-a11f-00262d289fc4}.TM.blf -> [2010/05/07 13:35:44 | 000,065,536 | -HS- | C] ()
 GoogleUpdateTaskUserS-1-5-21-3488347447-2488368954-518346416-1000Core.job -> C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3488347447-2488368954-518346416-1000Core.job -> [2010/05/07 09:58:16 | 000,000,856 | —- | C] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/07 08:54:26 | 000,524,288 | -HS- | C] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/07 08:54:26 | 000,524,288 | -HS- | C] ()
 ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{006dea7b-59ee-11df-b8d5-00262d289fc4}.TM.blf -> [2010/05/07 08:54:26 | 000,065,536 | -HS- | C] ()
 StikyNot.exe -> C:\Windows\SysWow64\StikyNot.exe -> [2010/05/07 01:41:26 | 000,000,000 | —- | C] ()
 pcwrun.exe -> C:\Windows\SysWow64\pcwrun.exe -> [2010/05/06 22:43:50 | 000,000,000 | —- | C] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/06 20:16:00 | 000,524,288 | -HS- | C] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/06 20:16:00 | 000,524,288 | -HS- | C] ()
 ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{bd72ccac-597f-11df-9b4b-00262d289fc4}.TM.blf -> [2010/05/06 20:16:00 | 000,065,536 | -HS- | C] ()
 s.t.a.l.k.e.r.ltx -> C:\Users\Public\Documents\s.t.a.l.k.e.r.ltx -> [2010/05/06 15:33:22 | 000,006,593 | —- | C] ()
 WerConCpl.dll -> C:\Windows\SysWow64\WerConCpl.dll -> [2010/05/05 01:17:07 | 000,000,000 | —- | C] ()
 dinotify.exe -> C:\Windows\SysWow64\dinotify.exe -> [2010/05/05 01:16:23 | 000,000,000 | —- | C] ()
 pcalua.exe -> C:\Windows\SysWow64\pcalua.exe -> [2010/05/04 22:46:16 | 000,000,000 | —- | C] ()
 OASettings100504.OA -> C:\Users\Bryan\Documents\OASettings100504.OA -> [2010/05/04 22:09:54 | 000,992,229 | —- | C] ()
 OADriver.sys -> C:\Windows\SysWow64\drivers\OADriver.sys -> [2010/05/04 21:44:13 | 000,055,160 | —- | C] ()
 OnlineArmor_Setup_PlusPlus - Shortcut.lnk -> C:\Users\Bryan\Desktop\OnlineArmor_Setup_PlusPlus - Shortcut.lnk -> [2010/05/04 21:33:01 | 000,001,069 | —- | C] ()
 Paragon Backup & Recovery™ 10.1 Free Edition.lnk -> C:\Users\Bryan\Desktop\Paragon Backup & Recovery™ 10.1 Free Edition.lnk -> [2010/05/03 19:16:20 | 000,002,519 | —- | C] ()
 Google Chrome.lnk -> C:\Users\Public\Desktop\Google Chrome.lnk -> [2010/05/03 15:52:28 | 000,002,198 | —- | C] ()
 config.nt -> C:\Windows\SysWow64\config.nt -> [2010/05/03 15:51:31 | 000,000,000 | —- | C] ()
 ntuser.pol -> C:\Users\Bryan\ntuser.pol -> [2010/05/03 13:09:55 | 000,000,632 | RHS- | C] ()
 GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2010/05/03 03:28:12 | 000,000,896 | —- | C] ()
 GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2010/05/03 03:28:11 | 000,000,892 | —- | C] ()
 Microsoft Works.lnk -> C:\Users\Public\Desktop\Microsoft Works.lnk -> [2010/05/03 01:00:08 | 000,001,139 | —- | C] ()
 Adobe Reader 9.lnk -> C:\Users\Public\Desktop\Adobe Reader 9.lnk -> [2010/05/03 00:53:08 | 000,002,018 | —- | C] ()
 PokerStars.lnk -> C:\Users\Public\Desktop\PokerStars.lnk -> [2010/05/03 00:00:01 | 000,001,065 | —- | C] ()
 wklnhst.dat -> C:\Users\Bryan\AppData\Roaming\wklnhst.dat -> [2010/05/02 14:44:28 | 000,000,000 | —- | C] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/02 12:47:12 | 000,524,288 | -HS- | C] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/02 12:47:12 | 000,524,288 | -HS- | C] ()
 ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TM.blf -> C:\Users\Bryan\ntuser.dat{d41bcbb4-55ef-11df-b0d6-00262d289fc4}.TM.blf -> [2010/05/02 12:47:12 | 000,065,536 | -HS- | C] ()
 Internet Explorer.lnk -> C:\Users\Bryan\Desktop\Internet Explorer.lnk -> [2010/05/01 22:39:06 | 000,001,447 | —- | C] ()
 GDIPFONTCACHEV1.DAT -> C:\Users\Bryan\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010/05/01 22:36:07 | 000,079,152 | —- | C] ()
 Netflix.lnk -> C:\Users\Public\Desktop\Netflix.lnk -> [2010/05/01 22:35:59 | 000,002,102 | —- | C] ()
 eBay.lnk -> C:\Users\Public\Desktop\eBay.lnk -> [2010/05/01 22:35:56 | 000,002,609 | —- | C] ()
 ntuser.dat -> C:\Users\Bryan\ntuser.dat -> [2010/05/01 22:35:47 | 002,621,440 | -HS- | C] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms -> [2010/05/01 22:35:47 | 000,524,288 | -HS- | C] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms -> [2010/05/01 22:35:47 | 000,524,288 | -HS- | C] ()
 ntuser.dat.LOG1 -> C:\Users\Bryan\ntuser.dat.LOG1 -> [2010/05/01 22:35:47 | 000,262,144 | -HS- | C] ()
 NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf -> C:\Users\Bryan\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf -> [2010/05/01 22:35:47 | 000,065,536 | -HS- | C] ()
 ntuser.ini -> C:\Users\Bryan\ntuser.ini -> [2010/05/01 22:35:47 | 000,000,020 | -HS- | C] ()
 ntuser.dat.LOG2 -> C:\Users\Bryan\ntuser.dat.LOG2 -> [2010/05/01 22:35:47 | 000,000,000 | -HS- | C] ()
 GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2009/07/13 22:32:39 | 000,043,318 | —- | C] ()
 GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2009/07/13 22:32:39 | 000,029,779 | —- | C] ()
 GlobalSansSerif.CompositeFont -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont -> [2009/07/13 22:32:39 | 000,026,489 | —- | C] ()
 GlobalMonospace.CompositeFont -> C:\Windows\Fonts\GlobalMonospace.CompositeFont -> [2009/07/13 22:32:39 | 000,026,040 | —- | C] ()
 BWContextHandler.dll -> C:\Windows\SysWow64\BWContextHandler.dll -> [2009/07/13 16:42:10 | 000,064,000 | —- | C] ()
 msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2009/07/13 14:03:59 | 000,364,544 | —- | C] ()
 bdoscandellang.ini -> C:\Windows\bdoscandellang.ini -> [2009/01/05 15:44:10 | 000,000,453 | —- | C] ()
 
[File - Lop Check]
 Acer -> C:\Users\Bryan\AppData\Roaming\Acer -> [2010/05/01 22:39:25 | 000,000,000 | —D | M]
 ImgBurn -> C:\Users\Bryan\AppData\Roaming\ImgBurn -> [2010/05/12 22:10:54 | 000,000,000 | —D | M]
 Leadertech -> C:\Users\Bryan\AppData\Roaming\Leadertech -> [2010/05/01 22:39:24 | 000,000,000 | —D | M]
 Locate32 -> C:\Users\Bryan\AppData\Roaming\Locate32 -> [2010/05/12 11:46:15 | 000,000,000 | —D | M]
 Masque -> C:\Users\Bryan\AppData\Roaming\Masque -> [2010/05/10 12:07:38 | 000,000,000 | —D | M]
 OnlineArmor -> C:\Users\Bryan\AppData\Roaming\OnlineArmor -> [2010/05/12 09:52:38 | 000,000,000 | —D | M]
 OpenDNS Updater -> C:\Users\Bryan\AppData\Roaming\OpenDNS Updater -> [2010/05/03 03:02:20 | 000,000,000 | —D | M]
 Template -> C:\Users\Bryan\AppData\Roaming\Template -> [2010/05/02 14:44:55 | 000,000,000 | —D | M]
 WildTangent -> C:\Users\Bryan\AppData\Roaming\WildTangent -> [2010/05/02 14:46:49 | 000,000,000 | —D | M]
 Acer -> C:\Users\Daniel\AppData\Roaming\Acer -> [2010/05/02 11:14:08 | 000,000,000 | —D | M]
 Leadertech -> C:\Users\Daniel\AppData\Roaming\Leadertech -> [2010/05/02 11:14:07 | 000,000,000 | —D | M]
 WildTangent -> C:\Users\Daniel\AppData\Roaming\WildTangent -> [2010/05/02 11:30:02 | 000,000,000 | —D | M]
 Acer -> C:\Users\Daniel.Family\AppData\Roaming\Acer -> [2010/05/05 01:15:47 | 000,000,000 | —D | M]
 Leadertech -> C:\Users\Daniel.Family\AppData\Roaming\Leadertech -> [2010/05/05 01:15:47 | 000,000,000 | —D | M]
 OnlineArmor -> C:\Users\Daniel.Family\AppData\Roaming\OnlineArmor -> [2010/05/05 01:15:51 | 000,000,000 | —D | M]
 SystemRequirementsLab -> C:\Users\Daniel.Family\AppData\Roaming\SystemRequirementsLab -> [2010/05/05 01:50:03 | 000,000,000 | —D | M]
 Acer -> C:\Users\Zanthia\AppData\Roaming\Acer -> [2010/05/02 01:07:31 | 000,000,000 | —D | M]
 Leadertech -> C:\Users\Zanthia\AppData\Roaming\Leadertech -> [2010/05/02 01:07:29 | 000,000,000 | —D | M]
 Acer -> C:\Users\Zanthia.Family\AppData\Roaming\Acer -> [2010/05/02 12:55:48 | 000,000,000 | —D | M]
 Leadertech -> C:\Users\Zanthia.Family\AppData\Roaming\Leadertech -> [2010/05/02 12:55:47 | 000,000,000 | —D | M]
 Masque -> C:\Users\Zanthia.Family\AppData\Roaming\Masque -> [2010/05/18 14:46:51 | 000,000,000 | —D | M]
 OnlineArmor -> C:\Users\Zanthia.Family\AppData\Roaming\OnlineArmor -> [2010/05/05 00:31:53 | 000,000,000 | —D | M]
 SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2009/07/13 22:08:49 | 000,014,642 | —- | M] ()
 
[File - Purity Scan]
 
[Custom Scans]
< netsvcs >
< %SYSTEMDRIVE%\*.exe >
< MD5 Scans Start>
< %systemdrive%\AGP440.SYS  /md5 /s >
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0000\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0100\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0103\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0200\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0800\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0a03\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0b00\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0c01\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0c02\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0c04\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0c0b\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\_pnp0c0c\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\acpi_fixedbutton\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\acpi_thermalzone\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\pci_cc_0500\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\pci_cc_0601\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\pci_cc_0604\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\pci_ven_10de&dev_0752\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_mssmbios\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_rdp_kbd\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_rdp_mou\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_swenum\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_vdrvroot\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Users\Bryan\My Documents\My Drivers\System\root_volmgr\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Windows\SysWow64\DriverStore\FileRepository\machine.inf_amd64_neutral_9e6bb86c3b39a3e9\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
 AGP440.sys : MD5=608C14DBA7299D8CB6ED035A68A15799 -> C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7600.16385_none_1607dee2d861e021\AGP440.sys -> [2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation)
< %systemdrive%\ATAPI.SYS  /md5 /s >
 atapi.sys : MD5=02062C0B390B7729EDC9E69C680A6F3C -> C:\Users\Bryan\My Documents\My Drivers\hdc\internal_ide_channel\atapi.sys -> [2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation)
 atapi.sys : MD5=02062C0B390B7729EDC9E69C680A6F3C -> C:\Users\Bryan\My Documents\My Drivers\hdc\pci_cc_0101\atapi.sys -> [2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation)
 atapi.sys : MD5=02062C0B390B7729EDC9E69C680A6F3C -> C:\Windows\SysWow64\DriverStore\FileRepository\mshdc.inf_amd64_neutral_a69a58a4286f0b22\atapi.sys -> [2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation)
 atapi.sys : MD5=02062C0B390B7729EDC9E69C680A6F3C -> C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys -> [2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation)
< %systemdrive%\CNGAUDIT.DLL  /md5 /s >
 cngaudit.dll : MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -> C:\Windows\SysWOW64\cngaudit.dll -> [2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation)
 cngaudit.dll : MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -> C:\Windows\SysWOW64\cngaudit.dll -> [2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation)
 cngaudit.dll : MD5=50BA656134F78AF64E4DD3C8B6FEFD7E -> C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll -> [2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation)
 cngaudit.dll : MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 -> C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll -> [2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation)
< %systemdrive%\IASTORV.SYS  /md5 /s >
 iaStorV.sys : MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -> C:\Windows\SysWow64\DriverStore\FileRepository\iastorv.inf_amd64_neutral_18cccb83b34e1453\iaStorV.sys -> [2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation)
 iaStorV.sys : MD5=D83EFB6FD45DF9D55E9A1AFC63640D50 -> C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7600.16385_none_0b06441fa1790136\iaStorV.sys -> [2009/07/13 18:48:04 | 000,410,688 | —- | M] (Intel Corporation)
< %systemdrive%\NETLOGON.DLL  /md5 /s >
 netlogon.dll : MD5=956D030D375F207B22FB111E06EF9C35 -> C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_59aca8ea51aaeefe\netlogon.dll -> [2009/07/13 18:41:52 | 000,692,736 | —- | M] (Microsoft Corporation)
 netlogon.dll : MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -> C:\Windows\SysWOW64\netlogon.dll -> [2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation)
 netlogon.dll : MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -> C:\Windows\SysWOW64\netlogon.dll -> [2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation)
 netlogon.dll : MD5=EAA75D9000B71F10EEC04D2AE6C60E81 -> C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7600.16385_none_6401533c860bb0f9\netlogon.dll -> [2009/07/13 18:16:02 | 000,563,712 | —- | M] (Microsoft Corporation)
< %systemdrive%\NVRAID.SYS  /md5 /s >
 nvraid.sys : MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -> C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvraid.sys -> [2009/07/13 18:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation)
 nvraid.sys : MD5=3E38712941E9BB4DDBEE00AFFE3FED3D -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvraid.sys -> [2009/07/13 18:48:27 | 000,149,056 | —- | M] (NVIDIA Corporation)
< %systemdrive%\NVSTOR.SYS  /md5 /s >
 nvstor.sys : MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -> C:\Windows\SysWow64\DriverStore\FileRepository\nvraid.inf_amd64_neutral_5bde3fe2945bce9e\nvstor.sys -> [2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation)
 nvstor.sys : MD5=477DC4D6DEB99BE37084C9AC6D013DA1 -> C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7600.16385_none_95cfb4ced8afab0e\nvstor.sys -> [2009/07/13 18:45:45 | 000,167,488 | —- | M] (NVIDIA Corporation)
< %systemdrive%\SCECLI.DLL  /md5 /s >
 scecli.dll : MD5=26073302DAEA83CC5B944C546D6B47D2 -> C:\Windows\SysWOW64\scecli.dll -> [2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation)
 scecli.dll : MD5=26073302DAEA83CC5B944C546D6B47D2 -> C:\Windows\SysWOW64\scecli.dll -> [2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation)
 scecli.dll : MD5=26073302DAEA83CC5B944C546D6B47D2 -> C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9e577e55272d37b4\scecli.dll -> [2009/07/13 18:16:13 | 000,175,616 | —- | M] (Microsoft Corporation)
 scecli.dll : MD5=398712DDDAEFB85EDF61DF6A07B65C79 -> C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7600.16385_none_9402d402f2cc75b9\scecli.dll -> [2009/07/13 18:41:53 | 000,232,448 | —- | M] (Microsoft Corporation)
< MD5 Scans End>
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
 dxtmsft.dll : Unable to obtain MD5  -> C:\Windows\SysWOW64\dxtmsft.dll -> [2009/07/13 18:15:13 | 000,346,112 | —- | M] (Microsoft Corporation)
 dxtrans.dll : Unable to obtain MD5  -> C:\Windows\SysWOW64\dxtrans.dll -> [2009/07/13 18:15:13 | 000,215,552 | —- | M] (Microsoft Corporation)
 taskschd.dll : Unable to obtain MD5  -> C:\Windows\SysWOW64\taskschd.dll -> [2009/07/13 18:16:15 | 000,496,128 | —- | M] (Microsoft Corporation)
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
 mbamswissarmy.sys -> C:\Windows\SysWOW64\drivers\mbamswissarmy.sys -> [2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation)
 OADriver.sys -> C:\Windows\SysWOW64\drivers\OADriver.sys -> [2010/04/20 04:13:26 | 000,055,160 | —- | M] ()
 OAmon.sys -> C:\Windows\SysWOW64\drivers\OAmon.sys -> [2010/04/20 04:13:24 | 000,038,776 | —- | M] (Tall Emu)
 
CREATERESTOREPOINT
Error creating restore point.
< End of report >
Also I'm very curious as to what is wrong with the hosts file.
Hi

what product are you using for your antivirus? You seem to have a number of different ones. Uninstall all but ONE

Please do the following


Start OTS
Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.


[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< HOSTS File > ([2010/05/04 14:31:04 | 000,607,013 | —- | M] - 16089 lines) -> C:\Windows\SysNative\Drivers\etc\hosts
YN -> First 25 entries… ->
YN -> Reset Hosts ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {5C255C8A-E604-49b4-9D64-90988571CECB} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< 64bit-Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "Locked" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{05b36f1a-56d5-11df-ad58-00262d289fc4} ->
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell ->
YN -> \{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\\"" -> [AutoRun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command ->
YN -> \{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command\\"" -> G:\LaunchU3.exe [G:\LaunchU3.exe -a]
[Files/Folders - Created Within 30 Days]
NY -> 61bed -> C:\ProgramData\61bed
NY -> MSZNHANLRRE -> C:\ProgramData\MSZNHANLRRE
NY -> f5f4dad -> C:\f5f4dad
[Files/Folders - Modified Within 30 Days]
NY -> hosts.zip.zip -> C:\Windows\SysNative\drivers\etc\hosts.zip.zip
NY -> HOSTS -> C:\Windows\SysNative\drivers\etc\hosts.zip\HOSTS
NY -> HOSTS -> C:\Windows\SysNative\drivers\etc\HOSTS
[Purity]
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.
I removed the Online armor ++ because I'm not sure if the beta was causing problems but I suspect that some of them are linked to it. although I have more than one anti-virus program I use all but Windows security as on demand scanners. Here is the results of the fixes you asked for. All Processes Killed [Registry - Safe List] HOSTS file reset successfully! Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\Locked deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{05b36f1a-56d5-11df-ad58-00262d289fc4}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{05b36f1a-56d5-11df-ad58-00262d289fc4}\shell\AutoRun\command not found. [Files/Folders - Created Within 30 Days] C:\ProgramData\61bed folder moved successfully. C:\ProgramData\MSZNHANLRRE folder moved successfully. C:\f5f4dad\Quarantine Items folder moved successfully. C:\f5f4dad\MSESys folder moved successfully. C:\f5f4dad folder moved successfully. [Files/Folders - Modified Within 30 Days] C:\Windows\SysNative\drivers\etc\hosts.zip.zip moved successfully. C:\Windows\SysNative\drivers\etc\hosts.zip\HOSTS moved successfully. C:\Windows\SysNative\drivers\etc\HOSTS moved successfully. [Purity] Purity scan complete. [Empty Temp Folders] User: Administrator User: All Users User: Bryan ->Temp folder emptied: 97673 bytes ->Temporary Internet Files folder emptied: 41307414 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 456 bytes User: Bryan.JETS-F7DC2E7385 User: Daniel ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Daniel.Family ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Zanthia ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Zanthia.Family ->Temp folder emptied: 27222 bytes ->Temporary Internet Files folder emptied: 5215418 bytes ->Java cache emptied: 3542733 bytes ->Flash cache emptied: 456 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 14144 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 636559 bytes Total Files Cleaned = 49.00 mb < End of fix log > OTS by OldTimer - Version 3.1.31.0 fix logfile created on 05202010_111026 Files\Folders moved on Reboot… C:\Users\Bryan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Bryan\AppData\Local\Temp\~DF078AB7642B9A6D6B.TMP not found! File\Folder C:\Users\Bryan\AppData\Local\Temp\~DF08EB175761E0D47D.TMP not found! File\Folder C:\Users\Bryan\AppData\Local\Temp\~DF81C5446FF70DB68D.TMP not found! File\Folder C:\Users\Bryan\AppData\Local\Temp\~DFF42C66AF872C4E01.TMP not found! C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X35OBPZG\iframe[1].htm moved successfully. C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0485AE66\New_system_infected_need_help_t112069[1].htm moved successfully. C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0485AE66\signin[1].htm moved successfully. C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully. Registry entries deleted on Reboot…
How is the computer running now?

Any outstanding issues?

Please do the following:

  • Open your Malwarebytes' Anti-Malware program and select the update tab, select update now
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.


NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Back again, Ran both Mbam and Kaspersky. Neither showed anyting detected but the Kaspersky did pop up a notice saying that this program is only for 32 bit systems. The scan took over an hour (which is typical) but found nothing at all and also didn't create a log file. Here is the result of the Mbam scan. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4121 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 5/20/2010 11:31:11 AM mbam-log-2010-05-20 (11-31-11).txt Scan type: Quick scan Objects scanned: 152389 Time elapsed: 3 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Did the program you had me run reset the hosts file back to the default? Because I went to the folder and it still shows the hosts.zip file and the mvps file. Is this correct? I uninstalled the OA++ 64x beta completely. i'm still not sure where the problems came from or if everything is okay. I'm hoping that they are and have not had any problems in 2 days now. I wish I was as familiar with the Windows7 64x operating system as I am with XP 32x, but I'm learning. anything you can offer to further my knowledge will be appreciated. thank you once again Catbyte

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI