This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Hijack.FolderOptions?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, Last night I managed to get myself infected somehow, and since aside from crying like a little girl there isn't a whole lot I can do about it,
I've come to ask (beg) for help! :notworthy:

Basically last night out of the blue windows defender popped up saying something about a high risk threat, So I clicked okay to delete it. Right as it
prompted for a restart another window opened beside it with some sort of alert. Knew enough to realise it was a fake alert and task manager revealed
about 10 command prompts running. …bugger.

So a scan in safemode with malwarebytes found and removed about 120 infections (I'll provide the log if you need it?) but one remains, and comes back
every time malwarebytes removes it. Apparently its a "Hijack.FolderOptions"

I'm not sure how deep this runs, So any assistance would be greatly appreciated! Thanks a bunch!

Hijack this log;

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:19:11 PM, on 8/09/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Users\Vincent Pinto\Documents\G15\SirReal\LCDSirReal.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Freecorder\FLVSrvc.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Vincent Pinto\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [rnmxesocaw.exe] "C:\Users\VINCEN~1\AppData\Local\Temp\rnmxesocaw.exe"
O4 - HKLM\..\Run: [sraonecxmw.exe] "C:\Users\VINCEN~1\AppData\Local\Temp\sraonecxmw.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [YXE7DXCQ37] C:\Users\Vincent Pinto\AppData\Local\Temp\Ox7.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServiceWacom - Unknown owner - C:\Windows\system32\Wacom_Tablet.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 9561 bytes
Hi forgottenv, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKLM\..\Run: [rnmxesocaw.exe] "C:\Users\VINCEN~1\AppData\Local\Temp\rnmxesocaw.exe"
O4 - HKLM\..\Run: [sraonecxmw.exe] "C:\Users\VINCEN~1\AppData\Local\Temp\sraonecxmw.exe"
O4 - HKCU\..\Run: [YXE7DXCQ37] C:\Users\Vincent Pinto\AppData\Local\Temp\Ox7.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

Reboot your computer.



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



Download OTL to your desktop.
  • Right click on OTL.exe and selecy "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • MBRCheck log
  • both OTL logs
Thanks
Hi Oldman, Thanks for the quick reply

I did as you asked and have the logs, So here they are:

MBRCheck:

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Professional
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: Gigabyte Technology Co., Ltd.
BIOS Manufacturer: Award Software International, Inc.
System Manufacturer: Gigabyte Technology Co., Ltd.
System Product Name: EX58-UD5
Logical Drives Mask: 0x0000007c

Kernel Drivers (total 198):
0x02E0B000 \SystemRoot\system32\ntoskrnl.exe
0x033E7000 \SystemRoot\system32\hal.dll
0x00BAE000 \SystemRoot\system32\kdcom.dll
0x00C7A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CBE000 \SystemRoot\system32\PSHED.dll
0x00CD2000 \SystemRoot\system32\CLFS.SYS
0x00D30000 \SystemRoot\system32\CI.dll
0x00E0D000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00EB1000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00EC0000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x00F17000 \SystemRoot\system32\DRIVERS\WMILIB.SYS
0x00F20000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x00F2A000 \SystemRoot\system32\DRIVERS\pci.sys
0x00F5D000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00F6A000 \SystemRoot\System32\drivers\partmgr.sys
0x00F7F000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00F94000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FF0000 \SystemRoot\system32\DRIVERS\pciide.sys
0x00DF0000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00C00000 \SystemRoot\System32\drivers\mountmgr.sys
0x01090000 \SystemRoot\system32\DRIVERS\iaStorV.sys
0x011AE000 \SystemRoot\system32\DRIVERS\atapi.sys
0x011B7000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x011E1000 \SystemRoot\system32\DRIVERS\msahci.sys
0x011EC000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x01000000 \SystemRoot\system32\drivers\fltmgr.sys
0x0104C000 \SystemRoot\system32\drivers\fileinfo.sys
0x01256000 \SystemRoot\System32\Drivers\Ntfs.sys
0x00C1A000 \SystemRoot\System32\Drivers\msrpc.sys
0x01200000 \SystemRoot\System32\Drivers\ksecdd.sys
0x0145A000 \SystemRoot\System32\Drivers\cng.sys
0x014CD000 \SystemRoot\System32\drivers\pcw.sys
0x014DE000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x014E8000 \SystemRoot\system32\drivers\ndis.sys
0x016B9000 \SystemRoot\system32\drivers\NETIO.SYS
0x01719000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01802000 \SystemRoot\System32\drivers\tcpip.sys
0x01744000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0178E000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x0179E000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x017EA000 \SystemRoot\System32\Drivers\spldr.sys
0x017F2000 \SystemRoot\SysWOW64\speedfan.sys
0x01600000 \SystemRoot\System32\drivers\rdyboost.sys
0x0163A000 \SystemRoot\System32\Drivers\mup.sys
0x0164C000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01655000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x0168F000 \SystemRoot\system32\DRIVERS\disk.sys
0x01400000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x02D9F000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02DC9000 \SystemRoot\System32\Drivers\Null.SYS
0x02DD2000 \SystemRoot\System32\Drivers\Beep.SYS
0x02DD9000 \SystemRoot\System32\drivers\vga.sys
0x02C00000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02C25000 \SystemRoot\System32\drivers\watchdog.sys
0x02C35000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02C3E000 \SystemRoot\system32\drivers\rdpencdd.sys
0x02C47000 \SystemRoot\system32\drivers\rdprefmp.sys
0x02C50000 \SystemRoot\System32\Drivers\Msfs.SYS
0x02C5B000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01430000 \SystemRoot\system32\DRIVERS\tdx.sys
0x02DE7000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x04005000 \SystemRoot\system32\drivers\afd.sys
0x0408F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x040D4000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x040DD000 \SystemRoot\system32\DRIVERS\pacer.sys
0x04103000 \SystemRoot\system32\DRIVERS\netbios.sys
0x04112000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x0412D000 \??\C:\Windows\system32\Drivers\vmm.sys
0x0417A000 \SystemRoot\system32\DRIVERS\termdd.sys
0x0418E000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x041A8000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02DF4000 \SystemRoot\system32\drivers\nsiproxy.sys
0x0144E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x015DA000 \SystemRoot\System32\drivers\discache.sys
0x0424A000 \SystemRoot\system32\drivers\csc.sys
0x042CD000 \SystemRoot\System32\Drivers\dfsc.sys
0x042EB000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x042FC000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04322000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0FE5A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x10AEC000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x10AEE000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FE00000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0FE46000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x04338000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x10BE2000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x0438E000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x043B2000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04200000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x10BF3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x043E4000 \SystemRoot\system32\DRIVERS\VMNetSrv.sys
0x015E9000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x10BFC000 \SystemRoot\system32\DRIVERS\wacomvhid.sys
0x0121A000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x0423E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x01233000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x01060000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x01249000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04851000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04880000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x0489B000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x048BC000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x048D6000 \SystemRoot\system32\DRIVERS\hamachi.sys
0x048E1000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x048EC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x048FB000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x0496C000 \SystemRoot\system32\DRIVERS\swenum.sys
0x0496E000 \SystemRoot\system32\DRIVERS\ks.sys
0x049B1000 \SystemRoot\system32\drivers\LGBusEnum.sys
0x049B5000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0490A000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x049C7000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x049D4000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys
0x049DC000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x058DF000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x05AFC000 \SystemRoot\system32\drivers\portcls.sys
0x05B39000 \SystemRoot\system32\drivers\drmk.sys
0x05B5B000 \SystemRoot\system32\drivers\ksthunk.sys
0x05B61000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x05B6F000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x05B71000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x05B8E000 \SystemRoot\system32\DRIVERS\wacmoumonitor.sys
0x05B97000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x05BA8000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x05BB4000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
0x05BC7000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
0x05BDB000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x000A0000 \SystemRoot\System32\win32k.sys
0x05800000 \SystemRoot\System32\drivers\Dxapi.sys
0x0580C000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02C6C000 \SystemRoot\System32\Drivers\dump_iaStorV.sys
0x0581A000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x0582D000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x0583B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00430000 \SystemRoot\System32\TSDDD.dll
0x00730000 \SystemRoot\System32\cdd.dll
0x00820000 \SystemRoot\System32\ATMFD.DLL
0x05849000 \SystemRoot\system32\drivers\luafv.sys
0x0586C000 \SystemRoot\system32\drivers\WudfPf.sys
0x0588D000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x058BE000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x04800000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x064E5000 \SystemRoot\system32\drivers\HTTP.sys
0x065AD000 \SystemRoot\system32\DRIVERS\bowser.sys
0x065CB000 \SystemRoot\System32\drivers\mpsdrv.sys
0x06400000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0642D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0647B000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x0649E000 \SystemRoot\System32\Drivers\adfs.SYS
0x06814000 \SystemRoot\system32\drivers\peauth.sys
0x068BA000 \SystemRoot\System32\Drivers\secdrv.SYS
0x068C5000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x068F2000 \SystemRoot\System32\drivers\tcpipreg.sys
0x06904000 \SystemRoot\System32\DRIVERS\srv2.sys
0x06C02000 \SystemRoot\System32\DRIVERS\srv.sys
0x06C98000 \SystemRoot\system32\drivers\LGVirHid.sys
0x06C9B000 \SystemRoot\system32\drivers\spsys.sys
0x06D0C000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x76DD0000 \Windows\System32\ntdll.dll
0x47FC0000 \Windows\System32\smss.exe
0xFF0F0000 \Windows\System32\apisetschema.dll
0xFFA10000 \Windows\System32\autochk.exe
0xFF000000 \Windows\System32\advapi32.dll
0xFEF30000 \Windows\System32\usp10.dll
0xFEE20000 \Windows\System32\msctf.dll
0xFEE10000 \Windows\System32\nsi.dll
0xFED70000 \Windows\System32\clbcatq.dll
0xFEB10000 \Windows\System32\iertutil.dll
0xFEAF0000 \Windows\System32\imagehlp.dll
0xFEAA0000 \Windows\System32\Wldap32.dll
0xFE890000 \Windows\System32\ole32.dll
0xFE820000 \Windows\System32\gdi32.dll
0xFE6A0000 \Windows\System32\urlmon.dll
0xFE680000 \Windows\System32\sechost.dll
0x76FA0000 \Windows\System32\psapi.dll
0xFE670000 \Windows\System32\lpk.dll
0x76CD0000 \Windows\System32\user32.dll
0x76F90000 \Windows\System32\normaliz.dll
0xFE590000 \Windows\System32\oleaut32.dll
0xFE510000 \Windows\System32\shlwapi.dll
0xFE470000 \Windows\System32\msvcrt.dll
0xFE440000 \Windows\System32\imm32.dll
0xFE3A0000 \Windows\System32\comdlg32.dll
0xFE270000 \Windows\System32\rpcrt4.dll
0x76BB0000 \Windows\System32\kernel32.dll
0xFE220000 \Windows\System32\ws2_32.dll
0xFD490000 \Windows\System32\shell32.dll
0xFD2B0000 \Windows\System32\setupapi.dll
0xFD230000 \Windows\System32\difxapi.dll
0xFD100000 \Windows\System32\wininet.dll
0xFCF90000 \Windows\System32\crypt32.dll
0xFCEF0000 \Windows\System32\comctl32.dll
0xFCE80000 \Windows\System32\KernelBase.dll
0xFCE40000 \Windows\System32\wintrust.dll
0xFCE20000 \Windows\System32\devobj.dll
0xFCDE0000 \Windows\System32\cfgmgr32.dll
0xFCDD0000 \Windows\System32\msasn1.dll
0x769B0000 \Windows\SysWOW64\normaliz.dll

Processes (total 80):
0 System Idle Process
4 System
440 C:\Windows\System32\smss.exe
568 csrss.exe
644 C:\Windows\System32\wininit.exe
668 csrss.exe
700 C:\Windows\System32\services.exe
724 C:\Windows\System32\lsass.exe
732 C:\Windows\System32\lsm.exe
832 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\nvvsvc.exe
932 C:\Windows\System32\svchost.exe
996 C:\Windows\System32\svchost.exe
148 C:\Windows\System32\svchost.exe
456 C:\Windows\System32\svchost.exe
784 C:\Windows\System32\winlogon.exe
1028 C:\Windows\System32\audiodg.exe
1120 C:\Windows\System32\svchost.exe
1256 WUDFHost.exe
1380 WUDFHost.exe
1444 C:\Windows\System32\svchost.exe
1560 C:\Windows\System32\nvvsvc.exe
1576 C:\Windows\System32\wisptis.exe
1640 C:\Windows\System32\spoolsv.exe
1684 C:\Windows\System32\svchost.exe
1816 C:\Windows\System32\svchost.exe
1848 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
1884 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
1956 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
2012 C:\Windows\SysWOW64\PnkBstrA.exe
2036 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
1740 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
1996 C:\Windows\System32\svchost.exe
2096 C:\Windows\System32\Wacom_Tablet.exe
3044 C:\Windows\System32\taskeng.exe
3068 C:\Windows\System32\wisptis.exe
564 C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
1468 C:\Windows\System32\dwm.exe
2512 C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
1340 C:\Windows\explorer.exe
1240 C:\Windows\System32\taskhost.exe
2588 C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
2992 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
3060 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
3084 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
3140 C:\Program Files\Windows Sidebar\sidebar.exe
3160 C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
3196 C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
3508 C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
3516 C:\Program Files\Logitech\GamePanel Software\Applets\LCDClock.exe
3532 C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
3572 C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
3580 C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
3592 C:\Users\Vincent Pinto\Documents\G15\SirReal\LCDSirReal.exe
3644 C:\Windows\System32\WTablet\Wacom_TabletUser.exe
3772 C:\Program Files\Logitech\SetPoint\SetPoint.exe
3784 C:\Windows\System32\Wacom_Tablet.exe
4008 C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
4048 C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
4068 C:\Program Files (x86)\Java\jre6\bin\jusched.exe
4076 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
4084 C:\Program Files (x86)\Freecorder\FLVSrvc.exe
2980 C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
4060 C:\Windows\System32\SearchIndexer.exe
3208 C:\Program Files\Windows Media Player\wmpnetwk.exe
4248 C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
4420 C:\Windows\System32\SearchProtocolHost.exe
4448 C:\Windows\System32\SearchFilterHost.exe
4616 C:\Windows\System32\svchost.exe
5036 WmiPrvSE.exe
3780 C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
4940 C:\Program Files (x86)\Windows Media Player\wmplayer.exe
4792 taskhost.exe
6128 C:\Windows\System32\sppsvc.exe
2056 C:\Windows\explorer.exe
5300 C:\Windows\System32\svchost.exe
980 C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
2536 C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
2960 C:\Windows\System32\conhost.exe
3056 C:\Windows\System32\dllhost.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS)
\\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)
\\.\E: –> \\.\PhysicalDrive2 at offset 0x00000000`08100000 (NTFS)

PhysicalDrive0 Model Number:
PhysicalDrive1 Model Number: ST31000333AS, Rev: CC1F
PhysicalDrive2 Model Number: ST31500341AS, Rev: CC1H

Size Device Name MBR Status
——————————————–
596 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
931 GB \\.\PhysicalDrive1 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
1397 GB \\.\PhysicalDrive2 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!


————————————————————————————————————-

OTL.txt:

OTL logfile created on: 9/09/2010 7:48:49 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Vincent Pinto\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

12.00 Gb Total Physical Memory | 10.00 Gb Available Physical Memory | 85.00% Memory free
24.00 Gb Paging File | 22.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.08 Gb Total Space | 328.31 Gb Free Space | 55.08% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 671.64 Gb Free Space | 72.10% Space Free | Partition Type: NTFS
Drive E: | 1397.14 Gb Total Space | 299.05 Gb Free Space | 21.40% Space Free | Partition Type: NTFS
Unable to calculate disk information.
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHAOS_MKII
Current User Name: Vincent Pinto
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/09/09 19:46:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
PRC - [2010/07/09 16:09:52 | 000,248,936 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010/05/04 20:33:30 | 000,066,872 | —- | M] () – C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/03/30 11:16:16 | 001,820,040 | —- | M] (LogMeIn Inc.) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2009/12/10 09:00:32 | 000,522,760 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
PRC - [2009/11/16 06:59:11 | 000,158,752 | —- | M] (Applian Technologies, Inc.) – C:\Program Files (x86)\Freecorder\FLVSrvc.exe
PRC - [2009/11/09 13:17:50 | 000,180,224 | —- | M] (PowerISO Computing, Inc.) – C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2009/09/23 13:38:18 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/08/29 16:56:10 | 000,164,864 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2009/08/26 20:18:42 | 000,115,200 | —- | M] () – C:\Users\Vincent Pinto\My Documents\G15\SirReal\LCDSirReal.exe
PRC - [2009/07/20 03:00:00 | 000,077,824 | —- | M] () – C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
PRC - [2009/07/14 11:14:42 | 000,010,240 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe
PRC - [2007/10/18 11:34:02 | 005,724,184 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
PRC - [2007/07/24 10:15:14 | 000,185,632 | —- | M] (Protexis Inc.) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe


========== Modules (SafeList) ==========

MOD - [2010/09/09 19:46:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
MOD - [2010/09/09 19:42:19 | 000,012,800 | —- | M] (Applian Technologies, Inc.) – C:\Users\Vincent Pinto\AppData\Local\FLVService\lib\FLVSrvLib.dll
MOD - [2009/07/20 03:00:00 | 000,057,344 | —- | M] (Logitech, Inc.) – C:\Program Files\Logitech\SetPoint\x86\GameHook.dll
MOD - [2009/07/20 03:00:00 | 000,038,912 | —- | M] (Logitech, Inc.) – C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll
MOD - [2009/07/14 11:16:16 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll
MOD - [2009/07/14 11:14:10 | 000,095,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/14 11:03:50 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
MOD - [2009/06/11 07:23:11 | 000,632,656 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [Auto | Running] – C:\Windows\SysNative\PnkBstrA.exe – (PnkBstrA)
SRV:64bit: - [2010/03/08 15:47:06 | 006,245,744 | —- | M] (Wacom Technology, Corp.) [Auto | Running] – C:\Windows\SysNative\Wacom_Tablet.exe – (TabletServiceWacom)
SRV:64bit: - [2009/07/20 11:36:14 | 000,160,784 | —- | M] (Logitech, Inc.) [On_Demand | Stopped] – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe – (LBTServ)
SRV:64bit: - [2009/07/14 11:41:56 | 000,195,072 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\umrdp.dll – (UmRdpService)
SRV:64bit: - [2009/07/14 11:41:54 | 000,017,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\StorSvc.dll – (StorSvc)
SRV:64bit: - [2009/07/14 11:41:53 | 001,361,920 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\PeerDistSvc.dll – (PeerDistSvc)
SRV:64bit: - [2009/07/14 11:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/14 11:40:24 | 000,689,152 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\SysNative\cscsvc.dll – (CscService)
SRV:64bit: - [2009/07/14 11:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2010/07/09 16:09:52 | 000,248,936 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2010/05/04 20:33:30 | 000,066,872 | —- | M] () [Auto | Running] – C:\Windows\SysWOW64\PnkBstrA.exe – (PnkBstrA)
SRV - [2010/03/30 11:16:14 | 001,823,112 | —- | M] (LogMeIn Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe – (Hamachi2Svc)
SRV - [2010/03/18 17:23:04 | 000,044,376 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe – (aspnet_state)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/03/04 19:26:30 | 000,332,720 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/02/19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/10/27 08:26:36 | 000,657,408 | —- | M] (Nokia) [On_Demand | Stopped] – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe – (ServiceLayer)
SRV - [2009/09/23 13:38:18 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2008/10/25 10:44:08 | 000,065,888 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe – (Microsoft Office Groove Audit Service)
SRV - [2007/10/25 14:27:54 | 000,266,240 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe – (WLSetupSvc)
SRV - [2007/10/18 10:31:54 | 000,098,328 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe – (usnjsvc)
SRV - [2007/07/24 10:15:14 | 000,185,632 | —- | M] (Protexis Inc.) [Auto | Running] – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe – (PSI_SVC_2)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/03/16 02:00:35 | 000,294,248 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\VMM.sys – (vmm)
DRV:64bit: - [2010/01/24 14:32:24 | 000,018,216 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\wacmoumonitor.sys – (wacmoumonitor)
DRV:64bit: - [2009/11/23 16:38:00 | 000,016,008 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LGVirHid.sys – (LGVirHid)
DRV:64bit: - [2009/11/23 16:37:50 | 000,022,408 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LGBusEnum.sys – (LGBusEnum)
DRV:64bit: - [2009/10/06 10:54:18 | 000,008,704 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys – (UsbserFilt)
DRV:64bit: - [2009/10/06 10:53:56 | 000,025,088 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbox64.sys – (nmwcdcx64)
DRV:64bit: - [2009/10/06 10:53:56 | 000,008,704 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys – (upperdev)
DRV:64bit: - [2009/10/06 10:53:54 | 000,018,944 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ccdcmbx64.sys – (nmwcdx64)
DRV:64bit: - [2009/09/23 11:32:39 | 000,095,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vpcusb.sys – (vpcusb)
DRV:64bit: - [2009/09/23 11:32:33 | 000,187,904 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vpchbus.sys – (vpcbus)
DRV:64bit: - [2009/09/23 08:42:58 | 000,033,856 | -H– | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\hamachi.sys – (hamachi)
DRV:64bit: - [2009/09/21 15:29:22 | 000,016,168 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\wacomvhid.sys – (wacomvhid)
DRV:64bit: - [2009/07/14 11:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/14 11:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/14 11:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 11:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 11:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/14 11:45:55 | 000,200,272 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vmbus.sys – (vmbus)
DRV:64bit: - [2009/07/14 11:45:55 | 000,046,672 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\vmstorfl.sys – (storflt)
DRV:64bit: - [2009/07/14 11:45:55 | 000,034,896 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\storvsc.sys – (storvsc)
DRV:64bit: - [2009/07/14 11:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 10:06:32 | 000,032,768 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbser.sys – (usbser)
DRV:64bit: - [2009/07/14 09:42:58 | 000,006,656 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\vms3cap.sys – (s3cap)
DRV:64bit: - [2009/07/14 09:42:44 | 000,021,760 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VMBusHID.sys – (VMBusHID)
DRV:64bit: - [2009/07/14 09:24:27 | 000,514,048 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\csc.sys – (CSC)
DRV:64bit: - [2009/06/18 02:54:30 | 000,057,872 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LMouFilt.Sys – (LMouFilt)
DRV:64bit: - [2009/06/18 02:54:22 | 000,055,312 | —- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\LHidFilt.Sys – (LHidFilt)
DRV:64bit: - [2009/06/11 06:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/11 06:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/11 06:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/11 06:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/11 06:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/03/01 22:05:32 | 000,187,392 | —- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2008/08/28 10:44:42 | 000,025,600 | —- | M] (Nokia) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\pccsmcfdx64.sys – (pccsmcfd)
DRV:64bit: - [2008/02/05 00:50:42 | 000,079,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VMNetSrv.sys – (VPCNetS2)
DRV:64bit: - [2007/02/16 10:12:36 | 000,012,848 | —- | M] (Wacom Technology) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\wacommousefilter.sys – (wacommousefilter)
DRV - [2007/02/08 04:27:46 | 000,014,104 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | Boot | Running] – C:\Windows\SysWOW64\speedfan.sys – (speedfan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7D EA 37 F5 49 48 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..keyword.enabled: false

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/29 04:10:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/08/29 04:10:48 | 000,000,000 | —D | M]

[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions
[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/08 23:54:37 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Freecorder Toolbar) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/29 20:54:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/15 17:28:51 | 000,002,746 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\ebaycomau.xml
[2010/04/08 05:43:32 | 000,002,057 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\youtube-video-search.xml
[2010/09/08 23:54:37 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/16 19:36:46 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/07/16 19:36:46 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/07/16 19:36:46 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/07/16 19:36:46 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/05/15 03:40:20 | 000,000,875 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Support\AutoRun\AutoRun.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2010/09/09 19:46:48 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:40:17 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\Desktop\backups
[2010/09/08 22:17:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 00:22:33 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Local\Windows Server
[2010/09/08 00:22:26 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107
[2010/08/31 00:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lame for Audacity
[2010/08/25 22:16:24 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2010/08/11 19:09:22 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2010/08/11 19:09:22 | 003,955,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2010/08/11 19:09:21 | 003,899,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2010/08/11 19:09:17 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2010/08/11 19:09:17 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2010/08/11 19:09:17 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2010/08/11 19:09:17 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2010/08/11 19:09:17 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2010/08/11 19:09:17 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2010/08/11 19:09:11 | 000,082,944 | —- | C] (Radius Inc.) – C:\Windows\SysWow64\iccvid.dll
[2010/08/11 19:09:11 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rtutils.dll
[2010/08/11 19:09:11 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rtutils.dll

========== Files - Modified Within 30 Days ==========

[2010/09/09 19:49:23 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/09 19:49:23 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/09 19:46:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:44:12 | 000,080,384 | —- | M] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/09 19:42:45 | 003,932,160 | -HS- | M] () – C:\Users\Vincent Pinto\NTUSER.DAT
[2010/09/09 19:42:09 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/09 19:42:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/09 19:42:01 | 1071,738,878 | -HS- | M] () – C:\hiberfil.sys
[2010/09/09 19:40:34 | 001,744,867 | -H– | M] () – C:\Users\Vincent Pinto\AppData\Local\IconCache.db
[2010/09/08 22:16:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 21:36:51 | 000,782,154 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/08 21:36:51 | 000,668,918 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/09/08 21:36:51 | 000,126,634 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/09/08 05:42:02 | 000,010,921 | —- | M] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:55 | 006,363,136 | —- | M] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:32:10 | 004,434,836 | —- | M] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/03 21:12:02 | 000,078,522 | —- | M] () – C:\Windows\SysWow64\cid_store.dat
[2010/09/03 19:10:49 | 000,000,026 | —- | M] () – C:\Windows\SysWow64\xlhcc.dat
[2010/09/02 02:58:35 | 000,029,580 | —- | M] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | M] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 15:24:46 | 000,149,911 | —- | M] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/08/29 02:31:17 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/17 19:33:28 | 000,000,224 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/08/17 19:33:27 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2010/08/12 07:34:33 | 005,230,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT

========== Files Created - No Company Name ==========

[2010/09/09 19:44:10 | 000,080,384 | —- | C] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/08 05:41:50 | 000,010,921 | —- | C] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:19 | 006,363,136 | —- | C] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:30:04 | 004,434,836 | —- | C] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/02 02:58:34 | 000,029,580 | —- | C] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | C] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 14:41:21 | 000,149,911 | —- | C] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/06/11 21:28:23 | 000,001,456 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/05/25 22:48:53 | 000,000,224 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/05/25 22:48:40 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/05/15 04:21:30 | 000,000,132 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/04/05 07:46:19 | 000,003,584 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/14 23:00:44 | 000,769,110 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/01/29 22:57:12 | 000,003,088 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/01/29 22:57:12 | 000,000,008 | RHS- | C] () – C:\ProgramData\8AFF345C7D.sys
[2009/12/24 14:33:06 | 000,146,432 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/12/24 14:33:06 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2010/09/01 00:43:21 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Audacity
[2010/02/17 19:12:49 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Bioshock2
[2010/05/10 00:35:11 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
[2010/09/08 00:23:05 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107
[2010/02/05 14:55:05 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\FileZilla
[2009/12/23 19:26:27 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Leadertech
[2010/09/02 01:20:18 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\LimeWire
[2010/02/06 14:31:54 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Nokia
[2010/02/06 14:31:06 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\PC Suite
[2010/04/13 06:00:04 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Ponscripter
[2010/03/29 23:47:58 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Propellerhead Software
[2010/01/18 21:43:46 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Skinux
[2009/12/28 22:59:46 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Smith Micro
[2010/06/23 03:49:25 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\SYSTEMAX Software Development
[2010/09/08 00:06:05 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\uTorrent
[2010/07/08 19:34:03 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/09 19:42:01 | 1071,738,878 | -HS- | M] () – C:\hiberfil.sys
[2010/04/30 19:24:27 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2010/09/09 19:42:07 | 4292,300,798 | -HS- | M] () – C:\pagefile.sys
[2010/04/02 21:07:29 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2010/04/02 22:10:53 | 000,000,232 | -H– | M] () – C:\sqmdata01.sqm
[2010/06/13 18:51:25 | 000,000,232 | -H– | M] () – C:\sqmdata02.sqm
[2010/04/02 21:07:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/04/02 22:10:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/06/13 18:51:25 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm

< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:9D1B94FD
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:2B19EBF3
< End of report >
And lastly

Extras.txt

OTL Extras logfile created on: 9/09/2010 7:48:49 PM - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Vincent Pinto\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

12.00 Gb Total Physical Memory | 10.00 Gb Available Physical Memory | 85.00% Memory free
24.00 Gb Paging File | 22.00 Gb Available in Paging File | 92.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.08 Gb Total Space | 328.31 Gb Free Space | 55.08% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 671.64 Gb Free Space | 72.10% Space Free | Partition Type: NTFS
Drive E: | 1397.14 Gb Total Space | 299.05 Gb Free Space | 21.40% Space Free | Partition Type: NTFS
Unable to calculate disk information.
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHAOS_MKII
Current User Name: Vincent Pinto
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{55C09FC1-D2D8-495A-BD80-D6725F0DCA58}" = Logitech GamePanel Software 3.04.137
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4™
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{288DB08D-0708-4A94-B055-55B99E39EB62}" = Adobe Creative Suite 5 Master Collection
"{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{4A8B461A-9336-4CF9-98F4-14DD38E673F0}" = BioShock 2
"{4CE6B3C4-D8E2-4A5D-BEF5-5B69AF843B0C}" = PC Connectivity Solution
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2
"{564B16F4-6B5B-47B0-9AB6-FF2E943947F7}" = Nokia Ovi Suite Software Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{68BD9036-0952-4849-AE7A-963BB53EDB71}" = GGPO
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6fe0c46e-97d0-4734-b584-b0e7559b60c0}" = Nero 9
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8D100E0C-1A5A-43AD-93EF-76F94AE61C30}" = OviMPlatform
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_ULTIMATER_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}_ULTIMATER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AC70B07-AD4C-4733-8F0C-9245D8F0DC7E}" = Melty Blood Re-ACT Final Tuned
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B369483E-0728-405C-8F8C-3427B263B01F}" = Content
"{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}" = Nokia Ovi Suite
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C50EF365-2898-489A-B6C7-30DAA466E9A2}" = Nokia Connectivity Cable Driver
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
"{F1C3541D-5B93-4131-B440-692FBA3DD250}" = Ovi Desktop Sync Engine
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe® Flash® Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"DC++" = DC++ (remove only)
"FileZilla Client" = FileZilla Client 3.3.1
"Freecorder4.0" = Freecorder 4.0 Application
"InstallShield_{152B782A-05F3-48EC-9AAC-4D3EB68D9E20}" = Quake 4™
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LimeWire" = LimeWire 5.4.6
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Manga Studio EX 4.0" = Manga Studio EX 4.0
"Melty Blood ReACT English" = Melty Blood ReACT English v2.0
"Mobiola Web Camera for S60_is1" = Mobiola Web Camera for S60 3.0.15
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Narcissu 2 English" = Narcissu 2 English v1.0
"Nokia Ovi Suite" = Nokia Ovi Suite
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"pcsx2-r3113" = PCSX2 - Playstation 2 Emulator
"PowerISO" = PowerISO
"QuicktimeAlt_is1" = QuickTime Alternative 3.1.0
"RealAlt_is1" = Real Alternative 2.0.1
"Reason4_is1" = Reason 4.0
"SpeedFan" = SpeedFan (remove only)
"Steam App 10000" = Enemy Territory: QUAKE Wars
"Steam App 17410" = Mirror's Edge
"Steam App 21660" = Street Fighter IV
"Steam App 32430" = Star Wars: The Force Unleashed
"Steam App 3830" = Psychonauts
"Steam App 400" = Portal
"Steam App 40930" = The Misadventures of P.B. Winterbottom
"Steam App 630" = Alien Swarm
"StepMania" = StepMania 3.9a (remove only)
"ULTIMATER" = Microsoft Office Ultimate 2007
"uTorrent" = µTorrent
"Wacom Tablet Driver" = Wacom Tablet
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BlazBlue Continuum Shift " = BlazBlue Continuum Shift
"I-Doser v4" = I-Doser v4

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/09/2010 2:42:36 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:44:03 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:44:56 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:45:59 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:46:21 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:47:08 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:47:11 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:47:22 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:47:25 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

Error - 8/09/2010 2:47:29 PM | Computer Name = Chaos_MkII | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc.manifest.
Component
2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6.manifest.

[ System Events ]
Error - 21/07/2010 12:37:09 PM | Computer Name = Chaos_MkII | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 21/07/2010 6:05:25 PM | Computer Name = Chaos_MkII | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 22/07/2010 12:19:36 AM | Computer Name = Chaos_MkII | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 23/07/2010 2:11:08 AM | Computer Name = Chaos_MkII | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 23/07/2010 2:23:10 PM | Computer Name = Chaos_MkII | Source = Service Control Manager | ID = 7016
Description = The NVIDIA Display Driver Service service has reported an invalid
current state 32.

Error - 23/07/2010 6:16:43 PM | Computer Name = Chaos_MkII | Source = Microsoft-Windows-HAL | ID = 12
Description = The platform firmware has corrupted memory across the previous system
power transition. Please check for updated firmware for your system.

Error - 24/07/2010 8:53:10 PM | Computer Name = Chaos_MkII | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk3\DR3.

Error - 24/07/2010 8:53:11 PM | Computer Name = Chaos_MkII | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk3\DR3.

Error - 24/07/2010 8:53:11 PM | Computer Name = Chaos_MkII | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk3\DR3.

Error - 24/07/2010 8:53:12 PM | Computer Name = Chaos_MkII | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk3\DR3.


< End of report >
Hi forgottenv,

LimeWire
You have LimeWire, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it. It's not the program itself that's the problem but what can be downloaded with it usually from an unknown source.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove this program, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



Your java is out of date. Go to Start > Control Panel , switch to Classic View if it isn't already.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now


Next, Right click on OTL.exe and chose Run as Administrator to run it
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:reg

:OTL
O4 - HKCU..\Run: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Support\AutoRun\AutoRun.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Autorun.exe – File not found

:Files
ipconfig /flushdns /c
C:\Users\VINCEN~1\AppData\Local\Temp\rnmxesocaw.exe
C:\Users\VINCEN~1\AppData\Local\Temp\sraonecxmw.exe
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox7.exe

:Commands
[emptytemp]
[createrestorepoint]
[reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix


You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • OTL fix log
  • MBAM log

How's the computer?

Thanks
Atch! Stupid! Stupid Stupid! Don't have the OTL fixlog for you. Assumed it would have been automatically saved like the last two and accidentally closed it down. Sorry! Is there anything else I can do about it? On the bright side, Do have the MBAM log, This time it found the infection and deleted it without needing a reboot prompt. As for the computer, Since the infection windows explorer has crashed and restarted itself 3 times. A minor inconvenience but it never happened before, Was wondering if the two were connected? And incidentally I only ever use limewire for mp3s. Perhaps a stupid question, But is it possible to embed malware in an mp3? Thanks ever so much for all your help Oldman! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4582 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 9/09/2010 10:51:04 PM mbam-log-2010-09-09 (22-51-04).txt Scan type: Quick scan Objects scanned: 139634 Time elapsed: 3 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\YXE7DXCQ37 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi forgottenv,

The OTL fix log can be found at C:\_OTL\MovedFiles It will have a file name consisting of numders that reflect the date and time stamp the fix was ran. It will be something similar to 09092010_111009.log . Please copy and paste the contents into your next reply.

As for the computer, Since the infection windows explorer has crashed and restarted itself 3 times. A minor inconvenience but it never happened before, Was wondering if the two were connected?

Is this still happening?

And incidentally I only ever use limewire for mp3s. Perhaps a stupid question, But is it possible to embed malware in an mp3?

Would appear so.
http://readerszone.com/security/mp3-files-…-to-mcafee.html

After all a file is a file and can contain almost anything. The filename is meaningless as it can be changed.
http://www.ehow.com/how_6822088_tell-mp3-f…cted-virus.html


Let's see how it looks now.

  • Right click on OTL.exe and select "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the Custom Scan/Fixes box at the bottom copy and paste the following bold text

    /md5start
    explorer.exe
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt (no Extras.Txt this time.)

Please post the MBAM log that you said removed 120 items, it may show something related to the explorer problem.

Open MBAM
  • Click on the Logs tab
  • Click on the log you want to view and click Open
Please copy and paste the contents into your next reply.

Please post back with
  • OTL fix log
  • OTL.txt
  • MBAM log
Thanks
Thanks for cleaning up my accidental double post. …Whoops :blush:

And yes, Its still happening. It's happened twice within the last 20 minutes…

OTL fix log:

All processes killed
========== REGISTRY ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoFolderOptions deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found.
File F:\Support\AutoRun\AutoRun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File G:\Autorun.exe not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Vincent Pinto\Desktop\cmd.bat deleted successfully.
C:\Users\Vincent Pinto\Desktop\cmd.txt deleted successfully.
File\Folder C:\Users\VINCEN~1\AppData\Local\Temp\rnmxesocaw.exe not found.
File\Folder C:\Users\VINCEN~1\AppData\Local\Temp\sraonecxmw.exe not found.
File\Folder C:\Users\Vincent Pinto\AppData\Local\Temp\Ox7.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Vincent Pinto
->Temp folder emptied: 3634509 bytes
->Temporary Internet Files folder emptied: 45748270 bytes
->Java cache emptied: 51144598 bytes
->FireFox cache emptied: 118769731 bytes
->Flash cache emptied: 294850 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 8182188 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50333 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 217.00 mb

Error creating restore point.

OTL by OldTimer - Version 3.2.11.0 log created on 09092010_223901

Files\Folders moved on Reboot…
C:\Users\Vincent Pinto\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

Registry entries deleted on Reboot…

————————————————————————————

OTL:

OTL logfile created on: 11/09/2010 8:29:29 PM - Run 2
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Vincent Pinto\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

12.00 Gb Total Physical Memory | 8.00 Gb Available Physical Memory | 68.00% Memory free
24.00 Gb Paging File | 20.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.08 Gb Total Space | 328.17 Gb Free Space | 55.06% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 671.64 Gb Free Space | 72.10% Space Free | Partition Type: NTFS
Drive E: | 1397.14 Gb Total Space | 299.05 Gb Free Space | 21.40% Space Free | Partition Type: NTFS
Unable to calculate disk information.
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHAOS_MKII
Current User Name: Vincent Pinto
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Vincent Pinto\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation)
PRC - C:\Users\Vincent Pinto\My Documents\G15\SirReal\LCDSirReal.exe ()
PRC - C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Common Files\microsoft shared\ink\TabTip32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Vincent Pinto\AppData\Local\FLVService\lib\FLVSrvLib.dll (Applian Technologies, Inc.)
MOD - C:\Users\Vincent Pinto\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Logitech\SetPoint\x86\GameHook.dll (Logitech, Inc.)
MOD - C:\Program Files\Logitech\SetPoint\x86\lgscroll.dll (Logitech, Inc.)
MOD - C:\Program Files (x86)\Common Files\microsoft shared\ink\tiptsf.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_d08a205e442db5b
5\msvcr80.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (PnkBstrA) – C:\Windows\SysNative\PnkBstrA.exe File not found
SRV:64bit: - (TabletServiceWacom) – C:\Windows\SysNative\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (UmRdpService) – C:\Windows\SysNative\umrdp.dll (Microsoft Corporation)
SRV:64bit: - (StorSvc) – C:\Windows\SysNative\StorSvc.dll (Microsoft Corporation)
SRV:64bit: - (PeerDistSvc) – C:\Windows\SysNative\PeerDistSvc.dll (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (CscService) – C:\Windows\SysNative\cscsvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (aspnet_state) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_64) – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (Microsoft Office Groove Audit Service) – C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (WLSetupSvc) – C:\Program Files (x86)\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files (x86)\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (vmm) – C:\Windows\SysNative\drivers\VMM.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (LGVirHid) – C:\Windows\SysNative\drivers\LGVirHid.sys (Logitech Inc.)
DRV:64bit: - (LGBusEnum) – C:\Windows\SysNative\drivers\LGBusEnum.sys (Logitech Inc.)
DRV:64bit: - (UsbserFilt) – C:\Windows\SysNative\drivers\usbser_lowerfltx64j.sys (Nokia)
DRV:64bit: - (nmwcdcx64) – C:\Windows\SysNative\drivers\ccdcmbox64.sys (Nokia)
DRV:64bit: - (upperdev) – C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys (Nokia)
DRV:64bit: - (nmwcdx64) – C:\Windows\SysNative\drivers\ccdcmbx64.sys (Nokia)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (vmbus) – C:\Windows\SysNative\drivers\vmbus.sys (Microsoft Corporation)
DRV:64bit: - (storflt) – C:\Windows\SysNative\drivers\vmstorfl.sys (Microsoft Corporation)
DRV:64bit: - (storvsc) – C:\Windows\SysNative\drivers\storvsc.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (usbser) – C:\Windows\SysNative\drivers\usbser.sys (Microsoft Corporation)
DRV:64bit: - (s3cap) – C:\Windows\SysNative\drivers\vms3cap.sys (Microsoft Corporation)
DRV:64bit: - (VMBusHID) – C:\Windows\SysNative\drivers\VMBusHID.sys (Microsoft Corporation)
DRV:64bit: - (CSC) – C:\Windows\SysNative\drivers\csc.sys (Microsoft Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (VPCNetS2) – C:\Windows\SysNative\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Windows ® Server 2003 DDK provider)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ninemsn.com.au/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 23 4F 75 52 B9 50 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.enabled: false

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/08/29 04:10:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/09/09 22:36:47 | 000,000,000 | —D | M]

[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions
[2009/12/30 21:45:28 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/09/11 20:07:53 | 000,000,000 | —D | M] – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Freecorder Toolbar) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/19 18:31:08 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/05/29 20:54:29 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/04/15 17:28:51 | 000,002,746 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\ebaycomau.xml
[2010/04/08 05:43:32 | 000,002,057 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\Mozilla\Firefox\Profiles\yhidnb7o.default\searchplugins\youtube-video-search.xml
[2010/09/11 20:07:53 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/09/09 22:36:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/16 19:36:46 | 000,001,538 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/07/16 19:36:46 | 000,000,947 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/07/16 19:36:46 | 000,000,769 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/07/16 19:36:46 | 000,001,135 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/05/15 03:40:20 | 000,000,875 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files (x86)\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - Reg Error: Key error. - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/09/09 22:39:01 | 000,000,000 | —D | C] – C:\_OTL
[2010/09/09 22:37:08 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/09/09 22:37:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/09/09 22:36:47 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2010/09/09 22:36:47 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2010/09/09 22:36:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2010/09/09 22:36:47 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2010/09/09 19:46:48 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:40:17 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\Desktop\backups
[2010/09/08 22:17:08 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 00:22:33 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Local\Windows Server
[2010/09/08 00:22:26 | 000,000,000 | —D | C] – C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107
[2010/08/31 00:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Lame for Audacity
[2010/08/25 22:16:24 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll

========== Files - Modified Within 30 Days ==========

[2010/09/11 20:29:44 | 003,932,160 | -HS- | M] () – C:\Users\Vincent Pinto\NTUSER.DAT
[2010/09/11 19:54:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/11 13:49:52 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/11 13:49:52 | 000,020,512 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/11 13:40:14 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/11 13:40:05 | 1071,738,878 | -HS- | M] () – C:\hiberfil.sys
[2010/09/10 17:41:56 | 002,084,535 | -H– | M] () – C:\Users\Vincent Pinto\AppData\Local\IconCache.db
[2010/09/10 04:54:31 | 000,634,130 | —- | M] () – C:\Users\Public\Documents\Thorns of the Roses.png
[2010/09/09 19:46:52 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\Vincent Pinto\Desktop\OTL.exe
[2010/09/09 19:44:12 | 000,080,384 | —- | M] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/08 22:16:50 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Vincent Pinto\Desktop\HiJackThis.exe
[2010/09/08 21:36:51 | 000,782,154 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/09/08 21:36:51 | 000,668,918 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/09/08 21:36:51 | 000,126,634 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/09/08 05:42:02 | 000,010,921 | —- | M] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:55 | 006,363,136 | —- | M] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:32:10 | 004,434,836 | —- | M] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/03 21:12:02 | 000,078,522 | —- | M] () – C:\Windows\SysWow64\cid_store.dat
[2010/09/03 19:10:49 | 000,000,026 | —- | M] () – C:\Windows\SysWow64\xlhcc.dat
[2010/09/02 02:58:35 | 000,029,580 | —- | M] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | M] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 15:24:46 | 000,149,911 | —- | M] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/08/29 02:31:17 | 000,002,014 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/08/17 19:33:28 | 000,000,224 | —- | M] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/08/17 19:33:27 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini

========== Files Created - No Company Name ==========

[2010/09/10 04:54:29 | 000,634,130 | —- | C] () – C:\Users\Public\Documents\Thorns of the Roses.png
[2010/09/09 19:44:10 | 000,080,384 | —- | C] () – C:\Users\Vincent Pinto\Desktop\MBRCheck.exe
[2010/09/08 05:41:50 | 000,010,921 | —- | C] () – C:\Users\Vincent Pinto\Documents\New Microsoft Office Word Document.docx
[2010/09/04 04:41:19 | 006,363,136 | —- | C] () – C:\Users\Vincent Pinto\Documents\23 - Emiya -Kenji Kawai ver.-.mp3
[2010/09/04 04:30:04 | 004,434,836 | —- | C] () – C:\Users\Vincent Pinto\Documents\Fate_Stay Night OST - Emiya.mp3
[2010/09/02 02:58:34 | 000,029,580 | —- | C] () – C:\Users\Vincent Pinto\Documents\Peace being epic or something.docx
[2010/09/02 01:44:57 | 000,141,994 | —- | C] () – C:\Users\Public\Documents\T.T.T C2.jpg
[2010/09/01 14:41:21 | 000,149,911 | —- | C] () – C:\Users\Public\Documents\T.T.T C1.jpg
[2010/06/11 21:28:23 | 000,001,456 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/05/25 22:48:53 | 000,000,224 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\default.rss
[2010/05/25 22:48:40 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010/05/15 04:21:30 | 000,000,132 | —- | C] () – C:\Users\Vincent Pinto\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/04/05 07:46:19 | 000,003,584 | —- | C] () – C:\Users\Vincent Pinto\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/14 23:00:44 | 000,769,110 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/01/29 22:57:12 | 000,003,088 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/01/29 22:57:12 | 000,000,008 | RHS- | C] () – C:\ProgramData\8AFF345C7D.sys
[2009/12/24 14:33:06 | 000,146,432 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/12/24 14:33:06 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/14 09:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 07:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== Custom Scans ==========



< MD5 for: EXPLORER.EXE >
[2009/07/14 11:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\SysWOW64\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\SysWOW64\explorer.exe
[2009/10/31 15:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2009/10/31 16:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=41B469C2933A478A9A2F9D10EE160033 – C:\Windows\explorer.exe
[2009/08/03 16:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2009/10/31 16:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 15:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2009/10/31 16:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 15:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/14 11:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 16:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/08/03 16:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:9D1B94FD
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:2B19EBF3
< End of report >

———————————————

Original MBAM Log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4555

Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385

8/09/2010 1:49:00 AM
mbam-log-2010-09-08 (01-49-00).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 799824
Time elapsed: 1 hour(s), 18 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 59
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 68

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b1ba40a2-75f2-51bd-f413-04b13a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b1ba40a2-75f2-51bd-f413-04b13a2c8953} (Trojan.Ertfor) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\nofolderoptions (Hijack.FolderOptions) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ewrgetuj (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlhb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlhb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkic (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlkic (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlmoc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlmoc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlna (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlna (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejloc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejloc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlotc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlotc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlppf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlppf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlprc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlprc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqf (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqvc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlqvc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlrxc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlrxc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlswc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlswc (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlyr (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lvsvpiejlyr (Malware.Packer.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mediafix70700en02.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpe (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqpsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqqyc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqrtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqrtc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqsz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqsz (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqtw+ (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqurb (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvpc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mqvsc (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Vincent Pinto\AppData\Local\Temp\e55z4uf.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\Local Settings\Application Data\Windows Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\winamp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\avp32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\crhnici.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\mdm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\login.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\b26ayz45.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\cmd.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\hwblyxbm.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\le4f7z.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\knam.exe (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Windows\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\nwcemxasro.exe (Trojan.Bamital.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\install.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox4.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\services.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\nvsvc32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\scraxomwen.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\spoolsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\wininst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\uo43hs4q88ntx8.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\wininst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\tmvxmfu.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Windows\System32\o67e8k4fzw.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\win.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\csrss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\av4wkpm.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Windows\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\tujserrew.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Roaming\D52C82E4F8474F02F12730D6FFE8B107\mediafix70700en02.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\hexdump.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\geurge.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\o67e8k4fzw.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\maeswornxc.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\winlogon.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN03YMSO\mqupjickr[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RSMDAJ11\nezgb[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\user.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YDZFHJAN\mqupjickr[1].htm (Rogue.SecuritySuite) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox5.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\bl8v3uxpa.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\d3qxn7rt.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\sxcfgslr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\iexplorer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\ikjuc0.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Windows\Oqocaa.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\av4wkpm.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\mx8abzcoxfg.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\rph4gsb2.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\orhck4ecq8ydss.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox3.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\rph4gsb2.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Windows\SysWOW64\uk19rr.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\Ox6.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\skaioejiesfjoee.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Temp\thuurs.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EN03YMSO\cgbvd[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\uk19rr.dll (Trojan.Ertfor) -> Quarantined and deleted successfully.
C:\Users\Vincent Pinto\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUDNHL4E\mediafix70700en02[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
Hi forgottenv,

Anything particular you are doing when explorer crashes? Does it just shut down and restart?

Any error messages?

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    C:\Windows\explorer.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Thanks
Okay! I worked it out!

For some reason, Windows explorer is crashing whenever I get a balloon tip from the taskbar.
Like one of these

So now I know what causes it, what should I do? Repair windows from the CD?

Thanks so much again for your ongoing help! :notworthy:
Alrighty-then…

Heres the results:

VirSCAN.org Scanned Report :
Scanned time : 2010/09/16 22:10:56 (EST)
Scanner results: Scanners did not find malware!
File Name : explorer.exe
File Size : 2870272 byte
File Type : PE32+ executable for MS Windows (GUI)
MD5 : 41b469c2933a478a9a2f9d10ee160033
SHA1 : 15b40fd56042461bd47d6108ff822427e9d877fd
Online report : http://virscan.org/report/f47b41668ba4d40b…72c2fbb96d.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.19 20100916022003 2010-09-16 40.09 -
AhnLab V3 2010.09.16.01 2010.09.16 2010-09-16 40.09 -
AntiVir 8.2.4.52 7.10.11.192 2010-09-16 0.27 -
Antiy 2.0.18 20100914.5155144 2010-09-14 0.02 -
Arcavir 2009 201006281601 2010-06-28 0.00 -
Authentium 5.1.1 201009160641 2010-09-16 1.29 -
AVAST! 4.7.4 100916-0 2010-09-16 0.12 -
AVG 8.5.850 271.1.1/3138 2010-09-16 0.27 -
BitDefender 7.90123.6387262 7.33909 2010-09-16 4.54 -
ClamAV 0.96.1 11937 2010-09-16 0.74 -
Comodo 4.0 6093 2010-09-16 40.09 -
CP Secure 1.3.0.5 2010.09.16 2010-09-16 0.51 -
Dr.Web 5.0.2.3300 2010.09.16 2010-09-16 9.24 -
F-Prot 4.4.4.56 20100916 2010-09-16 1.31 -
F-Secure 7.02.73807 2010.09.16.03 2010-09-16 3.44 -
Fortinet 4.1.143 12.356 2010-09-15 5.61 -
GData 21.846/21.334 20100916 2010-09-16 40.09 -
ViRobot 20100915 2010.09.15 2010-09-15 40.09 -
Ikarus T3.1.32.15.0 2010.09.16.76739 2010-09-16 4.69 -
JiangMin 13.0.900 2010.08.30 2010-08-30 40.09 -
Kaspersky 5.5.10 2010.09.16 2010-09-16 0.08 -
KingSoft 2009.2.5.15 2010.9.16.18 2010-09-16 40.09 -
McAfee 5400.1158 6107 2010-09-15 18.79 -
Microsoft 1.6103 2010.09.16 2010-09-16 40.09 -
Norman 6.06.05 6.06.00 2010-09-15 8.01 -
Panda 9.05.01 2010.09.15 2010-09-15 40.09 -
Trend Micro 9.120-1004 7.466.05 2010-09-16 0.03 -
Quick Heal 11.00 2010.09.16 2010-09-16 40.09 -
Rising 20.0 22.65.02.04 2010-09-15 40.09 -
Sophos 3.11.2 4.57 2010-09-16 4.12 -
Sunbelt 3.9.2447.2 6880 2010-09-15 40.09 -
Symantec 1.3.0.24 20100915.002 2010-09-15 3.28 -
nProtect 20100914.01 9109121 2010-09-14 40.10 -
The Hacker [removed] v00020 2010-09-15 40.09 -
VBA32 3.12.14.0 20100916.0849 2010-09-16 2.89 -
VirusBuster 4.5.11.10 10.128.3/2048942 2010-09-16 3.30 -
Hi forgottenv,

Is it any tool tip ballon or a specific one?

You try this

To Run the SFC /SCANNOW Command
  • Click your start button > All Programs > Accessories
  • then right click on Command Prompt and click on Run as administrator
  • In the elevated command prompt, type sfc /scannow and press Enter


    Note
    there is one space after sfc (see image)

    [external image: Posted Image]
It may take a while so please be patient.

Let us know if sfc found anything and if the problem still persists.

Thanks
Okay, I ran sfc /scannow and it found some corrupted files. It also said there were some it couldnt repair for some reason… Regardless, It fixed the issue! windows explorer isn't crashing from the popups anymore. Do you think those "other files" could be an issue? would you like the log it left me?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI