This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

College son home - wants new PC - PC is slow and freezes

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello again! My son is home for Thanksgiving, and wants a new PC because his is so slow and freezes up unexpectedly. I'd like to clean it up first - rather than buy a PC - it's only 15 months old. I am hesitant to try to clean it up on my own. Can you assist? I appreciate any help you can give - thank you in advance!

Sara

Here are the OTL files:

OTL.txt:

OTL logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Pat\Downloads\OTL(3).exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (alssvc) – C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NvtSp50) – C:\Windows\System32\Drivers\NvtSp50.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (HECI) Intel® – C:\Windows\system32\drivers\heci.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (WavxDMgr) – C:\Windows\System32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (cvusbdrv) – C:\Windows\System32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rixdpcie) – C:\Windows\system32\drivers\rixdpe86.sys (REDC)
DRV - (risdpcie) – C:\Windows\system32\drivers\risdpe86.sys (REDC)
DRV - (rimspci) – C:\Windows\system32\drivers\rimspe86.sys (REDC)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (PBADRV) – C:\Windows\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.adultswim.com/shows/metalocalyp…tour/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.timanderic.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50-ff-aim-ab-en-us&query="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/01 17:25:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/11 11:33:34 | 000,000,000 | —D | M]

[2009/10/02 00:52:54 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Extensions
[2010/11/21 11:47:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions
[2009/10/02 10:34:02 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/03 22:53:12 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/18 01:02:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\[removed]
[2009/11/03 22:53:17 | 000,004,554 | —- | M] () – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\searchplugins\aim-search.xml
[2009/10/02 00:52:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/08/03 04:11:58 | 000,094,208 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/09/03 15:20:16 | 000,000,051 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2001/08/03 04:11:58 | 000,094,208 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.divxa32 - C:\Windows\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/11/15 15:21:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/11/15 09:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2010/11/15 09:49:56 | 000,000,000 | —D | C] – C:\Users\Pat\Documents\Vindictus
[2010/11/15 09:47:05 | 000,000,000 | —D | C] – C:\Program Files\BandiMPEG1
[2010/10/27 09:43:59 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/27 09:43:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 09:37:28 | 000,258,536 | —- | C] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/27 09:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Screentime
[2010/10/27 09:37:20 | 000,000,000 | —D | C] – C:\Users\Pat\AppData\Local\Screentime
[2010/10/24 02:21:20 | 000,000,000 | —D | C] – C:\Users\Pat\Desktop
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/21 20:17:41 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/21 20:01:01 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/21 19:45:31 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/21 11:40:20 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/21 11:40:20 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/21 11:35:47 | 000,000,000 | —- | M] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2010/11/21 11:35:42 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:27 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2010/11/18 19:39:26 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/17 19:05:39 | 000,001,536 | —- | M] () – C:\Users\Pat\Contacts\Desktop\NO$GBA.INP
[2010/11/17 18:23:52 | 000,008,268 | —- | M] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2010/11/15 15:21:39 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/11/15 09:47:06 | 000,000,207 | —- | M] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/27 09:37:28 | 000,258,536 | —- | M] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/26 19:44:15 | 000,000,295 | —- | M] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/10/24 02:01:41 | 000,012,288 | —- | M] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/15 09:47:06 | 000,000,207 | —- | C] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/26 19:44:15 | 000,000,295 | —- | C] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/07/02 19:35:00 | 000,056,320 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2010/07/02 19:28:22 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/30 20:12:11 | 000,000,208 | —- | C] () – C:\Windows\TLCAPPS.INI
[2010/06/30 20:11:31 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2010/05/18 12:16:03 | 000,065,536 | —- | C] () – C:\Windows\System32\HPPLVS.dll
[2010/05/11 11:02:13 | 000,000,552 | —- | C] () – C:\Users\Pat\AppData\Local\d3d8caps.dat
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\Users\Pat\AppData\Local\ru6R
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\ProgramData\ru6R
[2009/10/07 12:48:46 | 000,008,268 | —- | C] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/08/31 18:43:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/30 13:01:10 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/08/07 21:30:08 | 000,000,036 | -H– | C] () – C:\Windows\System32\swk.ini
[2009/08/07 21:27:49 | 000,012,288 | —- | C] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/01 13:13:07 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/01 13:05:21 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/01 10:06:42 | 000,000,000 | —- | C] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2009/07/27 20:32:24 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/07/27 20:21:57 | 000,279,888 | —- | C] () – C:\Windows\System32\brcmbsp.dll
[2009/07/27 20:19:21 | 000,080,368 | —- | C] () – C:\Windows\System32\pbadrvdll.dll
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/04/22 08:58:30 | 000,126,976 | —- | C] () – C:\Windows\System32\DTMessageLib.dll
[2009/04/10 11:01:12 | 000,143,360 | R— | C] () – C:\Windows\System32\preflib.dll
[2009/02/26 15:54:52 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_tr.dll
[2009/02/26 15:54:50 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_ro.dll
[2009/02/26 15:54:48 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt-BR.dll
[2009/02/26 15:54:48 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_hu.dll
[2009/02/26 15:54:46 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_he.dll
[2009/02/26 15:54:44 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_el.dll
[2009/02/26 15:54:44 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_fi.dll
[2009/02/26 15:54:42 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_cs.dll
[2009/02/26 15:54:40 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_ar.dll
[2009/02/26 15:54:40 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHT.dll
[2009/02/26 15:54:38 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHS.dll
[2009/02/26 15:54:36 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_sv.dll
[2009/02/26 15:54:34 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt.dll
[2009/02/26 15:54:34 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_ru.dll
[2009/02/26 15:54:32 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pl.dll
[2009/02/26 15:54:32 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_no.dll
[2009/02/26 15:54:30 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_nl.dll
[2009/02/26 15:54:28 | 000,090,112 | —- | C] () – C:\Windows\System32\Internationalization_ja.dll
[2009/02/26 15:54:28 | 000,086,016 | —- | C] () – C:\Windows\System32\Internationalization_ko.dll
[2009/02/26 15:54:26 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_it.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_fr.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_es.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_de.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_da.dll
[2009/02/17 08:51:28 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_es.dll
[2009/02/17 08:51:28 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_en.dll
[2009/02/17 08:51:26 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_fr.dll
[2009/02/17 08:51:24 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_it.dll
[2009/02/17 08:51:24 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_ja.dll
[2009/02/17 08:51:24 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_ko.dll
[2009/02/17 08:51:22 | 000,565,248 | —- | C] () – C:\Windows\System32\AmRes_ru.dll
[2009/02/17 08:51:22 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_pt-BR.dll
[2009/02/17 08:51:20 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_fi.dll
[2009/02/17 08:51:20 | 000,479,232 | —- | C] () – C:\Windows\System32\AmRes_zh-CHT.dll
[2009/02/17 08:51:20 | 000,475,136 | —- | C] () – C:\Windows\System32\AmRes_zh-CHS.dll
[2009/02/17 08:51:18 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_da.dll
[2009/02/17 08:51:16 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_nl.dll
[2009/02/17 08:51:16 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_pl.dll
[2009/02/17 08:51:16 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_no.dll
[2009/02/17 08:51:14 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_sv.dll
[2009/02/17 08:51:04 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_cs.dll
[2009/02/17 08:51:04 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_ar.dll
[2009/02/17 08:51:02 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_el.dll
[2009/02/17 08:51:02 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_he.dll
[2009/02/17 08:51:00 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_pt-PT.dll
[2009/02/17 08:51:00 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_hu.dll
[2009/02/17 08:50:58 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_ro.dll
[2009/02/17 08:50:58 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_tr.dll
[2009/02/17 07:46:36 | 000,544,768 | —- | C] () – C:\Windows\System32\AmRes_de.dll
[2009/01/06 15:25:36 | 000,010,752 | —- | C] () – C:\Windows\System32\Wavx_ESC_Logging.dll
[2008/12/22 13:13:54 | 000,249,856 | —- | C] () – C:\Windows\System32\wxvault.dll
[2008/10/06 17:36:56 | 000,839,680 | —- | C] () – C:\Windows\System32\DemoLicense.dll
[2008/03/25 08:46:00 | 000,077,536 | —- | C] () – C:\Windows\System32\xltZlib.dll
[2007/04/19 04:52:16 | 000,080,720 | —- | C] () – C:\Windows\System32\AsfBios.dll
[2007/04/19 04:28:10 | 000,025,424 | —- | C] () – C:\Windows\System32\drivers\netamsg.dll
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/30 11:58:44 | 000,176,128 | R— | C] () – C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 11:58:44 | 000,126,976 | R— | C] () – C:\Windows\System32\bioapi100.dll
[2004/09/10 12:34:00 | 000,917,504 | —- | C] () – C:\Windows\System32\lmgr10.dll
[2004/09/10 12:34:00 | 000,057,344 | —- | C] () – C:\Windows\System32\ADsSecurity.dll

========== LOP Check ==========

[2009/11/03 22:45:29 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\acccore
[2009/08/01 10:06:40 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Broadcom
[2010/11/21 20:25:28 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\DNA
[2010/10/24 02:21:23 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\GetRightToGo
[2010/02/08 22:59:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\NeopleLauncherDFO
[2009/10/24 20:33:13 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Recruitment Viewer
[2009/08/01 10:06:58 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Wave Systems Corp
[2010/11/21 02:15:13 | 000,032,624 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/20 20:34:29 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2009/07/27 22:58:15 | 000,004,848 | RH– | M] () – C:\dell.sdr
[2010/11/21 11:35:13 | 3745,415,168 | -HS- | M] () – C:\hiberfil.sys
[2009/11/03 22:45:18 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2010/05/18 12:17:13 | 000,020,012 | —- | M] () – C:\P1005.log
[2010/11/21 11:35:12 | 4059,037,696 | -HS- | M] () – C:\pagefile.sys
[2009/08/01 13:13:10 | 000,000,272 | —- | M] () – C:\Sonic-and-Knuckles-(JUE)-[!].srm

< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:35:34 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/09/22 10:50:36 | 000,293,888 | —- | M] (Hewlett-Packard ) – C:\Windows\System32\spool\prtprocs\w32x86\HP1006S.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/08/30 13:01:16 | 000,191,488 | —- | M] (ScreenTime Media) – C:\Windows\Final Fantasy VII Advent Children.scr
[2008/12/04 21:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 21:31:11 | 015,716,352 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 21:31:01 | 000,102,400 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 21:31:12 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/07 21:26:27 | 000,000,286 | -HS- | M] () – C:\Users\Pat\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-11 15:11:15

========== Files - Unicode (All) ==========
[2010/11/15 09:52:24 | 000,000,000 | —D | M](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
[2010/11/15 09:52:24 | 000,000,000 | —D | C](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613

< End of report >


extras.txt:

OTL Extras logfile created on: 11/21/2010 8:22:51 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 64.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 58.05 Gb Free Space | 39.52% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2D5CDB5B-24D0-4104-908E-D6B082A02396}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7E88AC9D-D5C0-40DB-ACE6-6401E26B3CCD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{9F8D2359-04C3-4611-98A1-26BF3B933726}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05128281-0438-4E44-BDBE-7FCAA6A03A48}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{1F5BDB5F-427A-4387-A322-0B24057539A2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{23CE22F3-84B8-421D-A12F-5EF235E579D6}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{23FA1FFE-2603-4600-B2D0-DD69F675810E}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{3ECE04F1-553F-4146-8601-41D51B463E8D}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{420F21E6-9FC7-476C-A122-8FCEDB73AAB1}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{5ADCDF6F-293A-4C61-B9C7-5F80B70C7BE5}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{641BA14C-3609-4E3D-93F6-DC68CB78B019}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{69062C4B-C3A0-4C7A-BBD9-0F4B68E7BC1D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{712C0BCD-E2C0-4911-8C6F-C146F244B4C0}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{8C5AF45F-CC6D-434E-A21B-95799617B9F2}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\hp1006mc.exe |
"{91F5B763-B607-4432-AF65-B952E03484F7}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{B935B986-C31C-4672-B1E5-10A13CB4A13D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BF6C7D7F-0306-451D-BFEA-74225DDB862A}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{C4C34B1B-6F9A-410D-86CC-6E366187AF33}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C78631D8-6EAC-49F7-A9C4-EA5A9D43751B}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{CD88E44B-7724-4AD8-A33A-0C283A6E879C}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{D41B1B59-ECE4-4A94-ACF5-0D090198F49B}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{D65C970B-CC58-44D6-9D28-2DB1F9FC80AD}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D90BC12F-5C7E-4775-B99C-98474E032BC8}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F914F5B0-16BF-4E59-BB3B-C180244204FA}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{FECBC724-A526-4E10-A650-BE1B085EB0FE}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"TCP Query User{0E6CC991-DFA1-4E7C-9EC1-D566616DC538}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"TCP Query User{203E858A-550D-4152-B8A0-BA61D4A7CCE5}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=6 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"TCP Query User{3C3E48B0-EE80-45C0-B50D-767B0E3705BA}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=6 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |
"TCP Query User{42B96B34-23A3-48F6-8BAF-5ED69CC75A92}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"TCP Query User{8FCD378D-E8AE-4358-8DAF-FC4FCF81EF4B}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{B1903BA0-C013-4097-8F78-3970B0EADE9F}C:\users\pat\program files\dna\btdna.exe" = protocol=6 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"TCP Query User{EDBA7BAE-DEA5-4A92-A368-FD71C705C4FB}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=6 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{025BF687-FFAE-43CE-A167-E44036761C61}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds.exe |
"UDP Query User{0A89863C-14FC-4F46-9456-9C4219566277}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{3477C977-4216-4D9B-BB6E-ED319E0A5A4D}C:\nexon\vindictus\en-us\nmservice.exe" = protocol=17 | dir=in | app=c:\nexon\vindictus\en-us\nmservice.exe |
"UDP Query User{655E4FE9-75C0-4996-9019-3BFF8C3D5EA4}C:\users\pat\program files\dna\btdna.exe" = protocol=17 | dir=in | app=c:\users\pat\program files\dna\btdna.exe |
"UDP Query User{78B8CB36-8117-47A1-8663-70F472E6BE88}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{7F9800BB-CB29-42FB-B0DB-0E0BC94A4030}C:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe" = protocol=17 | dir=in | app=c:\program files\lucasarts\star wars galactic battlegrounds saga\game\battlegrounds_x1.exe |
"UDP Query User{90F59E27-A25B-4279-8BAB-5AF6046F3F95}C:\users\pat\contacts\desktop\age of mythology\aom.exe" = protocol=17 | dir=in | app=c:\users\pat\contacts\desktop\age of mythology\aom.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{0394CDC8-FABD-4ED8-B104-03393876DFDF}" = Roxio Creator Tools
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{07159635-9DFE-4105-BFC0-2817DB540C68}" = Roxio Activation Module
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"{0D397393-9B50-4C52-84D5-77E344289F87}" = Roxio Creator Data
"{10133CDD-50B9-4783-B336-8B48F3653715}" = Star Wars Galactic Battlegrounds: Saga
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2220CF3A-EBD6-4070-94D0-0C7337B537A7}" = All Day Battery Life Configuration
"{2223FC2F-B862-4F83-BC9E-DDF2DADF2859}" = Intel® Network Connections 13.0.42.0
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2484631E-A7B3-4847-ACBB-4D881E6E9D5A}" = Dell ControlPoint Connection Manager
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4994A7CB-2BF4-4664-8FCE-DB66055ECEBC}" = Broadcom USH Host Components
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"{51D386C4-0227-46A9-AC45-61F0A50E7AFF}" = Rome - Total War
"{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"{5AF4F4C5-C71C-418F-B0B1-3903A345BD71}" = Ambient Light Sensor
"{619CDD8A-14B6-43A1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{67436268-FB14-4DFB-AE73-1B1EFA2B0213}" = Dell ControlPoint System Manager
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6D3963B0-E13B-4FC3-B0FF-506A304BB043}" = Cisco EAP-FAST Module
"{6EA8A52B-8EA1-4A59-85AB-48132299061A}" = Intel® PRO Alerting Agent
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{83FFCFC7-88C6-41C6-8752-958A45325C82}" = Roxio Creator Audio
"{86A8FD76-3268-4102-9674-7118881EC2C0}" = Wave Infrastructure Installer
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9593C6E5-205E-45C3-B785-05CF146CA76A}" = biolsp patch
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{99E39418-A6C1-4D2B-AF9F-9152C93F03A9}" = Dell Control Point
"{99ECF41F-5CCA-42BD-B8B8-A8333E2E2944}" = iTunes
"{9BCAC864-84C0-409F-8D12-364109622D18}_is1" = Europa Barbarorum 1.1
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}" = Trusted Drive Manager
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Embassy Trust Suite by Wave Systems
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF7E4468-E364-4991-BC2A-6E8293E1055B}" = BioAPI Framework
"{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"{BB93D30B-B395-44BB-A9ED-A0E057F07E53}" = NTRU TCG Software Stack
"{BC52E419-B185-488F-9973-049A88E5DCBE}" = Gemalto
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C337BDAF-CB4E-47E2-BE1A-CB31BB7DD0E3}" = Apple Mobile Device Support
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{DAC07FB2-2C63-44B2-8344-AB7542C936D2}" = DCP32MMWrapper
"{DB58A549-42CA-4081-986A-633479DE413F}" = SO32MMWrapper
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.0
"{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F4487649-7368-4217-AEA3-1E04DB3E2C5C}" = Dell ControlPoint Security Manager
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF1DDCF4-3A28-4F7F-96D8-E3F4BD1C1702}" = Dell Security Device Driver Pack
"9D57DE505B6D8C710EF3B74BE638DBB936EED8A3" = Windows Driver Package - Dell Inc. PBADRV System (01/07/2008 1.0.1.5)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AdventureTime_Screensaver" = AdventureTime_Screensaver
"AIM Toolbar" = AIM Toolbar
"avast5" = avast! Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility
"CleanUp!" = CleanUp!
"Creative OA001" = Integrated Webcam Driver (1.06.03.0309)
"Defraggler" = Defraggler
"Dell Webcam Central" = Dell Webcam Central
"DFO" = DFOLauncher
"DVD Player_is1" = DVD Player 1.0
"EB Documentation_is1" = EB Documentation 1.1
"EB Trivial Script_is1" = EB Trivial Script 0.125
"Final Fantasy VII Advent Children" = Final Fantasy VII Advent Children?????????
"GOM Player" = GOM Player
"InstallShield_{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software
"InstallShield_{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager
"InstallShield_{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}" = Document Manager Lite
"InstallShield_{53333479-6A52-4816-8497-5C52B67ED339}" = EMBASSY Security Setup
"InstallShield_{B7A9964C-A9A7-4714-B494-50067238876E}" = Fantasy Earth Zero
"InstallShield_{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}" = Secure Update
"InstallShield_{E738A392-F690-4A9D-808E-7BAF80E0B398}" = ESC Home Page Plugin
"InstallShield_{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}" = Security Wizards
"InstallShield_{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"NVIDIA Drivers" = NVIDIA Drivers
"PROR" = Microsoft Office Professional 2007 Trial
"PROSetDX" = Intel® Network Connections 13.0.42.0
"Recruitment Viewer_is1" = Recruitment Viewer 0.9
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Sonic and Knuckles 2_is1" = Sonic and Knuckles 2 1.0
"Sonic and Knuckles 3_is1" = Sonic and Knuckles 3 1.0
"Sonic and Knuckles_is1" = Sonic and Knuckles
"Vindictus" = Vindictus
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/15/2010 5:46:17 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/15/2010 5:47:01 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM

Error - 4/15/2010 5:47:02 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM

Error - 4/16/2010 2:24:34 AM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =

Error - 4/16/2010 3:45:57 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/16/2010 3:46:05 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM

Error - 4/16/2010 3:46:07 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM

Error - 4/16/2010 8:03:08 PM | Computer Name = Pat-PC | Source = EventSystem | ID = 4622
Description =

Error - 4/16/2010 8:04:14 PM | Computer Name = Pat-PC | Source = WinMgmt | ID = 10
Description =

Error - 4/16/2010 8:04:40 PM | Computer Name = Pat-PC | Source = Wave TCG Client Services | ID = 123
Description = The NTRU TSS is not running, Wave Software is unable to communicate
to TPM

[ Broadcom Wireless LAN Events ]
Error - 11/21/2010 3:56:00 AM | Computer Name = Pat-PC | Source = WLAN-Tray | ID = 0
Description = 01:56:00, Sun, Nov 21, 10 Error - Unable to gain access to user store


[ System Events ]
Error - 11/19/2010 12:55:34 AM | Computer Name = PAT-PC | Source = Service Control Manager | ID = 7001
Description =

Error - 11/19/2010 12:55:30 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/19/2010 10:39:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/20/2010 1:51:01 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:07:53 PM on 11/19/2010 was unexpected.

Error - 11/20/2010 1:51:09 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/20/2010 4:36:45 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/21/2010 3:54:05 AM | Computer Name = Pat-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:31:35 AM on 11/21/2010 was unexpected.

Error - 11/21/2010 3:54:12 AM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/21/2010 1:35:25 PM | Computer Name = Pat-PC | Source = HTTP | ID = 15016
Description =

Error - 11/21/2010 1:35:28 PM | Computer Name = Pat-PC | Source = Service Control Manager | ID = 7001
Description =


< End of report >
:welcome:

You have a few things going on, lets do this.

C:\Users\Pat\Program Files\DNA\btdna.exe (BitTorrent, Inc.) <–Your downloading files from an unknown source , malware writers are using file sharing programs like this to infect computers. I am going to ask you to uninstall this program via Programs and Features in the Control Panel.

c:\Program Files\Microsoft Security Essentials
C:\Program Files\Alwil Software
C:\Program Files\McAfee Security Scan

You have three Anti virus programs running, this will slow your system down to a crawl and cause other issues, personally I have had problems with Microsoft Security Essentials, I would uninstall this one also and Alwil if its the free version. You should only have one good Anti Virus program installed, keep it updated and run scans regularly.



You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again


C:\Windows\System32\iyvu9_32.dll <– This file

If the site is busy you can try this one

http://virusscan.jotti.org/en





Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Post the log its created please





[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks for the help so far. I removed the first program that you suggested, and deleted the virus programs, except for McAfee. When I tried to run McAfee, I got an error message that says the program is not available or I am not connected to the Internet. I tried a few times. Then I uninstalled MCAfee - with the assumption that if the PC had McAfee from a one year ago, it was expired anyway. I re-subscribed to MCAfee and downloaded the program. However, when I tried to install the download, I got the error message that I McAfee is not available or I'm not connected to the Internet again. Something on the PC is preventing McAfee from running. I proceeded with your instructions, in the belief that we have to get this cleaned up if we want to get MCAfee running again. Results of VirusTotal scan of : Antivirus Version Last Update Result AhnLab-V3 2010.11.24.00 2010.11.23 - AntiVir 7.10.14.82 2010.11.23 - Antiy-AVL 2.0.3.7 2010.11.24 - Avast 4.8.1351.0 2010.11.24 - Avast5 5.0.594.0 2010.11.24 - AVG 9.0.0.851 2010.11.24 - BitDefender 7.2 2010.11.24 - CAT-QuickHeal 11.00 2010.11.09 - ClamAV 0.96.4.0 2010.11.24 - Command 5.2.11.5 2010.11.24 - Comodo 6827 2010.11.24 - DrWeb 5.0.2.03300 2010.11.23 - Emsisoft 5.0.0.50 2010.11.24 - eSafe 7.0.17.0 2010.11.23 - eTrust-Vet 36.1.7996 2010.11.23 - F-Prot 4.6.2.117 2010.11.23 - F-Secure 9.0.16160.0 2010.11.24 - Fortinet 4.2.254.0 2010.11.23 - GData 21 2010.11.24 - Ikarus T3.1.1.90.0 2010.11.24 - Jiangmin 13.0.900 2010.11.20 - K7AntiVirus 9.68.3065 2010.11.24 - Kaspersky 7.0.0.125 2010.11.24 - McAfee 5.400.0.1158 2010.11.24 - McAfee-GW-Edition 2010.1C 2010.11.24 - Microsoft 1.6402 2010.11.24 - NOD32 5643 2010.11.23 - Norman 6.06.10 2010.11.24 - nProtect 2010-11-23.02 2010.11.23 - Panda 10.0.2.7 2010.11.23 - PCTools 7.0.3.5 2010.11.24 - Prevx 3.0 2010.11.24 - Rising 22.75.01.03 2010.11.24 - Sophos 4.59.0 2010.11.24 - SUPERAntiSpyware 4.40.0.1006 2010.11.24 - Symantec 20101.2.0.161 2010.11.24 - TheHacker 6.7.0.1.089 2010.11.23 - TrendMicro 9.120.0.1004 2010.11.24 - TrendMicro-HouseCall 9.120.0.1004 2010.11.24 - VBA32 3.12.14.2 2010.11.23 - VIPRE 7395 2010.11.24 - ViRobot 2010.11.20.4158 2010.11.24 - VirusBuster 13.6.56.0 2010.11.23 - Additional information Show all MD5 : 94a8ebd816a366041f8ccf5afd3ab7de SHA1 : 67f28427717228f3b8a21df2a5c7c1532165d63b SHA256: 8d9ae43649ce4ab4963f374be0e13517a52005690cd29dc5c0e44dc0c6a5966b I loaded GMER and unzipped it. Followed directions. (I wasn't sure if you wanted "Show all" checked or unchecked. I left it the way it was - unchecked. Ran GMER, and it stopped - error message said that windows stopped it because there was a problem. When I closed it out, the PC re-booted. I tried to re-run GMER and it stopped again, due to a "problem" detected by windows. Now what?
Hi,

Lets bypass GMER for the time being. You never posted the log that the OTL fix created


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Sorry about the OTL log. I guess I should not stay up until 3 AM. I can't find it anywhere. I know that I copied it, I probably forgot the paste part. Here is the MBAM log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5182 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18975 11/24/2010 9:05:54 AM mbam-log-2010-11-24 (09-05-54).txt Scan type: Quick scan Objects scanned: 144766 Time elapsed: 9 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Also, the PC seems much faster - It was making me very nervous to not have a virus scan installed, so I tired again and got that installed OK. I know you didn't tell me to do that, but I felt that I should. Thanks!
Just go ahead and post a new OTL log, no need to add the script or the extras log

Then try this rootkit scanner

RootRepeal - Rootkit Detector

  • Download RootRepeal from the following location and save it to your desktop.
  • Unzip it to your Desktop
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
    • Shadow SSDT
  • Click the OK button
  • Check the box for your main system drive (Usually C:), and Click OK to start the scan

    The scan can take some time. DO NOT run any other programs while the scan is running
  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
OK Here is a current OTL .txt:

OTL logfile created on: 11/24/2010 11:47:27 AM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 67.58 Gb Free Space | 46.02% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Pat\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Pat\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (alssvc) – C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NvtSp50) – C:\Windows\System32\Drivers\NvtSp50.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (HECI) Intel® – C:\Windows\system32\drivers\heci.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (WavxDMgr) – C:\Windows\System32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (cvusbdrv) – C:\Windows\System32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rixdpcie) – C:\Windows\system32\drivers\rixdpe86.sys (REDC)
DRV - (risdpcie) – C:\Windows\system32\drivers\risdpe86.sys (REDC)
DRV - (rimspci) – C:\Windows\system32\drivers\rimspe86.sys (REDC)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (PBADRV) – C:\Windows\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.adultswim.com/shows/metalocalyp…tour/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://mail.google.com/mail/?hl=en&shva=1#inbox/126fb6d8098ff8e7|http://forums.whatthetech.com/index.php?showforum=27|http://www.timanderic.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/11/24 02:48:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/24 02:24:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/11 11:33:34 | 000,000,000 | —D | M]

[2009/10/02 00:52:54 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Extensions
[2010/11/24 08:05:41 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions
[2009/10/02 10:34:02 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/03 22:53:12 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/18 01:02:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\[removed]
[2009/11/03 22:53:17 | 000,004,554 | —- | M] () – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\searchplugins\aim-search.xml
[2009/10/02 00:52:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/13 22:28:54 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/11/24 08:12:38 | 000,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2010/11/24 01:47:49 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101124022458.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/08/03 04:11:58 | 000,094,208 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/09/03 15:20:16 | 000,000,051 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2001/08/03 04:11:58 | 000,094,208 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/24 08:19:59 | 000,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/11/24 08:10:28 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/11/24 08:10:28 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/11/24 08:10:28 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/11/24 08:10:28 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/11/24 08:10:28 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/11/24 08:10:28 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/11/24 08:10:27 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/11/24 08:10:27 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/11/24 08:10:27 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/11/24 08:10:27 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/11/24 08:10:27 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/11/24 08:10:26 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/11/24 08:10:26 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/11/24 08:10:26 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/11/24 08:10:26 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/11/24 08:10:26 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/11/24 08:10:26 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/11/24 08:09:51 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2010/11/24 08:09:51 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2010/11/24 08:09:50 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2010/11/24 08:09:50 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2010/11/24 08:09:50 | 000,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2010/11/24 08:09:50 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2010/11/24 08:09:50 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2010/11/24 08:09:50 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2010/11/24 08:09:50 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2010/11/24 08:09:49 | 000,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/11/24 08:09:49 | 000,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2010/11/24 08:09:49 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2010/11/24 08:09:49 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2010/11/24 08:09:49 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2010/11/24 08:09:49 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2010/11/24 08:09:48 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2010/11/24 08:09:48 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/11/24 08:09:48 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/11/24 08:09:48 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2010/11/24 08:09:48 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2010/11/24 08:09:47 | 003,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2010/11/24 08:09:47 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2010/11/24 08:09:47 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2010/11/24 08:09:47 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2010/11/24 08:09:47 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2010/11/24 02:24:58 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/11/24 02:24:44 | 000,313,288 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/11/24 02:24:44 | 000,164,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/11/24 02:24:44 | 000,084,264 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/11/24 02:24:44 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/11/24 02:24:43 | 000,152,960 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/11/24 02:24:43 | 000,055,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/11/24 02:24:43 | 000,052,104 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/11/24 02:24:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/11/24 02:24:38 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2010/11/24 02:24:36 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/11/24 02:15:42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2010/11/24 01:46:21 | 000,000,000 | —D | C] – C:\_OTL
[2010/11/15 15:21:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/11/15 09:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2010/11/15 09:49:56 | 000,000,000 | —D | C] – C:\Users\Pat\Documents\Vindictus
[2010/11/15 09:47:05 | 000,000,000 | —D | C] – C:\Program Files\BandiMPEG1
[2010/10/27 09:43:59 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/27 09:43:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 09:37:28 | 000,258,536 | —- | C] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/27 09:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Screentime
[2010/10/27 09:37:20 | 000,000,000 | —D | C] – C:\Users\Pat\AppData\Local\Screentime

========== Files - Modified Within 30 Days ==========

[2010/11/24 11:01:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/24 10:25:34 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/24 10:25:34 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/24 09:58:32 | 000,013,312 | —- | M] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/24 08:51:30 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/24 08:32:45 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/24 08:32:45 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/24 08:28:00 | 000,000,000 | —- | M] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2010/11/24 08:27:56 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/24 08:27:55 | 000,001,737 | —- | M] () – C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2010/11/24 08:27:49 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/24 08:25:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/24 08:25:16 | 3743,338,496 | -HS- | M] () – C:\hiberfil.sys
[2010/11/24 08:19:48 | 000,000,945 | —- | M] () – C:\Users\Pat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/24 02:48:28 | 378,302,855 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/24 01:47:49 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2010/11/23 01:21:47 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/22 13:45:30 | 000,008,268 | —- | M] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2010/11/17 19:05:39 | 000,001,536 | —- | M] () – C:\Users\Pat\Contacts\Desktop\NO$GBA.INP
[2010/11/15 15:21:39 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/11/15 09:47:06 | 000,000,207 | —- | M] () – C:\Users\Public\Desktop\Vindictus.url
[2010/11/08 10:32:38 | 000,296,448 | —- | M] () – C:\Users\Pat\gmer.exe
[2010/11/08 10:32:38 | 000,296,448 | —- | M] () – C:\Users\Pat\Contacts\Desktop\gmer.exe
[2010/10/27 09:37:28 | 000,258,536 | —- | M] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/26 19:44:15 | 000,000,295 | —- | M] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk

========== Files Created - No Company Name ==========

[2010/11/24 08:51:30 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/24 08:19:48 | 000,000,945 | —- | C] () – C:\Users\Pat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/24 08:10:27 | 000,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2010/11/24 02:26:14 | 000,001,737 | —- | C] () – C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2010/11/24 01:59:46 | 000,296,448 | —- | C] () – C:\Users\Pat\Contacts\Desktop\gmer.exe
[2010/11/24 01:58:03 | 000,296,448 | —- | C] () – C:\Users\Pat\gmer.exe
[2010/11/15 09:47:06 | 000,000,207 | —- | C] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/26 19:44:15 | 000,000,295 | —- | C] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/07/02 19:35:00 | 000,056,320 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2010/07/02 19:28:22 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/30 20:12:11 | 000,000,208 | —- | C] () – C:\Windows\TLCAPPS.INI
[2010/06/30 20:11:31 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2010/05/18 12:16:03 | 000,065,536 | —- | C] () – C:\Windows\System32\HPPLVS.dll
[2010/05/11 11:02:13 | 000,000,552 | —- | C] () – C:\Users\Pat\AppData\Local\d3d8caps.dat
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\Users\Pat\AppData\Local\ru6R
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\ProgramData\ru6R
[2009/10/07 12:48:46 | 000,008,268 | —- | C] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/08/31 18:43:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/30 13:01:10 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/08/07 21:30:08 | 000,000,036 | -H– | C] () – C:\Windows\System32\swk.ini
[2009/08/07 21:27:49 | 000,013,312 | —- | C] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/01 13:13:07 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/01 13:05:21 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/01 10:06:42 | 000,000,000 | —- | C] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2009/07/27 20:32:24 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/07/27 20:21:57 | 000,279,888 | —- | C] () – C:\Windows\System32\brcmbsp.dll
[2009/07/27 20:19:21 | 000,080,368 | —- | C] () – C:\Windows\System32\pbadrvdll.dll
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/04/22 08:58:30 | 000,126,976 | —- | C] () – C:\Windows\System32\DTMessageLib.dll
[2009/04/10 11:01:12 | 000,143,360 | R— | C] () – C:\Windows\System32\preflib.dll
[2009/02/26 15:54:52 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_tr.dll
[2009/02/26 15:54:50 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_ro.dll
[2009/02/26 15:54:48 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt-BR.dll
[2009/02/26 15:54:48 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_hu.dll
[2009/02/26 15:54:46 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_he.dll
[2009/02/26 15:54:44 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_el.dll
[2009/02/26 15:54:44 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_fi.dll
[2009/02/26 15:54:42 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_cs.dll
[2009/02/26 15:54:40 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_ar.dll
[2009/02/26 15:54:40 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHT.dll
[2009/02/26 15:54:38 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHS.dll
[2009/02/26 15:54:36 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_sv.dll
[2009/02/26 15:54:34 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt.dll
[2009/02/26 15:54:34 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_ru.dll
[2009/02/26 15:54:32 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pl.dll
[2009/02/26 15:54:32 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_no.dll
[2009/02/26 15:54:30 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_nl.dll
[2009/02/26 15:54:28 | 000,090,112 | —- | C] () – C:\Windows\System32\Internationalization_ja.dll
[2009/02/26 15:54:28 | 000,086,016 | —- | C] () – C:\Windows\System32\Internationalization_ko.dll
[2009/02/26 15:54:26 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_it.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_fr.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_es.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_de.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_da.dll
[2009/02/17 08:51:28 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_es.dll
[2009/02/17 08:51:28 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_en.dll
[2009/02/17 08:51:26 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_fr.dll
[2009/02/17 08:51:24 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_it.dll
[2009/02/17 08:51:24 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_ja.dll
[2009/02/17 08:51:24 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_ko.dll
[2009/02/17 08:51:22 | 000,565,248 | —- | C] () – C:\Windows\System32\AmRes_ru.dll
[2009/02/17 08:51:22 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_pt-BR.dll
[2009/02/17 08:51:20 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_fi.dll
[2009/02/17 08:51:20 | 000,479,232 | —- | C] () – C:\Windows\System32\AmRes_zh-CHT.dll
[2009/02/17 08:51:20 | 000,475,136 | —- | C] () – C:\Windows\System32\AmRes_zh-CHS.dll
[2009/02/17 08:51:18 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_da.dll
[2009/02/17 08:51:16 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_nl.dll
[2009/02/17 08:51:16 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_pl.dll
[2009/02/17 08:51:16 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_no.dll
[2009/02/17 08:51:14 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_sv.dll
[2009/02/17 08:51:04 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_cs.dll
[2009/02/17 08:51:04 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_ar.dll
[2009/02/17 08:51:02 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_el.dll
[2009/02/17 08:51:02 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_he.dll
[2009/02/17 08:51:00 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_pt-PT.dll
[2009/02/17 08:51:00 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_hu.dll
[2009/02/17 08:50:58 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_ro.dll
[2009/02/17 08:50:58 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_tr.dll
[2009/02/17 07:46:36 | 000,544,768 | —- | C] () – C:\Windows\System32\AmRes_de.dll
[2009/01/06 15:25:36 | 000,010,752 | —- | C] () – C:\Windows\System32\Wavx_ESC_Logging.dll
[2008/12/22 13:13:54 | 000,249,856 | —- | C] () – C:\Windows\System32\wxvault.dll
[2008/10/06 17:36:56 | 000,839,680 | —- | C] () – C:\Windows\System32\DemoLicense.dll
[2008/03/25 08:46:00 | 000,077,536 | —- | C] () – C:\Windows\System32\xltZlib.dll
[2007/04/19 04:52:16 | 000,080,720 | —- | C] () – C:\Windows\System32\AsfBios.dll
[2007/04/19 04:28:10 | 000,025,424 | —- | C] () – C:\Windows\System32\drivers\netamsg.dll
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/30 11:58:44 | 000,176,128 | R— | C] () – C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 11:58:44 | 000,126,976 | R— | C] () – C:\Windows\System32\bioapi100.dll
[2004/09/10 12:34:00 | 000,917,504 | —- | C] () – C:\Windows\System32\lmgr10.dll
[2004/09/10 12:34:00 | 000,057,344 | —- | C] () – C:\Windows\System32\ADsSecurity.dll

========== Files - Unicode (All) ==========
[2010/11/15 09:52:24 | 000,000,000 | —D | M](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
[2010/11/15 09:52:24 | 000,000,000 | —D | C](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613

< End of report >



Rootrepeal .txt

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/11/24 12:13
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
——————-
Name: cdfs.sys
Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
Address: 0x90AA8000 Size: 90112 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x90ACB000 Size: 897024 File Visible: No Signed: -
Status: -

Name: Fs_Rec.SYS
Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
Address: 0x907AF000 Size: 36864 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: mup.sys
Image Path: C:\Windows\System32\Drivers\mup.sys
Address: 0x8C15C000 Size: 61440 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9EBDF000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\System Volume Information\{60389cfe-f0bd-11df-959f-d84d695c5848}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1a82d02e-f325-11df-ab29-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1aa507af-f666-11df-a758-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1aa507cf-f666-11df-a758-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{7f118e07-f7a1-11df-b0f5-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{90625b55-f7a7-11df-93f2-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{a7c9fa50-f595-11df-abce-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{a7c9fa57-f595-11df-abce-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{b3e2b12e-f255-11df-a8f4-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{b4f6b5cd-f3ea-11df-805f-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{baa6bce3-f791-11df-b5c1-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d25a18ec-f4e5-11df-bbc0-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e924694e-f193-11df-8117-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\Windows\System32\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\System32\GATHER~1.XSL
Status: Locked to the Windows API!

Path: c:\windows\temp\mcafee_xnzuh2r39sgdr2k
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\Program Files\Windows Media Player\Network Sharing\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850
4d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053
e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d
d7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab
ac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b
5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.21022.8_none_b81d038aaf540e86.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea
1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc
0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f
0bcaee084e72e5d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_ecff
360cfb2594f3.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c
2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003
bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.4148_none_80b7c8a91e9d
d16a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11d
f268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.4148_none_0
e9108e3b72e14d4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_5169
53ad0f4d16c4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_d088a2ec442ef17
b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f47e
1bd6f6571810.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cd
a6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_b7e610287b2b4ea5.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c
0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d
131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0ef
b442f8a0f46c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_4973eb1d754a
9dc9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_4bf5400abf9d60b
7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.21022.8_none_5926f98
ceadc42c2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe7680
6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_a6e4a798
0e9b18a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddf
c6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a
620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\1154a0dd8ec7062351d700a2d07b3bb5154c840bfc84077d20f6947d1e08bb6f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\534cf013667c78b2ecf44e00183c95e4c2336f1e150a38452cd7e61ec2a73bfc.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18527_none_b4d48387d6d3c659\$$DeleteMe.urlmon.dll.01cb8be1d932852e.0002
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\MI2095~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\MIC237~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18527_none_479516058c8e0b49\$$DeleteMe.iertutil.dll.01cb8be1d8eb1bee.0001
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18527_none_01da5f29a1dcecec\$$DeleteMe.wininet.dll.01cb8be1d8d34e2e.0000
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.1638
6_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18528_none_0b5c2f154f22adf2\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22331_none_0bd3f43c684ec0d7\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22762_none_0bb48c5a6866229d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18005_none_0d553c2b4c3b84e1\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16789_none_09360999522be962\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.20976_none_09c777586b441e5d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18185_none_0b1847174f5614f7\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18311_none_0d4670c94c4732eb\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22486_none_0d895f92659914ff\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\PLA\Reports\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\PLA\Rules\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\System32\migwiz\dlmanifests\MIC237~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\System32\migwiz\dlmanifests\MI2095~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sortkey.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sortkey.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sorttbls.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sorttbls.nlp
Status: Locked to the Windows API!

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\RWS_SA~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\TLIB_A~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\TLIB_N~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles\6.0.6000.16386__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Locked to the Windows API!

Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1344 Status: Locked to the Windows API!

Stealth Objects
——————-
Object: Hidden Module [Name: msgsres.dll]
Process: msnmsgr.exe (PID: 3964) Address: 0x63c70000 Size: 11403264

Object: Hidden Module [Name: msgslang.14.0.8050.1202.dll]
Process: msnmsgr.exe (PID: 3964) Address: 0x67000000 Size: 315392

Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 3964) Address: 0x6a3c0000 Size: 20480

==EOF==

But rootrepeal ended with an error message:

FOPS-DeviceIoControlError! Error Code = 0xC0000001 Extended Info (0x000000e0)

Should I run it again?
OK Here is a current OTL .txt:

OTL logfile created on: 11/24/2010 11:47:27 AM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Pat\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 62.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 146.87 Gb Total Space | 67.58 Gb Free Space | 46.02% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.12 Gb Free Space | 55.89% Space Free | Partition Type: NTFS
Drive E: | 127.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAT-PC | User Name: Pat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Pat\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe (McAfee, Inc.)
PRC - C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe (McAfee, Inc.)
PRC - C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\HP1006MC.EXE (Software 2000 Limited)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
PRC - C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
PRC - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe (Dell Inc.)
PRC - C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
PRC - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
PRC - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
PRC - C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
PRC - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Pat\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18523_none_5cdd65e20837faf2\comctl32.dll (Microsoft Corporation)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV - (mfevtp) – C:\Windows\System32\mfevtps.exe (McAfee, Inc.)
SRV - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McProxy) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNASvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McNaiAnn) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (mcmscsvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McMPFSvc) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (McAfee SiteAdvisor Service) – C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV - (npggsvc) – C:\Windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_820ff26a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TdmService) – C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe (Wave Systems Corp.)
SRV - (SMManager) – C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe (Smith Micro Software, Inc.)
SRV - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Credential Vault Host Control Service) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe (Broadcom Corporation)
SRV - (Credential Vault Host Storage) – C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe (Broadcom Corporation)
SRV - (buttonsvc32) – C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe (Dell Inc.)
SRV - (SecureStorageService) – C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe (Wave Systems Corp.)
SRV - (tcsd_win32.exe) – C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe ()
SRV - (alssvc) – C:\Program Files\Dell\Ambient Light Sensor\AlsSvc.exe (Dell Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ASFAgent) – C:\Program Files\Intel\ASF Agent\ASFAgent.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NvtSp50) – C:\Windows\System32\Drivers\NvtSp50.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (EagleNT) – C:\Windows\System32\drivers\EagleNT.sys File not found
DRV - (mfehidk) – C:\Windows\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfefirek) – C:\Windows\System32\drivers\mfefirek.sys (McAfee, Inc.)
DRV - (mfewfpk) – C:\Windows\System32\drivers\mfewfpk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\Windows\System32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mferkdet) – C:\Windows\System32\drivers\mferkdet.sys (McAfee, Inc.)
DRV - (mfenlfk) – C:\Windows\System32\drivers\mfenlfk.sys (McAfee, Inc.)
DRV - (cfwids) – C:\Windows\System32\drivers\cfwids.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (HECI) Intel® – C:\Windows\system32\drivers\heci.sys (Intel Corporation)
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (WavxDMgr) – C:\Windows\System32\drivers\WavxDMgr.sys (Wave Systems Corp.)
DRV - (cvusbdrv) – C:\Windows\System32\drivers\cvusbdrv.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\Windows\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\system32\drivers\rimsptsk.sys (REDC)
DRV - (rixdpcie) – C:\Windows\system32\drivers\rixdpe86.sys (REDC)
DRV - (risdpcie) – C:\Windows\system32\drivers\risdpe86.sys (REDC)
DRV - (rimspci) – C:\Windows\system32\drivers\rimspe86.sys (REDC)
DRV - (OA001Ufd) – C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (OA001Vid) – C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (e1yexpress) Intel® – C:\Windows\System32\drivers\e1y6032.sys (Intel Corporation)
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (BCM43XX) – C:\Windows\System32\drivers\BCMWL6.SYS (Broadcom Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (PBADRV) – C:\Windows\system32\DRIVERS\PBADRV.sys (Dell Inc)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.adultswim.com/shows/metalocalyp…tour/index.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://mail.google.com/mail/?hl=en&shva=1#inbox/126fb6d8098ff8e7|http://forums.whatthetech.com/index.php?showforum=27|http://www.timanderic.com/"
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.5.3
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/11/24 02:48:27 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/24 02:24:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/11 11:33:34 | 000,000,000 | —D | M]

[2009/10/02 00:52:54 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Extensions
[2010/11/24 08:05:41 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions
[2009/10/02 10:34:02 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/11/03 22:53:12 | 000,000,000 | —D | M] (AIM Toolbar) – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2010/04/18 01:02:20 | 000,000,000 | —D | M] – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\extensions\[removed]
[2009/11/03 22:53:17 | 000,004,554 | —- | M] () – C:\Users\Pat\AppData\Roaming\Mozilla\Firefox\Profiles\j1m3u5n2.default\searchplugins\aim-search.xml
[2009/10/02 00:52:40 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/10/13 22:28:54 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files\Mozilla Firefox\components\Scriptff.dll
[2010/11/24 08:12:38 | 000,002,024 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2010/11/24 01:47:49 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20101124022458.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Dell Webcam Central] C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [DellConnectionManager] C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe (Smith Micro Software, Inc.)
O4 - HKLM..\Run: [DellControlPoint] C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe (Dell Inc.)
O4 - HKLM..\Run: [EmbassySecurityCheck] C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Microsoft Default Manager] C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\Windows\System32\nvHotkey.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [USCService] C:\Program Files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe (Broadcom Corporation)
O4 - HKLM..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe (Wave Systems Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Pat\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Authentication Packages - (wvauth) - C:\Windows\System32\wvauth.dll (Wave Systems Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2001/08/03 04:11:58 | 000,094,208 | R— | M] () - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2002/09/03 15:20:16 | 000,000,051 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7fa058a5-7af0-11de-abfb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Autorun.exe – [2001/08/03 04:11:58 | 000,094,208 | R— | M] ()
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/24 08:19:59 | 000,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/11/24 08:10:28 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/11/24 08:10:28 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/11/24 08:10:28 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/11/24 08:10:28 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/11/24 08:10:28 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/11/24 08:10:28 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/11/24 08:10:27 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/11/24 08:10:27 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/11/24 08:10:27 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/11/24 08:10:27 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/11/24 08:10:27 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/11/24 08:10:26 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/11/24 08:10:26 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/11/24 08:10:26 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/11/24 08:10:26 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/11/24 08:10:26 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/11/24 08:10:26 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/11/24 08:09:51 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2010/11/24 08:09:51 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2010/11/24 08:09:50 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2010/11/24 08:09:50 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2010/11/24 08:09:50 | 000,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2010/11/24 08:09:50 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2010/11/24 08:09:50 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2010/11/24 08:09:50 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2010/11/24 08:09:50 | 000,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2010/11/24 08:09:49 | 000,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2010/11/24 08:09:49 | 000,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2010/11/24 08:09:49 | 000,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2010/11/24 08:09:49 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2010/11/24 08:09:49 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2010/11/24 08:09:49 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2010/11/24 08:09:48 | 000,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2010/11/24 08:09:48 | 000,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2010/11/24 08:09:48 | 000,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/11/24 08:09:48 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2010/11/24 08:09:48 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2010/11/24 08:09:47 | 003,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2010/11/24 08:09:47 | 000,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2010/11/24 08:09:47 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2010/11/24 08:09:47 | 000,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2010/11/24 08:09:47 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2010/11/24 02:24:58 | 000,009,344 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeclnk.sys
[2010/11/24 02:24:44 | 000,313,288 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfefirek.sys
[2010/11/24 02:24:44 | 000,164,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfewfpk.sys
[2010/11/24 02:24:44 | 000,084,264 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mferkdet.sys
[2010/11/24 02:24:44 | 000,064,304 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfenlfk.sys
[2010/11/24 02:24:43 | 000,152,960 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfeavfk.sys
[2010/11/24 02:24:43 | 000,055,840 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\cfwids.sys
[2010/11/24 02:24:43 | 000,052,104 | —- | C] (McAfee, Inc.) – C:\Windows\System32\drivers\mfebopk.sys
[2010/11/24 02:24:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Mcafee
[2010/11/24 02:24:38 | 000,000,000 | —D | C] – C:\Program Files\McAfee.com
[2010/11/24 02:24:36 | 000,000,000 | —D | C] – C:\Program Files\McAfee
[2010/11/24 02:15:42 | 000,141,792 | —- | C] (McAfee, Inc.) – C:\Windows\System32\mfevtps.exe
[2010/11/24 01:46:21 | 000,000,000 | —D | C] – C:\_OTL
[2010/11/15 15:21:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/11/15 09:51:09 | 000,000,000 | —D | C] – C:\ProgramData\Nexon
[2010/11/15 09:49:56 | 000,000,000 | —D | C] – C:\Users\Pat\Documents\Vindictus
[2010/11/15 09:47:05 | 000,000,000 | —D | C] – C:\Program Files\BandiMPEG1
[2010/10/27 09:43:59 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2010/10/27 09:43:59 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2010/10/27 09:37:28 | 000,258,536 | —- | C] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/27 09:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Screentime
[2010/10/27 09:37:20 | 000,000,000 | —D | C] – C:\Users\Pat\AppData\Local\Screentime

========== Files - Modified Within 30 Days ==========

[2010/11/24 11:01:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/24 10:25:34 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/11/24 10:25:34 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/11/24 09:58:32 | 000,013,312 | —- | M] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/24 08:51:30 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/24 08:32:45 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/11/24 08:32:45 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/11/24 08:28:00 | 000,000,000 | —- | M] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2010/11/24 08:27:56 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.001
[2010/11/24 08:27:55 | 000,001,737 | —- | M] () – C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2010/11/24 08:27:49 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/24 08:25:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/11/24 08:25:16 | 3743,338,496 | -HS- | M] () – C:\hiberfil.sys
[2010/11/24 08:19:48 | 000,000,945 | —- | M] () – C:\Users\Pat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/24 02:48:28 | 378,302,855 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/11/24 01:47:49 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2010/11/23 01:21:47 | 000,027,649 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/11/22 13:45:30 | 000,008,268 | —- | M] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2010/11/17 19:05:39 | 000,001,536 | —- | M] () – C:\Users\Pat\Contacts\Desktop\NO$GBA.INP
[2010/11/15 15:21:39 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2010/11/15 09:47:06 | 000,000,207 | —- | M] () – C:\Users\Public\Desktop\Vindictus.url
[2010/11/08 10:32:38 | 000,296,448 | —- | M] () – C:\Users\Pat\gmer.exe
[2010/11/08 10:32:38 | 000,296,448 | —- | M] () – C:\Users\Pat\Contacts\Desktop\gmer.exe
[2010/10/27 09:37:28 | 000,258,536 | —- | M] (ScreenTime Media) – C:\Windows\System32\AdventureTime_Screensaver.scr
[2010/10/26 19:44:15 | 000,000,295 | —- | M] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk

========== Files Created - No Company Name ==========

[2010/11/24 08:51:30 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/24 08:19:48 | 000,000,945 | —- | C] () – C:\Users\Pat\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/11/24 08:10:27 | 000,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2010/11/24 02:26:14 | 000,001,737 | —- | C] () – C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2010/11/24 01:59:46 | 000,296,448 | —- | C] () – C:\Users\Pat\Contacts\Desktop\gmer.exe
[2010/11/24 01:58:03 | 000,296,448 | —- | C] () – C:\Users\Pat\gmer.exe
[2010/11/15 09:47:06 | 000,000,207 | —- | C] () – C:\Users\Public\Desktop\Vindictus.url
[2010/10/26 19:44:15 | 000,000,295 | —- | C] () – C:\Users\Pat\Documents\Pat - Shortcut.lnk
[2010/07/02 19:35:00 | 000,056,320 | —- | C] () – C:\Windows\System32\iyvu9_32.dll
[2010/07/02 19:28:22 | 000,000,039 | —- | C] () – C:\Windows\WININIT.INI
[2010/06/30 20:12:11 | 000,000,208 | —- | C] () – C:\Windows\TLCAPPS.INI
[2010/06/30 20:11:31 | 000,000,000 | —- | C] () – C:\Windows\setup32.INI
[2010/05/18 12:16:03 | 000,065,536 | —- | C] () – C:\Windows\System32\HPPLVS.dll
[2010/05/11 11:02:13 | 000,000,552 | —- | C] () – C:\Users\Pat\AppData\Local\d3d8caps.dat
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\Users\Pat\AppData\Local\ru6R
[2010/03/17 21:19:09 | 000,010,390 | -HS- | C] () – C:\ProgramData\ru6R
[2009/10/07 12:48:46 | 000,008,268 | —- | C] () – C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/08/31 18:43:20 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/08/30 13:01:10 | 000,012,288 | —- | C] () – C:\Windows\impborl.dll
[2009/08/07 21:30:08 | 000,000,036 | -H– | C] () – C:\Windows\System32\swk.ini
[2009/08/07 21:27:49 | 000,013,312 | —- | C] () – C:\Users\Pat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/01 13:13:07 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/01 13:05:21 | 000,027,649 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/01 10:06:42 | 000,000,000 | —- | C] () – C:\Users\Pat\AppData\Local\WavXMapDrive.bat
[2009/07/27 20:32:24 | 000,055,808 | —- | C] () – C:\Windows\System32\bcmwlrmt.dll
[2009/07/27 20:21:57 | 000,279,888 | —- | C] () – C:\Windows\System32\brcmbsp.dll
[2009/07/27 20:19:21 | 000,080,368 | —- | C] () – C:\Windows\System32\pbadrvdll.dll
[2009/07/08 19:03:02 | 000,058,880 | —- | C] () – C:\Windows\System32\bdmpegv.dll
[2009/04/22 08:58:30 | 000,126,976 | —- | C] () – C:\Windows\System32\DTMessageLib.dll
[2009/04/10 11:01:12 | 000,143,360 | R— | C] () – C:\Windows\System32\preflib.dll
[2009/02/26 15:54:52 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_tr.dll
[2009/02/26 15:54:50 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_ro.dll
[2009/02/26 15:54:48 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt-BR.dll
[2009/02/26 15:54:48 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_hu.dll
[2009/02/26 15:54:46 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_he.dll
[2009/02/26 15:54:44 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_el.dll
[2009/02/26 15:54:44 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_fi.dll
[2009/02/26 15:54:42 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_cs.dll
[2009/02/26 15:54:40 | 000,094,208 | —- | C] () – C:\Windows\System32\Internationalization_ar.dll
[2009/02/26 15:54:40 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHT.dll
[2009/02/26 15:54:38 | 000,081,920 | —- | C] () – C:\Windows\System32\Internationalization_zh-CHS.dll
[2009/02/26 15:54:36 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_sv.dll
[2009/02/26 15:54:34 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pt.dll
[2009/02/26 15:54:34 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_ru.dll
[2009/02/26 15:54:32 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_pl.dll
[2009/02/26 15:54:32 | 000,098,304 | —- | C] () – C:\Windows\System32\Internationalization_no.dll
[2009/02/26 15:54:30 | 000,106,496 | —- | C] () – C:\Windows\System32\Internationalization_nl.dll
[2009/02/26 15:54:28 | 000,090,112 | —- | C] () – C:\Windows\System32\Internationalization_ja.dll
[2009/02/26 15:54:28 | 000,086,016 | —- | C] () – C:\Windows\System32\Internationalization_ko.dll
[2009/02/26 15:54:26 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_it.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_fr.dll
[2009/02/26 15:54:24 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_es.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_de.dll
[2009/02/26 15:54:20 | 000,102,400 | —- | C] () – C:\Windows\System32\Internationalization_da.dll
[2009/02/17 08:51:28 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_es.dll
[2009/02/17 08:51:28 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_en.dll
[2009/02/17 08:51:26 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_fr.dll
[2009/02/17 08:51:24 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_it.dll
[2009/02/17 08:51:24 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_ja.dll
[2009/02/17 08:51:24 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_ko.dll
[2009/02/17 08:51:22 | 000,565,248 | —- | C] () – C:\Windows\System32\AmRes_ru.dll
[2009/02/17 08:51:22 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_pt-BR.dll
[2009/02/17 08:51:20 | 000,520,192 | —- | C] () – C:\Windows\System32\AmRes_fi.dll
[2009/02/17 08:51:20 | 000,479,232 | —- | C] () – C:\Windows\System32\AmRes_zh-CHT.dll
[2009/02/17 08:51:20 | 000,475,136 | —- | C] () – C:\Windows\System32\AmRes_zh-CHS.dll
[2009/02/17 08:51:18 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_da.dll
[2009/02/17 08:51:16 | 000,540,672 | —- | C] () – C:\Windows\System32\AmRes_nl.dll
[2009/02/17 08:51:16 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_pl.dll
[2009/02/17 08:51:16 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_no.dll
[2009/02/17 08:51:14 | 000,516,096 | —- | C] () – C:\Windows\System32\AmRes_sv.dll
[2009/02/17 08:51:04 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_cs.dll
[2009/02/17 08:51:04 | 000,512,000 | —- | C] () – C:\Windows\System32\AmRes_ar.dll
[2009/02/17 08:51:02 | 000,536,576 | —- | C] () – C:\Windows\System32\AmRes_el.dll
[2009/02/17 08:51:02 | 000,503,808 | —- | C] () – C:\Windows\System32\AmRes_he.dll
[2009/02/17 08:51:00 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_pt-PT.dll
[2009/02/17 08:51:00 | 000,528,384 | —- | C] () – C:\Windows\System32\AmRes_hu.dll
[2009/02/17 08:50:58 | 000,532,480 | —- | C] () – C:\Windows\System32\AmRes_ro.dll
[2009/02/17 08:50:58 | 000,524,288 | —- | C] () – C:\Windows\System32\AmRes_tr.dll
[2009/02/17 07:46:36 | 000,544,768 | —- | C] () – C:\Windows\System32\AmRes_de.dll
[2009/01/06 15:25:36 | 000,010,752 | —- | C] () – C:\Windows\System32\Wavx_ESC_Logging.dll
[2008/12/22 13:13:54 | 000,249,856 | —- | C] () – C:\Windows\System32\wxvault.dll
[2008/10/06 17:36:56 | 000,839,680 | —- | C] () – C:\Windows\System32\DemoLicense.dll
[2008/03/25 08:46:00 | 000,077,536 | —- | C] () – C:\Windows\System32\xltZlib.dll
[2007/04/19 04:52:16 | 000,080,720 | —- | C] () – C:\Windows\System32\AsfBios.dll
[2007/04/19 04:28:10 | 000,025,424 | —- | C] () – C:\Windows\System32\drivers\netamsg.dll
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/06/30 11:58:44 | 000,176,128 | R— | C] () – C:\Windows\System32\bioapi_mds300.dll
[2006/06/30 11:58:44 | 000,126,976 | R— | C] () – C:\Windows\System32\bioapi100.dll
[2004/09/10 12:34:00 | 000,917,504 | —- | C] () – C:\Windows\System32\lmgr10.dll
[2004/09/10 12:34:00 | 000,057,344 | —- | C] () – C:\Windows\System32\ADsSecurity.dll

========== Files - Unicode (All) ==========
[2010/11/15 09:52:24 | 000,000,000 | —D | M](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그
[2010/11/15 09:52:24 | 000,000,000 | —D | C](C:\Users\Pat\Documents\?? ???) – C:\Users\Pat\Documents\넥슨 플러그

========== Alternate Data Streams ==========

@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:BEB15613

< End of report >



Rootrepeal .txt

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/11/24 12:13
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
——————-
Name: cdfs.sys
Image Path: C:\Windows\system32\DRIVERS\cdfs.sys
Address: 0x90AA8000 Size: 90112 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x90ACB000 Size: 897024 File Visible: No Signed: -
Status: -

Name: Fs_Rec.SYS
Image Path: C:\Windows\System32\Drivers\Fs_Rec.SYS
Address: 0x907AF000 Size: 36864 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: mup.sys
Image Path: C:\Windows\System32\Drivers\mup.sys
Address: 0x8C15C000 Size: 61440 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9EBDF000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\System Volume Information\{60389cfe-f0bd-11df-959f-d84d695c5848}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1a82d02e-f325-11df-ab29-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1aa507af-f666-11df-a758-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{1aa507cf-f666-11df-a758-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{7f118e07-f7a1-11df-b0f5-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{90625b55-f7a7-11df-93f2-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{a7c9fa50-f595-11df-abce-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{a7c9fa57-f595-11df-abce-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{b3e2b12e-f255-11df-a8f4-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{b4f6b5cd-f3ea-11df-805f-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{baa6bce3-f791-11df-b5c1-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d25a18ec-f4e5-11df-bbc0-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e924694e-f193-11df-8117-0024e8ad31ca}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\Windows\System32\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\System32\GATHER~1.XSL
Status: Locked to the Windows API!

Path: c:\windows\temp\mcafee_xnzuh2r39sgdr2k
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\Program Files\Windows Media Player\Network Sharing\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850
4d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_5090ab56bcba71c
2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053
e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d
d7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab
ac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b
5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.21022.8_none_b81d038aaf540e86.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea
1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc
0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f
0bcaee084e72e5d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_ecff
360cfb2594f3.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c
2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003
bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.4148_none_80b7c8a91e9d
d16a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11d
f268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.30729.4148_none_0
e9108e3b72e14d4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_5169
53ad0f4d16c4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_d088a2ec442ef17
b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f47e
1bd6f6571810.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cd
a6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_b7e610287b2b4ea5.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c
0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d
131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0ef
b442f8a0f46c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_4973eb1d754a
9dc9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.4148_none_4bf5400abf9d60b
7.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.21022.8_none_5926f98
ceadc42c2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe7680
6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_a6e4a798
0e9b18a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddf
c6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a
620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\1154a0dd8ec7062351d700a2d07b3bb5154c840bfc84077d20f6947d1e08bb6f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Manifests\534cf013667c78b2ecf44e00183c95e4c2336f1e150a38452cd7e61ec2a73bfc.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18527_none_b4d48387d6d3c659\$$DeleteMe.urlmon.dll.01cb8be1d932852e.0002
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\MI2095~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-m..-downlevelmanifests_31bf3856ad364e35_6.0.6002.18005_none_04642e8a80bb8b27\MIC237~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18289_none_0b1c4a254f52777a\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18065_none_0d145ca34c6c2c87\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18527_none_479516058c8e0b49\$$DeleteMe.iertutil.dll.01cb8be1d8eb1bee.0001
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18527_none_01da5f29a1dcecec\$$DeleteMe.wininet.dll.01cb8be1d8d34e2e.0000
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18005_none_9e2fbb5f0207ec84\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.VBS
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\GATHER~1.XSL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.1638
6_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18528_none_0b5c2f154f22adf2\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22331_none_0bd3f43c684ec0d7\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22470_none_0ba7b6286870146b\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22762_none_0bb48c5a6866229d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18005_none_0d553c2b4c3b84e1\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16789_none_09360999522be962\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16885_none_09320a57522f812d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.20976_none_09c777586b441e5d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21083_none_09b97eb06b4f218b\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18185_none_0b1847174f5614f7\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18311_none_0d4670c94c4732eb\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22172_none_0d9028a465949c3d\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22486_none_0d895f92659914ff\RENDER~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\PLA\Reports\REPORT~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\PLA\Rules\RULESS~1.XML
Status: Locked to the Windows API!

Path: C:\Windows\System32\migwiz\dlmanifests\MIC237~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\System32\migwiz\dlmanifests\MI2095~1.MAN
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sortkey.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sortkey.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sorttbls.nlp
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Temp\PendingDeletes\sorttbls.nlp
Status: Locked to the Windows API!

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\RWS_SA~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\TLIB_A~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Users\Pat\Documents\MEtal files\Swamplord\TLIB_N~1.MPG:Zone.Identifier
Status: Visible to the Windows API, but not on disk.

Path: C:\Windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles\6.0.6000.16386__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Locked to the Windows API!

Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Locked to the Windows API!

Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1344 Status: Locked to the Windows API!

Stealth Objects
——————-
Object: Hidden Module [Name: msgsres.dll]
Process: msnmsgr.exe (PID: 3964) Address: 0x63c70000 Size: 11403264

Object: Hidden Module [Name: msgslang.14.0.8050.1202.dll]
Process: msnmsgr.exe (PID: 3964) Address: 0x67000000 Size: 315392

Object: Hidden Module [Name: msgrvsta.thm]
Process: msnmsgr.exe (PID: 3964) Address: 0x6a3c0000 Size: 20480

==EOF==

But rootrepeal ended with an error message:

FOPS-DeviceIoControlError! Error Code = 0xC0000001 Extended Info (0x000000e0)

Should I run it again?
Your fine

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
The only stuff is that file was this: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK Pretty boring! It took about 1 hour 18 minutes to run the scan. But I did have trouble using MS Explorer. It shut down twice while I was trying to access the site to run ESET. But the PC still seems much faster. Sara
Hello Sara,

Why dont you post in our windows forum and see if they can help you speed up your system, they can go through running programs and start up programs that may be causing you some problems. You can link them to this thread if you wish so they can see what we have done and if they feel its still malware related we can dig a bit deeper
http://forums.whatthetech.com/index.php?showforum=119

  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI