This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Email account was hacked

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Sir/Mdm,

My email account has been hacked and stolen. The hackers had stole my account and use it to register on some gaming site. I came to know about it when i keep recieving alot of mails from the site itself. I suspect that my pc might have been infected by malware or maybe some sort of keyloggers. Can you kindly help me take a look at my pc? Thank you.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:35:00 PM, on 8/26/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Razer\Diamondback 3G\razerhid.exe
C:\Program Files\Razer\Lycosa\razerhid.exe
C:\Program Files\Folder Guard Pro\FGKey.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Razer\Diamondback 3G\razerofa.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PPVADownloader - {A986E409-30CC-4185-89BB-AB212C104524} - C:\Program Files\PPLive\PPVA\DownloaderManager.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Six Engine] "C:\Program Files\ASUS\Six Engine\SixEngine.exe" -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [DT PHL] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -PHL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Diamondback] C:\Program Files\Razer\Diamondback 3G\razerhid.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Lycosa] "C:\Program Files\Razer\Lycosa\razerhid.exe"
O4 - HKLM\..\Run: [FG_Monitor] C:\Program Files\Folder Guard Pro\FGKey.exe /Start
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1241279085483
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1241285791015
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.yycast.com/vjocx-en-black.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} (PPLive Lite Class) - http://dl.pplive.com/PluginSetup.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 11184 bytes
Hi D3stinY,

:welcome:

My name is NightWizard and I will be your helper. :)

While I go through your log, I would very much appreciate it if you read the following.

  • I aim provide you with the best instructions possible to resolve your issue. However, I ask that you understand that malware is complex and the process usually takes a few attempts before successfully cleaning everything out. In severe cases cleaning may not be possible and a reformat may be our only option.
  • If you are unresponsive to this thread within three days, the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
  • Please do not make any new threads about this issue here or any other malware removal forum; it wastes other helpers' time and it can be dangerous for your PC.
  • If you don't understand a set of instructions or you are having trouble performing some of the fix, don't panic! Let me know and I will be happy to help in any way I can.
  • Please remember that the absence of symptoms does not mean you are clean. I request that you stick to this log until the very end - I will inform you when your system is clean.
  • Please do not use any tools other than the ones I instruct you to use. Some of the tools available can be dangerous if used incorrectly.

Please be advised that I am still in training at this forum. My posts will be checked by experts before I post in this thread. This is to ensure you get the best possible help available. This may cause delay however I will do my best to limit the time gaps between posts.



Thanks for choosing WhatTheTech and I will be back with a fix shortly! :)


-NightWizard
Please work your way through the following scans:

1. OTL Scan
———————————-


Please download OTL from one of the following links
  • LINK 1
  • LINK 2
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in;

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.



2. GMER Scan
———————————-


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




In your next reply please include:
  • The OTL logs.
  • The GMER log.
Cheers :thumbup:
Hi Sir, thanks for you help. I have the OTL log below. However for the GMER log, i left it to scan for 5 hours on and it still couldn't complete the scan. Afterwhich it makes my pc very lag and keeps on not responding. I've tried it for about 5 to 6 times now, it just couldn't work.

Here's the OTL log:

OTL logfile created on: 8/27/2010 6:52:44 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Kennethzzz\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.74 Gb Total Space | 262.12 Gb Free Space | 56.28% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 15.69 Mb Total Space | 12.86 Mb Free Space | 81.95% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KENNETH-8PMZR3I
Current User Name: Kennethzzz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/27 18:51:55 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kennethzzz\Desktop\OTL.exe
PRC - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/01/28 20:54:14 | 002,937,528 | —- | M] () – C:\Program Files\Pando Networks\Media Booster\PMB.exe
PRC - [2009/06/24 16:51:12 | 000,803,176 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psi.exe
PRC - [2009/02/07 08:07:48 | 000,027,512 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/11/23 06:12:34 | 001,333,016 | —- | M] (Diskeeper Corporation) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2008/06/22 09:05:40 | 000,069,632 | —- | M] () – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
PRC - [2008/06/22 09:01:32 | 000,090,112 | —- | M] (Portrait Displays, Inc.) – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
PRC - [2008/06/03 16:06:34 | 005,964,800 | —- | M] () – C:\Program Files\ASUS\Six Engine\SixEngine.exe
PRC - [2008/04/14 08:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/01/05 00:00:00 | 000,118,600 | —- | M] (WinAbility® Software Corporation) – C:\Program Files\Folder Guard Pro\FGKey.exe
PRC - [2007/11/21 07:53:36 | 000,147,456 | —- | M] (Razer USA Ltd.) – C:\Program Files\Razer\Lycosa\razerhid.exe
PRC - [2007/08/02 05:07:06 | 000,147,456 | —- | M] () – C:\Program Files\Razer\Diamondback 3G\razerhid.exe
PRC - [2007/02/15 02:11:18 | 000,163,840 | —- | M] (Razer Inc.) – C:\Program Files\Razer\Diamondback 3G\razerofa.exe
PRC - [2007/02/10 03:17:30 | 000,694,008 | —- | M] () – C:\Program Files\Portrait Displays\Pivot Software\Floater.exe
PRC - [2007/02/10 03:17:26 | 000,694,008 | —- | M] () – C:\Program Files\Portrait Displays\Pivot Software\wpCtrl.exe
PRC - [2006/11/13 13:39:52 | 001,289,000 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2006/11/13 13:39:34 | 000,199,464 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2006/11/04 10:20:12 | 000,866,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/04 10:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MsMpEng.exe


========== Modules (SafeList) ==========

MOD - [2010/08/27 18:51:55 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kennethzzz\Desktop\OTL.exe
MOD - [2008/04/14 08:12:10 | 000,018,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wtsapi32.dll
MOD - [2008/04/14 08:12:09 | 000,053,760 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\winsta.dll
MOD - [2008/04/14 08:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
MOD - [2008/01/05 00:00:00 | 000,108,872 | —- | M] (WinAbility® Software Corporation) – C:\Program Files\Folder Guard Pro\FGH32.DLL
MOD - [2007/02/10 03:16:08 | 000,245,760 | —- | M] () – C:\Program Files\Portrait Displays\Pivot Software\Winphook.dll
MOD - [2005/11/29 04:57:10 | 000,512,090 | —- | M] (Stardock.Net, Inc) – C:\Program Files\Stardock\Object Desktop\WindowBlinds\wblind.dll
MOD - [2004/09/19 06:37:00 | 000,028,740 | —- | M] (Stardock.Net, Inc) – C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbhelp.dll
MOD - [2003/02/27 11:27:44 | 000,036,864 | —- | M] (Stardock.Net, Inc) – C:\WINDOWS\system32\wbsys.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/06/10 21:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/10/29 00:02:00 | 003,407,292 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\System32\GameMon.des – (npggsvc)
SRV - [2009/03/18 14:04:44 | 001,685,024 | —- | M] (NanJing Nagasoft Co, LTD.) [Auto | Stopped] – C:\WINDOWS\system32\nagasoft\vjocx.dll – (vvdsvc)
SRV - [2008/11/23 06:12:34 | 001,333,016 | —- | M] (Diskeeper Corporation) [Auto | Running] – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe – (Diskeeper)
SRV - [2008/06/22 09:05:40 | 000,069,632 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe – (DTSRVC)
SRV - [2008/06/22 09:01:32 | 000,090,112 | —- | M] (Portrait Displays, Inc.) [Auto | Running] – C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe – (PdiService)
SRV - [2006/11/04 10:19:58 | 000,013,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MsMpEng.exe – (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\XDva219.sys – (XDva219)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\dHook.sys – (EnumHook2)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\EagleNT.sys – (EagleNT)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\KENNET~1\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2009/06/17 20:20:34 | 000,012,648 | —- | M] (Secunia) [File_System | On_Demand | Running] – C:\WINDOWS\system32\drivers\psi_mf.sys – (PSI)
DRV - [2009/05/03 11:34:44 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/05/03 10:45:01 | 000,114,048 | —- | M] (Acronis) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\snapman.sys – (snapman)
DRV - [2009/03/27 16:16:28 | 000,012,672 | —- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\cpuz132_x32.sys – (cpuz132)
DRV - [2008/12/02 06:13:40 | 003,452,928 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2008/11/01 02:52:16 | 000,093,184 | R— | M] (ATI Research Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV - [2008/10/17 16:50:00 | 000,131,072 | —- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys – (Mkd2kfNt)
DRV - [2008/10/17 16:50:00 | 000,079,104 | —- | M] (AhnLab, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys – (Mkd2Nadr)
DRV - [2008/09/24 01:15:00 | 000,038,400 | R— | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/07/22 16:01:34 | 000,151,592 | —- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mv61xx.sys – (mv61xx)
DRV - [2008/07/03 17:03:00 | 004,745,216 | R— | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/06/22 09:01:44 | 000,017,064 | —- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\PdiPorts.sys – (PdiPorts)
DRV - [2008/04/14 00:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/13 11:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/01/19 05:43:16 | 000,016,128 | —- | M] (Razer USA Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Lycosa.sys – (LycoFltr)
DRV - [2008/01/05 00:00:00 | 000,054,008 | —- | M] (WinAbility® Software Corporation) [Kernel | Auto | Running] – C:\Program Files\Folder Guard Pro\FGUARD32.SYS – (FGUARD32)
DRV - [2007/12/17 17:14:06 | 000,012,400 | R— | M] () [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AsIO.sys – (AsIO)
DRV - [2007/02/10 03:17:18 | 000,017,465 | —- | M] (Portrait Displays, Inc.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\pivot.sys – (Pivot)
DRV - [2007/02/10 03:17:16 | 000,011,323 | —- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\pivotmou.sys – (pivotmou)
DRV - [2005/04/25 13:43:58 | 000,013,225 | —- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DB3G.sys – (Razerlow)
DRV - [2004/08/13 18:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2001/08/17 20:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\el90xbc5.sys – (EL90XBC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.neopets.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.neopets.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/24 19:55:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/24 19:55:05 | 000,000,000 | —D | M]

[2009/05/08 10:34:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\Mozilla\Extensions
[2010/08/23 21:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\Mozilla\Firefox\Profiles\y0hqi2h9.default\extensions
[2010/06/12 23:18:43 | 000,000,000 | —D | M] (IE Tab 2 (FF 3.6+)) – C:\Documents and Settings\Kennethzzz\Application Data\Mozilla\Firefox\Profiles\y0hqi2h9.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
[2009/08/15 23:24:30 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kennethzzz\Application Data\Mozilla\Firefox\Profiles\y0hqi2h9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/23 21:04:49 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 16:14:24 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/04 13:02:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/28 20:46:01 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll

O1 HOSTS File: ([2001/08/23 20:00:00 | 000,000,734 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Download_Bho Class) - {A986E409-30CC-4185-89BB-AB212C104524} - C:\Program Files\PPLive\PPVA\DownloaderManager.dll (Synacast)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Diamondback] C:\Program Files\Razer\Diamondback 3G\razerhid.exe ()
O4 - HKLM..\Run: [DT PHL] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
O4 - HKLM..\Run: [FG_Monitor] C:\Program Files\Folder Guard Pro\FGKey.exe (WinAbility® Software Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Lycosa] C:\Program Files\Razer\Lycosa\razerhid.exe (Razer USA Ltd.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKLM..\Run: [Six Engine] C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Kennethzzz\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Kennethzzz\Start Menu\Programs\Startup\Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1241279085483 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1241285791015 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} http://ax.emsisoft.com/asquared.cab (a-squared Scanner)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.yycast.com/vjocx-en-black.cab (VodClient Control Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} http://dl.pplive.com/PluginSetup.cab (PPLive Lite Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\WBSrv: DllName - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll (Stardock)
O24 - Desktop WallPaper: C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/02 15:16:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{3f38a93c-4ed3-11de-938c-00248c414482}\Shell\AutoRun\command - "" = G:\PMB_P.exe – File not found
O33 - MountPoints2\{ef12ddbc-3792-11de-932e-0001028044ad}\Shell\AutoRun\command - "" = G:\mwfubaob.exe – File not found
O33 - MountPoints2\{ef12ddbc-3792-11de-932e-0001028044ad}\Shell\open\Command - "" = G:\mwfubaob.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecx.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (76011798628663296)

========== Files/Folders - Created Within 90 Days ==========

[2010/08/27 18:51:52 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kennethzzz\Desktop\OTL.exe
[2010/08/27 14:31:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Sex and Zen 3 - 1998
[2010/08/24 22:48:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Demon Beast Invasion 1-6
[2010/08/16 20:12:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\The.Last.Song.2010.DVDRip.XviD-ZMG
[2010/08/11 10:22:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Call Of Duty Modern Warfare 2 [English][PC][2DVDs][WwW.GamesTorrents.CoM]
[2010/08/07 15:28:44 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/08/07 15:28:41 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/08/07 15:25:20 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/08/04 13:02:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/22 14:56:53 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Blizzard Entertainment
[2010/07/21 16:40:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Remember Me (2010) DVDRip XviD-MAXSPEED
[2010/07/05 17:14:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Fated Soccerjam Server
[2010/07/03 15:53:50 | 000,000,000 | —D | C] – C:\Program Files\Free WMA to MP3 Converter
[2010/07/02 22:20:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\Temp
[2010/07/02 22:19:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\Google
[2010/07/02 18:07:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\Fifa World Cup South Africa 2010 Babes
[2010/06/27 14:11:52 | 000,000,000 | —D | C] – C:\WINDOWS\RegisteredPackages
[2010/06/26 21:18:47 | 000,000,000 | -H-D | C] – C:\VJVod_Cache
[2010/06/26 21:18:47 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\nagasoft
[2010/06/25 22:17:04 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nagasoft
[2010/06/25 17:29:33 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2010/06/25 17:29:06 | 000,000,000 | —D | C] – C:\ATI
[2010/06/24 11:42:10 | 000,000,000 | —D | C] – C:\Program Files\Whisper Technology
[2010/06/23 10:44:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Desktop\render
[2010/06/14 00:11:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Kennethzzz\Application Data\StreamTorrent
[2010/06/14 00:11:50 | 000,000,000 | —D | C] – C:\Program Files\StreamTorrent 1.0
[2010/05/31 19:55:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nexon
[2010/05/31 19:51:36 | 000,000,000 | —D | C] – C:\Temp
[2009/08/09 16:03:01 | 000,095,560 | —- | C] (WinAbility® Software Corporation) – C:\Program Files\Folder Guard - Emergency Recovery Utility.exe
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/27 18:51:55 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kennethzzz\Desktop\OTL.exe
[2010/08/27 17:56:39 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/27 13:29:12 | 000,049,664 | —- | M] () – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/27 11:54:28 | 000,525,448 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/27 11:54:28 | 000,443,588 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/08/27 11:54:28 | 000,071,846 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/08/27 11:53:10 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/08/27 11:50:33 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/27 11:50:02 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/27 11:50:00 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/27 11:49:59 | 000,069,112 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2010/08/26 19:44:33 | 009,175,040 | —- | M] () – C:\Documents and Settings\Kennethzzz\NTUSER.DAT
[2010/08/26 19:44:20 | 002,638,742 | -H– | M] () – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\IconCache.db
[2010/08/26 18:42:35 | 730,585,088 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\S Zen 2.avi
[2010/08/26 00:14:23 | 007,312,737 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\BOB - Airplanes (feat. Hayley Williams).mp3
[2010/08/22 09:57:00 | 000,000,096 | -H– | M] () – C:\WINDOWS\System32\HsInfo.dat
[2010/08/19 22:55:53 | 000,041,662 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\pKCP-4879092v275.jpg
[2010/08/16 17:45:48 | 008,768,018 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Rihanna - Hate That I Love You ft. Ne-Yo.mp3
[2010/08/15 19:40:10 | 006,434,688 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Orianthi - Shut Up and Kiss Me.mp3
[2010/08/14 15:23:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/08/14 14:17:07 | 000,036,251 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\51JDYkv9I2L__SS500_.jpg
[2010/08/12 21:23:57 | 000,079,198 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\changes.jpg
[2010/08/12 14:19:14 | 000,291,680 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/08/12 13:55:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/08/11 19:45:19 | 000,138,184 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2010/08/11 12:01:59 | 1335,040,000 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\The Girl With The Dragon Tattoo (2009) DvdRip {1337x}-X.avi
[2010/08/11 10:13:41 | 000,327,081 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\manu
[2010/08/10 09:58:46 | 000,027,088 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Archuleta-FauxHawkHairstyle.jpg
[2010/08/08 20:58:07 | 000,014,100 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\FS4481_main.jpg
[2010/08/07 23:09:56 | 000,013,821 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\111111.jpg
[2010/07/30 17:47:12 | 000,037,809 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\1002.jpg
[2010/07/27 14:55:59 | 000,199,125 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\starcraft_ii_logo.png
[2010/07/27 00:13:51 | 000,066,776 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/07/26 14:16:07 | 009,523,991 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\3 Doors Down - Kryptonite.mp3
[2010/07/22 15:12:23 | 668,670,008 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\SC2_ProtossGameplay_1280x720_ESRB_enUS.avi
[2010/07/14 18:08:40 | 629,215,731 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[Heiwa Fansubs] Magerarenai Onna Ep04 HD.mp4
[2010/07/10 18:46:39 | 000,082,984 | —- | M] () – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/07/07 13:46:27 | 629,247,382 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 04 HD [E45C5459].mp4
[2010/07/05 17:23:55 | 000,227,657 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\4759676388_f21772bd47_b.jpg
[2010/07/05 17:23:54 | 000,237,759 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\4759041373_43226791a2_b.jpg
[2010/07/05 17:23:54 | 000,216,601 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\4759041045_ca1da421f4_b.jpg
[2010/07/05 17:23:54 | 000,195,802 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\4759676726_09b5121819_b.jpg
[2010/07/02 14:51:01 | 008,108,630 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\01 Waka Waka (This Time For Africa) Quality iTunes (Official Song FIFA World Cup 2010).mp3
[2010/06/27 18:57:02 | 000,480,056 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\encore 2.wav
[2010/06/27 14:21:09 | 000,062,009 | —- | M] (Portrait Displays, Inc.) – C:\WINDOWS\System32\wpfb_ati2dvag.dll
[2010/06/23 15:16:06 | 009,898,258 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Katy Perry - Thinking Of You.mp3
[2010/06/16 23:03:19 | 006,035,328 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\atomic kitten-whole again.mp3
[2010/06/16 11:54:30 | 628,940,782 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 03 HD [3C43B102].mp4
[2010/06/09 13:25:49 | 629,207,629 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 02 HD [117D8420].mp4
[2010/06/02 16:33:23 | 964,069,175 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 01 HD [6CF4F112].mp4
[2010/05/31 11:42:42 | 1662,638,776 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Dragonica_Setup.exe
[2010/05/31 10:17:36 | 001,875,600 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\DragonicaDownloaderV1.4.0.exe
[2010/05/30 16:26:41 | 629,062,139 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\[Heiwa Fansubs] Magerarenai Onna Ep03 HD.mp4
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/08/26 17:54:56 | 007,312,737 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\BOB - Airplanes (feat. Hayley Williams).mp3
[2010/08/24 22:12:09 | 730,585,088 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\S Zen 2.avi
[2010/08/19 23:04:43 | 000,041,662 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\pKCP-4879092v275.jpg
[2010/08/15 21:33:05 | 008,768,018 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\Rihanna - Hate That I Love You ft. Ne-Yo.mp3
[2010/08/14 14:17:12 | 000,036,251 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\51JDYkv9I2L__SS500_.jpg
[2010/08/14 14:12:04 | 006,434,688 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\Orianthi - Shut Up and Kiss Me.mp3
[2010/08/12 21:25:24 | 000,079,198 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\changes.jpg
[2010/08/11 10:13:29 | 000,327,081 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\manu
[2010/08/10 11:12:32 | 1335,040,000 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\The Girl With The Dragon Tattoo (2009) DvdRip {1337x}-X.avi
[2010/08/10 10:03:59 | 000,027,088 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\Archuleta-FauxHawkHairstyle.jpg
[2010/08/08 20:59:02 | 000,014,100 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\FS4481_main.jpg
[2010/08/07 23:10:16 | 000,013,821 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\111111.jpg
[2010/07/30 18:03:54 | 000,037,809 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\1002.jpg
[2010/07/27 14:56:06 | 000,199,125 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\starcraft_ii_logo.png
[2010/07/26 10:06:17 | 009,523,991 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\3 Doors Down - Kryptonite.mp3
[2010/07/22 14:57:02 | 668,670,008 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\SC2_ProtossGameplay_1280x720_ESRB_enUS.avi
[2010/07/05 18:10:32 | 000,227,657 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\4759676388_f21772bd47_b.jpg
[2010/07/05 18:10:28 | 000,195,802 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\4759676726_09b5121819_b.jpg
[2010/07/05 18:10:24 | 000,237,759 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\4759041373_43226791a2_b.jpg
[2010/07/05 18:10:19 | 000,216,601 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\4759041045_ca1da421f4_b.jpg
[2010/07/02 10:13:33 | 629,247,382 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 04 HD [E45C5459].mp4
[2010/07/01 11:41:12 | 008,108,630 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\01 Waka Waka (This Time For Africa) Quality iTunes (Official Song FIFA World Cup 2010).mp3
[2010/06/27 18:57:02 | 000,480,056 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\encore 2.wav
[2010/06/27 14:11:34 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2010/06/27 14:11:34 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2010/06/27 14:11:34 | 000,052,224 | —- | C] () – C:\WINDOWS\System32\msdvbnp.ax
[2010/06/27 14:11:34 | 000,052,224 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2010/06/27 14:11:34 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\psisrndr.ax
[2010/06/27 14:11:34 | 000,030,208 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2010/06/27 14:11:33 | 001,798,144 | —- | C] () – C:\WINDOWS\System32\dllcache\qedit.dll
[2010/06/27 14:11:33 | 000,733,184 | —- | C] () – C:\WINDOWS\System32\dllcache\qedwipes.dll
[2010/06/27 14:11:33 | 000,173,056 | —- | C] () – C:\WINDOWS\System32\dllcache\qasf.dll
[2010/06/27 14:11:33 | 000,013,312 | —- | C] () – C:\WINDOWS\System32\dllcache\msdmo.dll
[2010/06/27 14:11:32 | 000,470,528 | —- | C] () – C:\WINDOWS\System32\dllcache\qdvd.dll
[2010/06/27 14:11:32 | 000,316,928 | —- | C] () – C:\WINDOWS\System32\dllcache\qdv.dll
[2010/06/27 14:11:32 | 000,257,024 | —- | C] () – C:\WINDOWS\System32\dllcache\qcap.dll
[2010/06/27 14:11:32 | 000,136,192 | —- | C] () – C:\WINDOWS\System32\dllcache\mpg2splt.ax
[2010/06/27 14:11:32 | 000,132,608 | —- | C] () – C:\WINDOWS\System32\dllcache\devenum.dll
[2010/06/27 14:11:32 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\dllcache\amstream.dll
[2010/06/27 14:11:32 | 000,034,304 | —- | C] () – C:\WINDOWS\System32\dllcache\mciqtz32.dll
[2010/06/25 17:29:54 | 000,057,480 | —- | C] () – C:\WINDOWS\System32\atiapfxx.blb
[2010/06/23 14:50:36 | 009,898,258 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\Katy Perry - Thinking Of You.mp3
[2010/06/16 17:08:27 | 006,035,328 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\atomic kitten-whole again.mp3
[2010/06/12 09:40:55 | 628,940,782 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 03 HD [3C43B102].mp4
[2010/06/09 09:57:31 | 629,207,629 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 02 HD [117D8420].mp4
[2010/06/01 13:57:01 | 964,069,175 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\[TimeLesSub] Tsuki no Koibito Ep 01 HD [6CF4F112].mp4
[2010/05/31 10:18:20 | 1662,638,776 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\Dragonica_Setup.exe
[2010/05/31 10:17:33 | 001,875,600 | —- | C] () – C:\Documents and Settings\Kennethzzz\Desktop\DragonicaDownloaderV1.4.0.exe
[2009/11/14 23:40:18 | 000,002,528 | —- | C] () – C:\Documents and Settings\Kennethzzz\Application Data\$_hpcst$.hpc
[2009/10/17 00:04:06 | 000,000,319 | —- | C] () – C:\WINDOWS\game.ini
[2009/08/15 10:33:48 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/08/15 10:33:48 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/08/15 10:33:47 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/08/15 10:33:46 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/08/15 10:33:46 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/07/04 22:38:12 | 000,138,184 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/06/28 17:01:08 | 006,440,983 | —- | C] () – C:\Program Files\VideoraiPodConverter.exe
[2009/06/06 09:26:53 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/05/31 10:50:11 | 000,000,484 | —- | C] () – C:\WINDOWS\FOE2.ini
[2009/05/11 11:19:57 | 000,000,236 | —- | C] () – C:\WINDOWS\ACTIVEJP.INI
[2009/05/04 12:27:20 | 000,000,072 | —- | C] () – C:\WINDOWS\WB.ini
[2009/05/04 10:13:02 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\wbload.dll
[2009/05/03 11:39:05 | 000,049,664 | —- | C] () – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/03 11:34:44 | 000,721,904 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2009/05/03 07:20:03 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\Machnm32.sys
[2009/05/03 06:48:28 | 000,000,133 | —- | C] () – C:\Documents and Settings\Kennethzzz\Local Settings\Application Data\fusioncache.dat
[2009/05/03 00:57:23 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2009/05/03 00:57:23 | 000,012,400 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2009/05/03 00:57:21 | 000,011,832 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp64.sys
[2009/05/03 00:57:21 | 000,010,216 | —- | C] () – C:\WINDOWS\System32\drivers\AsInsHelp32.sys
[2009/05/03 00:43:57 | 000,036,015 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/05/03 00:43:42 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/05/03 00:43:37 | 000,035,562 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/05/03 00:43:37 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

========== LOP Check ==========

[2009/05/03 11:14:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2009/05/03 11:36:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/05/21 04:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
[2010/05/31 19:55:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2010/05/31 10:18:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/08/23 16:46:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLive
[2010/05/11 15:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PPLiveVA
[2009/06/03 06:29:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Razer
[2009/11/11 14:45:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2009/07/04 11:00:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/04/20 18:20:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/19 14:01:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/21 04:07:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/05/03 12:21:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\DAEMON Tools Lite
[2009/05/03 07:32:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\DisplayTune
[2009/11/17 17:11:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\DMCache
[2010/01/18 14:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\DragonicaSCB
[2010/02/03 16:50:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\EA
[2010/05/28 14:50:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\GetRightToGo
[2009/05/04 00:19:54 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Kennethzzz\Application Data\ijjigame
[2009/07/04 22:18:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\Leadertech
[2009/05/09 11:56:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\Nexon
[2009/05/04 00:27:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\NPLUTO Corporation
[2010/08/23 16:46:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\PPLive
[2009/11/17 12:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\PPLiveVA
[2009/11/11 15:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\Sports Interactive
[2010/06/14 00:11:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\StreamTorrent
[2010/08/27 18:52:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Kennethzzz\Application Data\uTorrent
[2010/08/27 11:53:10 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/11/17 01:17:12 | 000,025,102 | —- | M] () – C:\ASLog.txt
[2009/05/02 15:16:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/05/16 01:16:02 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2009/05/02 15:16:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/08/29 20:23:03 | 000,000,717 | —- | M] () – C:\CPUID CPU-Z.lnk
[2009/05/02 15:16:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/05/02 15:16:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/05/02 23:58:56 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/05/03 01:41:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/08/27 11:49:55 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/05/03 01:12:32 | 000,000,046 | -H– | M] () – C:\splash.idx
[2008/08/16 11:02:18 | 000,005,632 | -H– | M] () – C:\version

< %systemroot%\Fonts\*.com >
[2006/04/19 06:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/30 05:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 06:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/30 05:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/05/02 15:16:35 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/05 00:00:00 | 000,095,560 | —- | M] (WinAbility® Software Corporation) – C:\Program Files\Folder Guard - Emergency Recovery Utility.exe
[2008/05/14 14:10:31 | 006,440,983 | —- | M] () – C:\Program Files\VideoraiPodConverter.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/05/02 08:08:59 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/05/02 08:08:59 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/02 08:08:59 | 000,421,888 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/05/03 01:44:38 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/03 01:48:41 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Kennethzzz\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/05/02 15:19:46 | 000,000,079 | —- | M] () – C:\Documents and Settings\Kennethzzz\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/05/31 10:17:36 | 001,875,600 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\DragonicaDownloaderV1.4.0.exe
[2010/05/31 11:42:42 | 1662,638,776 | —- | M] () – C:\Documents and Settings\Kennethzzz\Desktop\Dragonica_Setup.exe
[2010/08/27 18:51:55 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kennethzzz\Desktop\OTL.exe
[2009/05/03 07:45:49 | 000,274,224 | —- | M] (BitTorrent, Inc.) – C:\Documents and Settings\Kennethzzz\Desktop\utorrent.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-25 13:46:24

========== Files - Unicode (All) ==========
[2010/08/22 15:20:09 | 1746,161,530 | —- | M] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?02?????????????[1920x1080p H.264 AAC].mkv) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第02夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].mkv
[2010/08/19 13:04:28 | 000,062,692 | —- | M] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?01?????????????[1920x1080p H.264 AAC].srt) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第01夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].srt
[2010/08/19 13:04:28 | 000,062,692 | —- | C] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?01?????????????[1920x1080p H.264 AAC].srt) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第01夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].srt
[2010/08/19 13:03:06 | 1746,161,530 | —- | C] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?02?????????????[1920x1080p H.264 AAC].mkv) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第02夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].mkv
[2010/08/06 17:00:17 | 2477,178,453 | —- | M] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?01?????????????[1920x1080p H.264 AAC].mkv) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第01夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].mkv
[2010/08/06 14:37:03 | 2477,178,453 | —- | C] ()(C:\Documents and Settings\Kennethzzz\Desktop\???????2 ?01?????????????[1920x1080p H.264 AAC].mkv) – C:\Documents and Settings\Kennethzzz\Desktop\ホタルノヒカリ2 第01夜「綾瀬はるか、藤木直人」[1920x1080p H.264 AAC].mkv
[2010/08/03 18:15:01 | 004,020,811 | —- | M] ()(C:\Documents and Settings\Kennethzzz\Desktop\?? - ?????.mp3) – C:\Documents and Settings\Kennethzzz\Desktop\伍佰 - 世界第一等.mp3
[2010/08/03 11:35:53 | 004,020,811 | —- | C] ()(C:\Documents and Settings\Kennethzzz\Desktop\?? - ?????.mp3) – C:\Documents and Settings\Kennethzzz\Desktop\伍佰 - 世界第一等.mp3
[2010/06/27 18:50:54 | 000,480,056 | —- | M] ()(C:\Documents and Settings\Kennethzzz\Desktop\? ? ZSS? ™ ? ?_6_27_2010@18_50_14.wav) – C:\Documents and Settings\Kennethzzz\Desktop\♠ ♥ ZΣΣЩ ™ ♣ ♦_6_27_2010@18_50_14.wav
[2010/06/27 18:50:54 | 000,480,056 | —- | C] ()(C:\Documents and Settings\Kennethzzz\Desktop\? ? ZSS? ™ ? ?_6_27_2010@18_50_14.wav) – C:\Documents and Settings\Kennethzzz\Desktop\♠ ♥ ZΣΣЩ ™ ♣ ♦_6_27_2010@18_50_14.wav

========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
Hi D3stinY,

Good to see you back, please try running GMER in safe mode following the above instructions (you may want to print them out or write them down).

To boot into safe mode, Reboot then tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu.

Cheers :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI