This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows cannot find 'C:\Program'.

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys and gals, I am completely new to this forum and am not much of a computer guru. But a few weeks ago, this message has been popping up: "Windows cannot find C:\Program'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search. Also, since that problem has been occurring, whenever I use Chrome, an error message will pop up saying: "The application failed to initialize properly (0x0000022). Click on Ok to terminate the application." Now, I have tried going to properties of chrome and doing –no-sandbox, that works occasionally but I have to redo it serveral times in order for it to work. Also, I have tried to go on local disk and fix hard drive errors as well but that did not work. Please help me :( Thanks, Alex/Pokerman2280
Hello there, Alex

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
This is the result for the OTL.TXT


OTL logfile created on: 6/16/2010 7:47:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 398.00 Mb Available Physical Memory | 39.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 11.23 Gb Free Space | 15.07% Space Free | Partition Type: NTFS
Drive D: | 480.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-125676138
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL (1).exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL (1).exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\comssdtc.dll ()
MOD - C:\WINDOWS\system32\cabinet.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
MOD - C:\WINDOWS\system32\hccutils.dll (Intel Corporation)
MOD - C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll ()


========== Win32 Services (SafeList) ==========

SRV - (NMIndexingService) – File not found
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (WLANKEEPER) Intel® – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel Corporation)
SRV - (S24EventMonitor) Intel® – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTSERIAL) – C:\WINDOWS\system32\drivers\btserial.sys (Broadcom Corporation.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (btwmodem) – C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.)
DRV - (BTWUSB) – C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar;=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar;=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?wl=true
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn.com/{SUB_RFC1766}/src…autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:8080

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:3.3.0.3971
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.9
FF - prefs.js..network.proxy.ftp: "127.0.0.1"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.gopher: "5.6.7"
FF - prefs.js..network.proxy.gopher_port: 8080
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 1080
FF - prefs.js..network.proxy.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.ssl_port: 8080

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/26 22:27:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2010/05/20 20:00:21 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/27 21:21:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/21 00:13:10 | 000,000,000 | —D | M]

[2009/09/10 20:39:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2009/09/10 20:39:48 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010/06/04 16:15:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nr7ooiuy.default\extensions
[2009/09/26 22:45:20 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nr7ooiuy.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/08 23:48:55 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/07 01:16:25 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/10/24 16:12:28 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2010/05/20 20:01:08 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/04/07 01:16:00 | 000,023,512 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/04/07 01:16:00 | 000,137,176 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2007/04/10 17:21:08 | 000,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
[2010/05/20 20:00:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/07 01:16:11 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 000,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
[2009/02/27 13:13:42 | 000,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/09/26 14:03:39 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2010/04/07 01:16:14 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/04/07 01:16:14 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/04/07 01:16:14 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/04/07 01:16:14 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/04/07 01:16:14 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/04/07 01:16:14 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/04/07 01:16:14 | 000,000,792 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml

O1 HOSTS File: ([2010/02/03 12:39:38 | 000,329,883 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11300 more lines…
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Address;) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Links;) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Google Update] C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Skype] C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKLM..\RunOnce: [NSSInstallation] C:\Program Files\DivX\Symantec\scstubinstaller.exe File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 255
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1252630697578 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed]
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/09/08 15:59:21 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2003/05/18 14:54:20 | 000,061,440 | R— | M] () - D:\autoplay.exe – [ CDFS ]
O32 - AutoRun File - [2003/02/12 03:01:48 | 000,000,050 | R— | M] () - D:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{2f598aba-0583-11df-b230-0016cffbee5e}\Shell - "" = AutoRun
O33 - MountPoints2\{2f598aba-0583-11df-b230-0016cffbee5e}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{2f598aba-0583-11df-b230-0016cffbee5e}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{83f52205-aa35-11de-b1d8-0016cffbee5e}\Shell - "" = Autorun
O33 - MountPoints2\{83f52205-aa35-11de-b1d8-0016cffbee5e}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{83f52205-aa35-11de-b1d8-0016cffbee5e}\Shell\AutoRun\command - "" = C:\WINDOWS\System32\shell32.dll – [2008/06/17 15:02:19 | 008,461,312 | —- | M] (Microsoft Corporation)
O33 - MountPoints2\{83f52205-aa35-11de-b1d8-0016cffbee5e}\Shell\Open\command - "" = E:\resycled\boot.com – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O36 - AppCertDlls: lpqcess - (C:\WINDOWS\system32\comssdtc.dll) - C:\WINDOWS\system32\comssdtc.dll ()
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/13 03:04:53 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/06/08 17:52:53 | 002,120,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxsfs.dll
[2010/06/08 17:52:53 | 000,698,864 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\px.dll
[2010/06/08 17:52:53 | 000,567,792 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxdrv.dll
[2010/06/08 17:52:53 | 000,440,816 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxwave.dll
[2010/06/08 17:52:53 | 000,219,632 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxmas.dll
[2010/06/08 17:52:53 | 000,133,616 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxafs.dll
[2010/06/08 17:52:53 | 000,126,448 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsi64.exe
[2010/06/08 17:52:53 | 000,123,888 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpyi64.exe
[2010/06/08 17:52:53 | 000,100,848 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\vxblock.dll
[2010/06/08 17:52:53 | 000,072,176 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxhpinst.exe
[2010/06/08 17:52:53 | 000,068,592 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxinsa64.exe
[2010/06/08 17:52:53 | 000,068,080 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\pxcpya64.exe
[2010/06/08 17:52:53 | 000,009,200 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys
[2010/06/08 17:52:53 | 000,009,072 | —- | C] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys
[2010/06/08 17:52:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2010/06/08 17:45:37 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2010/06/06 04:17:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/06/05 15:38:57 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_26.dll
[2010/06/05 15:38:53 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_25.dll
[2010/06/05 15:37:41 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wstdecod.dll
[2010/06/05 15:37:40 | 000,052,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\msdv.sys
[2010/06/05 15:37:40 | 000,052,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msdv.sys
[2010/06/05 15:37:40 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2010/06/05 15:37:40 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\bdaplgin.ax
[2010/06/05 15:37:40 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\mpe.sys
[2010/06/05 15:37:40 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2010/06/05 15:37:40 | 000,011,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\bdasup.sys
[2010/06/05 15:37:40 | 000,011,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2010/06/05 15:37:39 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksolay.ax
[2010/06/05 15:37:36 | 000,667,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dinput8.dll
[2010/06/05 15:37:36 | 000,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmime.dll
[2010/06/05 15:37:36 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmusic.dll
[2010/06/05 15:37:36 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmsynth.dll
[2010/06/05 15:37:36 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmstyle.dll
[2010/06/05 15:37:36 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmscript.dll
[2010/06/05 15:37:36 | 000,058,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmcompos.dll
[2010/06/05 15:37:36 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmloader.dll
[2010/06/05 15:37:36 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dmband.dll
[2010/06/05 15:37:36 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dswave.dll
[2010/06/05 15:37:35 | 001,201,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\d3d8.dll
[2010/06/05 15:37:35 | 001,189,888 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dx8vb.dll
[2010/06/05 15:37:35 | 000,974,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxdiag.exe
[2010/06/05 15:37:35 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnet.dll
[2010/06/05 15:37:35 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dsdmoprp.dll
[2010/06/05 15:37:35 | 000,381,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpvoice.dll
[2010/06/05 15:37:35 | 000,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\joy.cpl
[2010/06/05 15:37:35 | 000,186,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dsdmo.dll
[2010/06/05 15:37:35 | 000,112,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpvvox.dll
[2010/06/05 15:37:35 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpvsetup.exe
[2010/06/05 15:37:35 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnhupnp.dll
[2010/06/05 15:37:35 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dxdllreg.exe
[2010/06/05 15:37:35 | 000,032,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnhpast.dll
[2010/06/05 15:37:35 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pid.dll
[2010/06/05 15:37:35 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpvacm.dll
[2010/06/05 15:37:35 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnsvr.exe
[2010/06/05 15:37:35 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\d3d8thk.dll
[2010/06/05 15:37:35 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnlobby.dll
[2010/06/05 15:37:35 | 000,003,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpnaddr.dll
[2010/06/05 15:37:34 | 001,294,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dsound3d.dll
[2010/06/05 15:37:34 | 000,797,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\d3dim700.dll
[2010/06/05 15:37:34 | 000,648,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dinput.dll
[2010/06/05 15:37:34 | 000,602,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dx7vb.dll
[2010/06/05 15:37:34 | 000,381,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dsound.dll
[2010/06/05 15:37:34 | 000,292,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddraw.dll
[2010/06/05 15:37:34 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dplayx.dll
[2010/06/05 15:37:34 | 000,079,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpwsockx.dll
[2010/06/05 15:37:34 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dpmodemx.dll
[2010/06/05 15:37:34 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dplaysvr.exe
[2010/06/05 15:37:34 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ddrawex.dll
[2010/06/05 13:15:28 | 000,000,000 | —D | C] – C:\Program Files\DAEMON Tools Lite
[2010/06/05 13:14:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite
[2010/06/05 13:13:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010/06/01 23:15:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\LolClient
[2010/06/01 22:59:12 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_2.dll
[2010/06/01 22:59:12 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_1.dll
[2010/06/01 22:59:03 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_39.dll
[2010/06/01 22:59:03 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_39.dll
[2010/06/01 22:58:41 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_39.dll
[2010/06/01 22:58:13 | 000,000,000 | —D | C] – C:\WINDOWS\Logs
[2010/06/01 22:57:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/06/01 22:45:37 | 000,000,000 | —D | C] – C:\Riot Games
[2010/06/01 22:36:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\League Of Legends
[2010/06/01 22:36:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\PMB Files
[2010/06/01 22:36:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/06/01 22:36:21 | 000,000,000 | —D | C] – C:\Program Files\Pando Networks
[2010/06/01 10:03:20 | 000,000,000 | —D | C] – C:\Program Files\GRETECH
[2010/05/30 16:18:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Desktop\MusicYoutube
[2010/05/23 23:15:59 | 000,139,264 | —- | C] (Blizzard Entertainment) – C:\WINDOWS\War3Unin.exe
[2010/05/23 23:10:52 | 000,000,000 | —D | C] – C:\Program Files\Warcraft III
[2010/05/20 20:00:57 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/20 20:00:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/20 20:00:57 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/18 01:43:29 | 000,000,000 | —D | C] – C:\Program Files\RegCure
[2008/08/25 19:40:00 | 000,122,880 | —- | C] ( ) – C:\WINDOWS\System32\sbcrreag.dll
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/16 19:32:13 | 000,000,069 | —- | M] () – C:\Documents and Settings\Owner\jagex_runescape_preferences.dat
[2010/06/16 19:32:12 | 000,000,041 | —- | M] () – C:\Documents and Settings\Owner\jagex__preferences3.dat
[2010/06/16 19:32:11 | 000,000,087 | —- | M] () – C:\Documents and Settings\Owner\jagex_runescape_preferences2.dat
[2010/06/16 19:27:00 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-413027322-725345543-1003UA.job
[2010/06/16 00:27:01 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-796845957-413027322-725345543-1003Core.job
[2010/06/13 23:19:58 | 000,200,506 | —- | M] () – C:\Documents and Settings\Owner\My Documents\ts3_clientui-win32-11239-2010-06-13 23_19_56.765125.dmp
[2010/06/13 03:04:53 | 000,001,984 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/06/12 23:42:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/12 23:41:58 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/12 23:41:57 | 1063,714,816 | -HS- | M] () – C:\hiberfil.sys
[2010/06/12 17:00:39 | 009,437,184 | -H– | M] () – C:\Documents and Settings\Owner\NTUSER.DAT
[2010/06/12 17:00:39 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Owner\ntuser.ini
[2010/06/12 17:00:01 | 001,581,964 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/06/11 11:13:48 | 000,000,679 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/11 11:13:48 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/06/11 11:13:48 | 000,000,209 | -HS- | M] () – C:\boot.ini
[2010/06/11 09:32:33 | 001,991,264 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 03:23:44 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/06/11 03:15:31 | 000,506,244 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/11 03:15:31 | 000,444,596 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/06/11 03:15:31 | 000,072,306 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/06/09 20:49:25 | 000,302,472 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/09 15:27:59 | 000,002,310 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk
[2010/06/09 03:36:08 | 000,208,618 | —- | M] () – C:\Documents and Settings\Owner\Desktop\supremecy banner copy.png
[2010/06/09 03:35:51 | 002,236,530 | —- | M] () – C:\Documents and Settings\Owner\Desktop\supremecy banner.psd
[2010/06/08 17:54:04 | 000,001,447 | —- | M] () – C:\Documents and Settings\Owner\Desktop\DivX Movies.lnk
[2010/06/08 17:53:06 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/06/08 17:52:45 | 000,000,817 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_3872885758
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_3783381249
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_2932528544
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_268313212
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_2370710833
[2010/06/05 15:39:04 | 000,001,798 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Age of Empires III.lnk
[2010/06/05 13:16:02 | 000,001,613 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2010/06/05 13:15:59 | 000,691,696 | —- | M] () – C:\WINDOWS\System32\drivers\sptd.sys
[2010/06/05 09:57:40 | 000,101,376 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/04 15:54:37 | 000,605,861 | —- | M] () – C:\Documents and Settings\Owner\Desktop\26167_ystrahovski_mhoct0802t_122_131lo.jpg
[2010/06/03 10:21:10 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/01 22:59:21 | 000,001,614 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Play League of Legends.lnk
[2010/06/01 10:03:39 | 000,000,762 | —- | M] () – C:\Documents and Settings\All Users\Desktop\GOM Player.lnk
[2010/05/26 18:24:08 | 000,204,183 | —- | M] () – C:\Documents and Settings\Owner\My Documents\ts3_clientui-win32-10723-2010-05-26 18_24_06.906250.dmp
[2010/05/23 23:38:33 | 000,082,713 | —- | M] () – C:\WINDOWS\War3Unin.dat
[2010/05/23 23:34:33 | 000,001,619 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Frozen Throne.lnk
[2010/05/23 23:34:18 | 000,139,264 | —- | M] (Blizzard Entertainment) – C:\WINDOWS\War3Unin.exe
[2010/05/23 23:34:18 | 000,002,829 | —- | M] () – C:\WINDOWS\War3Unin.pif
[2010/05/21 11:48:19 | 000,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Divine Forces.doc
[2010/05/21 10:11:39 | 000,113,082 | —- | M] () – C:\Documents and Settings\Owner\Desktop\photo.jpg
[2010/05/20 20:00:16 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/20 20:00:16 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/20 20:00:16 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/20 20:00:16 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/20 20:00:16 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/20 19:31:56 | 000,166,562 | —- | M] () – C:\Documents and Settings\Owner\Desktop\###### u ross.JPG
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/13 23:19:56 | 000,200,506 | —- | C] () – C:\Documents and Settings\Owner\My Documents\ts3_clientui-win32-11239-2010-06-13 23_19_56.765125.dmp
[2010/06/13 03:04:53 | 000,001,984 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HiJackThis.lnk
[2010/06/09 03:36:06 | 000,208,618 | —- | C] () – C:\Documents and Settings\Owner\Desktop\supremecy banner copy.png
[2010/06/09 03:35:49 | 002,236,530 | —- | C] () – C:\Documents and Settings\Owner\Desktop\supremecy banner.psd
[2010/06/09 03:25:00 | 000,205,772 | —- | C] () – C:\Documents and Settings\Owner\Desktop\DeutscheZierschrift.ttf
[2010/06/08 17:53:06 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/06/08 17:52:45 | 000,000,817 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Converter.lnk
[2010/06/08 02:54:38 | 000,000,000 | —- | C] () – C:\icon_3872885758
[2010/06/08 02:54:38 | 000,000,000 | —- | C] () – C:\icon_3783381249
[2010/06/08 02:54:38 | 000,000,000 | —- | C] () – C:\icon_2932528544
[2010/06/08 02:54:38 | 000,000,000 | —- | C] () – C:\icon_268313212
[2010/06/08 02:54:38 | 000,000,000 | —- | C] () – C:\icon_2370710833
[2010/06/05 15:39:04 | 000,001,798 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Age of Empires III.lnk
[2010/06/05 15:37:38 | 001,798,144 | —- | C] () – C:\WINDOWS\System32\dllcache\qedit.dll
[2010/06/05 15:37:38 | 000,733,184 | —- | C] () – C:\WINDOWS\System32\dllcache\qedwipes.dll
[2010/06/05 15:37:38 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\dllcache\msdmo.dll
[2010/06/05 15:37:37 | 000,470,528 | —- | C] () – C:\WINDOWS\System32\dllcache\qdvd.dll
[2010/06/05 15:37:37 | 000,316,928 | —- | C] () – C:\WINDOWS\System32\dllcache\qdv.dll
[2010/06/05 15:37:37 | 000,257,024 | —- | C] () – C:\WINDOWS\System32\dllcache\qcap.dll
[2010/06/05 15:37:37 | 000,132,608 | —- | C] () – C:\WINDOWS\System32\dllcache\devenum.dll
[2010/06/05 15:37:37 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\dllcache\amstream.dll
[2010/06/05 15:37:37 | 000,034,304 | —- | C] () – C:\WINDOWS\System32\dllcache\mciqtz32.dll
[2010/06/05 13:16:01 | 000,001,613 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DAEMON Tools Lite.lnk
[2010/06/05 13:15:58 | 000,691,696 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2010/06/04 15:54:37 | 000,605,861 | —- | C] () – C:\Documents and Settings\Owner\Desktop\26167_ystrahovski_mhoct0802t_122_131lo.jpg
[2010/06/03 11:53:07 | 000,639,595 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Doyle Brunson's Super System.pdf
[2010/06/01 22:59:21 | 000,001,614 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Play League of Legends.lnk
[2010/06/01 10:03:38 | 000,000,762 | —- | C] () – C:\Documents and Settings\All Users\Desktop\GOM Player.lnk
[2010/05/26 18:24:06 | 000,204,183 | —- | C] () – C:\Documents and Settings\Owner\My Documents\ts3_clientui-win32-10723-2010-05-26 18_24_06.906250.dmp
[2010/05/23 23:34:33 | 000,001,619 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Frozen Throne.lnk
[2010/05/23 23:16:01 | 000,082,713 | —- | C] () – C:\WINDOWS\War3Unin.dat
[2010/05/23 23:16:00 | 000,002,829 | —- | C] () – C:\WINDOWS\War3Unin.pif
[2010/05/22 12:19:32 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/05/21 10:08:22 | 000,113,082 | —- | C] () – C:\Documents and Settings\Owner\Desktop\photo.jpg
[2010/05/20 19:31:56 | 000,166,562 | —- | C] () – C:\Documents and Settings\Owner\Desktop\###### u ross.JPG
[2010/04/29 01:08:38 | 000,032,768 | -H– | C] () – C:\WINDOWS\System32\comssdtc.dll
[2009/11/14 02:52:51 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/10/08 19:50:48 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2009/09/26 00:37:20 | 000,000,213 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/09/25 23:34:55 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/09/08 18:10:15 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2009/09/08 18:05:23 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4814.dll
[2009/09/08 17:42:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/24 18:16:22 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\btprn2k.dll
[2005/08/05 14:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/02/17 12:41:32 | 000,000,603 | —- | C] () – C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 12:41:30 | 000,000,593 | —- | C] () – C:\WINDOWS\System32\btcss.dll.manifest
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 13:56:00 | 001,802,240 | —- | C] () – C:\WINDOWS\System32\lcppn21.dll
[2001/07/07 03:00:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/06/05 13:15:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/09/08 16:25:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2010/03/22 01:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software
[2010/03/22 01:05:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2010/06/01 22:36:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/12/08 17:08:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/09/11 15:21:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SwiftKit
[2010/04/24 22:01:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2009/09/26 14:07:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/06/05 15:05:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DAEMON Tools Lite
[2010/04/04 12:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GameRanger
[2010/06/01 23:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\LolClient
[2009/09/11 22:03:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\ProxyCap
[2010/05/26 20:40:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TS3Client
[2010/06/05 13:16:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2010/05/07 13:44:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Western Digital

========== Purity Check ==========



========== Custom Scans ==========


< etsvcs >

< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/10 06:00:00 | 016,971,599 | —- | M] () .cab file – C:\Data Backup\data\i386\sp2.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/09/26 15:52:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/09/26 15:52:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 00:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\Data Backup\data\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2004/08/10 06:00:00 | 016,971,599 | —- | M] () .cab file – C:\Data Backup\data\i386\sp2.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/09/26 15:52:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/09/26 15:52:19 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 23:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\Data Backup\data\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/10 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 06:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\Data Backup\data\i386\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: IASTOR.SYS >
[2006/05/11 12:30:52 | 000,247,808 | —- | M] (Intel Corporation) MD5=294110966CEDD127629C5BE48367C8CF – C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 06:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\Data Backup\data\i386\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: NVATABUS.SYS >
[2006/03/16 20:51:32 | 000,099,840 | —- | M] (NVIDIA Corporation) MD5=B7FB72492B753930EC70A0F49D04F12F – C:\WINDOWS\dell\nvraid\NvAtaBus.sys

< MD5 for: SCECLI.DLL >
[2004/08/10 06:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\Data Backup\data\i386\scecli.dll
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< MD5 for: SYMMPI.SYS >
[2005/11/17 14:58:16 | 000,092,672 | —- | M] (LSI Logic) MD5=1FD5249D5103125D2DA63F68D7BE1D35 – C:\WINDOWS\dell\symmpi\symmpi.sys

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 20:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2010/06/05 13:15:59 | 000,691,696 | —- | M] () Unable to obtain MD5 – C:\WINDOWS\system32\drivers\sptd.sys

< %systemroot%\System32\config\*.sav >
[2009/09/08 11:11:53 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/09/08 11:11:53 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/09/08 11:11:53 | 000,892,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/27 14:40:40 | 000,009,072 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\cdr4_xp.sys
[2010/04/27 14:40:40 | 000,009,200 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\cdralw2k.sys
[2010/04/27 14:40:40 | 000,045,648 | —- | M] (Sonic Solutions) – C:\WINDOWS\system32\drivers\PxHelp20.sys
[2010/06/05 13:15:59 | 000,691,696 | —- | M] () – C:\WINDOWS\system32\drivers\sptd.sys
[2010/03/26 15:07:02 | 000,032,768 | —- | M] (AnchorFree Inc) – C:\WINDOWS\system32\drivers\taphss.sys
< End of report >
This is the result for the Extras.TXT


OTL Extras logfile created on: 6/16/2010 7:47:49 PM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,014.00 Mb Total Physical Memory | 398.00 Mb Available Physical Memory | 39.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 68.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 11.23 Gb Free Space | 15.07% Space Free | Partition Type: NTFS
Drive D: | 480.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-125676138
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"56548:TCP" = 56548:TCP:*:Enabled:Pando Media Booster
"56548:UDP" = 56548:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"56548:TCP" = 56548:TCP:*:Enabled:Pando Media Booster
"56548:UDP" = 56548:UDP:*:Enabled:Pando Media Booster
"8378:TCP" = 8378:TCP:*:Enabled:League of Legends Launcher
"8378:UDP" = 8378:UDP:*:Enabled:League of Legends Launcher

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:CyberLink PowerDVD – (CyberLink Corp.)
"D:\CDS\Nero\Installation\Setupx.exe" = D:\CDS\Nero\Installation\Setupx.exe:*:Enabled:Nero ProductSetup – File not found
"C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe" = C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe:*:Enabled:Bradford Persistent Agent – File not found
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe" = C:\Program Files\Java\jre1.6.0_07\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – (Microsoft Corporation)
"C:\Documents and Settings\Owner\Desktop\Counter Strike\hl2.exe" = C:\Documents and Settings\Owner\Desktop\Counter Strike\hl2.exe:*:Enabled:hl2 – File not found
"C:\Data Backup\Program Files\Your Freedom\freedom.exe" = C:\Data Backup\Program Files\Your Freedom\freedom.exe:*:Enabled:freedom – ()
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 – (Microsoft Corporation)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App – (Microsoft Corporation)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – (Skype Technologies)
"C:\Program Files\Pocket Tanks Deluxe\pockettanks.exe" = C:\Program Files\Pocket Tanks Deluxe\pockettanks.exe:*:Enabled:Pocket Tanks – File not found
"C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe" = C:\WINDOWS\pchealth\helpctr\binaries\helpctr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice – (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Your Freedom\freedom.exe" = C:\Program Files\Your Freedom\freedom.exe:*:Enabled:Your Freedom client software – File not found
"F:\Data Backup\Program Files\Your Freedom\freedom.exe" = F:\Data Backup\Program Files\Your Freedom\freedom.exe:*:Enabled:freedom – File not found
"C:\Documents and Settings\Owner\Application Data\GameRanger\GameRanger\GameRanger.exe" = C:\Documents and Settings\Owner\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger – (GameRanger Technologies)
"C:\Program Files\Microsoft Games\Age Of Empires II Gold Edition\Age2_x1\age2_x1.exe" = C:\Program Files\Microsoft Games\Age Of Empires II Gold Edition\Age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion – (Microsoft Corporation)
"C:\Program Files\Microsoft Games\Age Of Empires II Gold Edition\empires2.exe" = C:\Program Files\Microsoft Games\Age Of Empires II Gold Edition\empires2.exe:*:Enabled:Age of Empires II – (Microsoft Corporation)
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\Warcraft III\Warcraft III.exe" = C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III – (Blizzard Entertainment)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Riot Games\League of Legends\air\LolClient.exe" = C:\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby – ()
"C:\Riot Games\League of Legends\game\League of Legends.exe" = C:\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client – ()
"C:\Program Files\Microsoft Games\Age of Empires III\age3.exe" = C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:*:Enabled:Age of Empires 3 – (Ensemble Studios)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype – (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0046FA01-C5B9-4985-BACB-398DC480FC05}" = Adobe Photoshop CS3
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{32A3A4F4-B792-11D6-A78A-00B0D0160070}" = Java™ SE Development Kit 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = WIDCOMM Bluetooth Software
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57B2281D-A34A-4a48-8C68-169B8873659D}" = c4100_Help
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{829CD169-E692-48E8-9BDE-A3E8D8B65538}" = mSCfg
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{952C0A72-C051-4D35-BD9E-9A3239A2A0C0}_is1" = Age Of Empires 2 : Gold Edition
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}" = HP Software Update
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C871525F-7116-4d26-BA6D-215F59B6F88B}" = C4100
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD49361E-3FE6-457E-90A1-9C59E29B5D02}" = Java DB 10.3.1.4
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D1BB4446-AE9C-4256-9A7F-4D46604D2462}" = Adobe Setup
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}" = iTunes
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E81667C6-2856-46D6-ABEA-6A2F42166779}" = mCore
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F94CFF0E-600E-4E1C-A0A5-5053C1816A9F}" = League of Legends
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"4569969E1360D2854474C661EF9B4D54F143EB16" = Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_2ac78060bc5856b0c1cf873bb919b58" = Adobe Photoshop CS3
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"DivX Setup.divx.com" = DivX Setup
"ESPNMotion" = ESPNMotion
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.2
"GOM Player" = GOM Player
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"InstallShield_{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}" = Age of Empires III
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"PokerStars" = PokerStars
"ProInst" = Intel® PROSet/Wireless Software
"ShortKeys Lite" = ShortKeys Lite
"SocksCap V2" = SocksCap V2
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"uTorrent" = µTorrent
"Virtual DJ - Atomix Productions" = Virtual DJ - Atomix Productions
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Your Freedom" = Your Freedom

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"309a46b1dc89b774" = Dell Driver Download Manager
"GameRanger" = GameRanger
"Google Chrome" = Google Chrome
"SwiftKit" = SwiftKit
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/8/2010 11:55:47 PM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application photoshop.exe, version 10.0.0.0, faulting module
photoshop.exe, version 10.0.0.0, fault address 0x00764400.

Error - 6/8/2010 11:55:59 PM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application photoshop.exe, version 10.0.0.0, faulting module
photoshop.exe, version 10.0.0.0, fault address 0x00764400.

Error - 6/9/2010 1:07:51 AM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application photoshop.exe, version 10.0.0.0, faulting module
photoshop.exe, version 10.0.0.0, fault address 0x00764400.

Error - 6/11/2010 6:03:21 PM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application gameranger.exe, version 1.0.0.0, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0001072f.

Error - 6/12/2010 11:54:40 PM | Computer Name = OWNER-125676138 | Source = Windows Live Messenger | ID = 1000
Description =

Error - 6/13/2010 3:04:16 AM | Computer Name = OWNER-125676138 | Source = MsiInstaller | ID = 10005
Description = Product: HiJackThis – The installer has encountered an unexpected
error installing this package. This may indicate a problem with this package. The
error code is 2884. The arguments are: ErrorDlg, ,

Error - 6/13/2010 3:04:20 AM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application msiexec.exe, version 3.1.4001.5512, faulting
module unknown, version 0.0.0.0, fault address 0x0000000f.

Error - 6/13/2010 4:23:23 PM | Computer Name = OWNER-125676138 | Source = Windows Live Messenger | ID = 1000
Description =

Error - 6/13/2010 9:58:41 PM | Computer Name = OWNER-125676138 | Source = Application Hang | ID = 1002
Description = Hanging application chrome.exe, version 0.0.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 6/13/2010 11:20:03 PM | Computer Name = OWNER-125676138 | Source = Application Error | ID = 1000
Description = Faulting application ts3client_win32.exe, version 1.0.0.0, faulting
module unknown, version 0.0.0.0, fault address 0x00000000.


< End of report >
Dear Conspire, There could be a problem. I tried to download and use the scanner (part 2). I followed your directions and the first time I did it my computer just like stopped working, I couldn't control alt delete. Then the second time i did it there was a blue screen. I'm going to try it a third time and let you know what happens. Alex
Hi,

Please run the tool below and then try to run GMER again if possible.

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

===================================================

If that fails, then I need you to reboot your computer into Safe Mode and run GMER again, but this time you only have to check "Sections" and "C:/" drive and leave out all other boxes unchecked.

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
===================================================

Can you tell me what are these files for?

[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_3872885758
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_3783381249
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_2932528544
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_268313212
[2010/06/08 02:54:38 | 000,000,000 | —- | M] () – C:\icon_2370710833

===================================================


On your next reply please post :
GMER log
Do you use proxy?
Query on the files

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI