This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

xp pro sp3, playing a game system froze, now wont boot in normal mode

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
System seemed to be working okay, while playing game flatout 2 my system froze, ctl alt del would not work so I restarted computer, during boot up I noticed that the screen has vertical lines made up of dots, the lines are in pairs of four, four lines with small dots then four lines with larger dots. While attempting to start I could see a blue screen error and the system tries to restart again. I can't read any of the blue screen as it flashes by too fast.

The only way I can start is in safe mode.
I tried system restore to an earlier date but same results.
Before posting I tried downloading hijack this but it looks like it wants an agreement clicked but I can't see an accept box because my display is rather large and I can't change display settings while in safe mode.
Help plz

Just got hijack to work, here are results

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:44:09 AM, on 1/23/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\MIKE\Desktop\Hijack This.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: SearchHook Class - {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [BCU] "C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GBTUpd] C:\Program Files\GIGABYTE\GBTUpd\PreRun.exe
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [EasyTuneVI] C:\Program Files\GIGABYTE\ET6\ETCall.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.samsungportal.com
O16 - DPF: {01025D1C-BB03-4369-8344-732CD0DCCCF0} (NVIDIA GPU Reader Class) - http://www.geforce.com/services_toolkit/Sh…/GPU_Reader.cab
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab
O16 - DPF: {714E667D-360C-4BFB-8C1A-E4812B608CC1} (ACUBETrustChecker Control) - http://service.samsungportal.com/EP/web/co…rustChecker.cab
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Browser Configuration Utility Service (BCUService) - DeviceVM, Inc. - C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: DiRT Drivers Auto Removal (pr2ah4nc) (pr2ah4nc) - CODEMASTERS - C:\WINDOWS\system32\pr2ah4nc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe

–
End of file - 8003 bytes
Hello, gcdi
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





We Need to Diagnose Your BlueScreen
  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:
    [external image: Posted Image]
  • When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:
    [external image: Posted Image]

Hello, gcdi
Welcome to the WhatTheTech Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.



Please take note of some guidelines for this fix:

  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





We Need to Diagnose Your BlueScreen
  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:
    [external image: Posted Image]
  • When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:
    [external image: Posted Image]

Hi Tom and thanks for the reply. Before I start with your suggestions I'd like to give you some updates on changes before I received your reply. I think the main problem might have been a graphics card. I was running two graphics cards so I switched to one and still had the problem, replaced it with card #2 and it boots normally. Tried it for a while and all seemed okay, put graphics card #1 back in and problem was there so went back to card #2 and it has been booting normally and most things seem to be normal. I am still having a problem of after closing some programs I'll get a message that the program has a problem and needs shut down but don't see the message until I've already closed the program. Also having some picture problems depending which browser I'm using. Example, using IE I'll open a page that should have a picture but get a blank area and right clicking does not give the option of show picture but can use google chrome go to the same page and the picture will show. I also possibly had an email account hijacked, seeing many messages in sent file that I did not send, followed some suggestions from MSN Hotmail and haven't seen any recently but not sure that I may still have a problem there. After all that now if you would let me know how to proceed. Thanks Mike
Hi,

Ok, then we will go from there. Please follow these instructions:


  • Please download OTL from one of the following mirrors:
    • This is THE Mirror
  • Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemdrive%\*.sys /90 /md5
  • Push the Quick Scan button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <– Will be opened
    • Extra.txt <– Will be minimized






Please download Rootkit Unhooker from one of the following links and save it to your desktop. Link 1 (.exe file) Link 2 (zipped file) Link 3 (.rar file)
In order to use this tool if you downloaded from either of the second two links, you will need to extract the RKUnhookerLE.exe file using a program capable of extracing ZIP and RAR compressed files. If you don't have an extraction program, you can downlaod, install and use the free 7-zip utility.
  • Double-click on RKUnhookerLE.exe to start the program. Vista/Windows 7 users right-click and select Run As Administrator.
  • Click the Report tab, then click Scan.
  • Check Drivers, Stealth, and uncheck the rest.
  • Click OK.
  • Wait until it's finished and then go to File > Save Report.
  • Save the report to your Desktop.
  • Copy and paste the contents of the report into your next reply.
– Note: You may get this warning…just ignore it, click OK and continue: "Rootkit Unhooker has detected a parasite inside itself! It is recommended to remove parasite, okay?".
OTL logfile created on: 1/27/2011 1:36:41 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MIKE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 868.16 Gb Free Space | 93.20% Space Free | Partition Type: NTFS
Drive D: | 4.64 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 69.23 Gb Total Space | 39.39 Gb Free Space | 56.89% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 179.49 Gb Free Space | 77.07% Space Free | Partition Type: NTFS

Computer Name: GCDI-F7150E40D8 | User Name: MIKE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
PRC - [2010/12/27 02:49:25 | 000,202,256 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2009/11/19 17:15:46 | 000,583,016 | —- | M] (Sony Corporation) – C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
PRC - [2009/09/25 08:59:18 | 000,106,496 | —- | M] (NEC Electronics Corporation) – C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009/08/24 14:38:06 | 000,068,136 | —- | M] () – C:\Program Files\Gigabyte\EasySaver\essvr.exe
PRC - [2009/08/04 17:29:54 | 000,219,360 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009/08/04 17:29:52 | 000,346,320 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009/07/17 13:47:44 | 000,322,088 | —- | M] (Gigabyte) – C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe
PRC - [2009/06/04 00:55:16 | 000,025,600 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\Ctxfihlp.exe
PRC - [2009/06/04 00:49:56 | 001,213,440 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTxfispi.exe
PRC - [2009/02/23 11:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/25 16:21:56 | 000,219,656 | —- | M] () – C:\Program Files\Gigabyte\ET6\GUI.exe
PRC - [2007/08/31 09:48:28 | 000,262,144 | —- | M] () – C:\WINDOWS\tsnp2std.exe
PRC - [2007/08/09 01:27:52 | 000,073,728 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/08/07 12:49:18 | 000,348,160 | —- | M] (Sonix) – C:\WINDOWS\vsnp2std.exe
PRC - [2007/07/11 15:09:48 | 000,020,480 | —- | M] () – C:\WINDOWS\FixCamera.exe
PRC - [2006/12/12 10:46:52 | 000,019,456 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CtHelper.exe
PRC - [2005/03/07 22:42:09 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
PRC - [2004/12/02 17:23:34 | 000,102,400 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PRC - [2004/04/23 13:28:00 | 000,077,824 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Profiler\LWEMon.exe


========== Modules (SafeList) ==========

MOD - [2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
MOD - [2010/12/27 02:50:17 | 000,040,960 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/08/07 16:10:18 | 000,007,168 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTAGENT.DLL
MOD - [2004/04/23 13:26:48 | 000,053,248 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Profiler\LWEHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/12/08 02:56:30 | 000,079,360 | —- | M] (Creative Labs) [On_Demand | Stopped] – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe – (Creative Audio Engine Licensing Service)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2009/08/24 14:38:06 | 000,068,136 | —- | M] () [Auto | Running] – C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE – (ES lite Service)
SRV - [2009/08/10 14:58:28 | 000,093,848 | —- | M] (SiSoftware) [On_Demand | Stopped] – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe – (SandraAgentSrv)
SRV - [2009/08/04 17:29:54 | 000,219,360 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2009/02/23 11:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) [Auto | Running] – C:\Program Files\Creative\Shared Files\CTAudSvc.exe – (CTAudSvcService)
SRV - [2007/08/09 01:27:52 | 000,073,728 | —- | M] (HP) [Auto | Running] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/05/18 13:53:29 | 000,407,152 | —- | M] (CODEMASTERS) [Auto | Stopped] – C:\WINDOWS\System32\pr2ah4nc.exe – (pr2ah4nc) DiRT Drivers Auto Removal (pr2ah4nc)


========== Driver Services (SafeList) ==========

DRV - [2011/01/27 01:22:12 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A32EC7-2EC3-4C22-8ABC-546DCD6D468C}\MpKsl96232e8d.sys – (MpKsl96232e8d)
DRV - [2011/01/27 01:12:04 | 000,024,944 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\GVTDrv.sys – (GVTDrv)
DRV - [2011/01/27 01:11:29 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\gdrv.sys – (gdrv)
DRV - [2011/01/24 08:02:14 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\etdrv.sys – (etdrv)
DRV - [2010/10/16 12:55:00 | 009,623,680 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2010/07/04 05:41:23 | 000,023,456 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\DrvAgent32.sys – (DrvAgent32)
DRV - [2010/03/12 04:35:48 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Program Files\Gigabyte\ET6\i386\AODDriver.sys – (AODDriver)
DRV - [2009/10/21 08:28:42 | 005,934,592 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/10/07 05:26:18 | 000,099,440 | R— | M] (JMicron Technology Corp.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\jraid.sys – (JRAID)
DRV - [2009/09/25 08:57:40 | 000,138,240 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nusb3xhc.sys – (nusb3xhc)
DRV - [2009/09/25 08:57:36 | 000,056,576 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nusb3hub.sys – (nusb3hub)
DRV - [2009/08/07 23:46:56 | 000,023,112 | —- | M] (SiSoftware) [Kernel | On_Demand | Stopped] – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\sandra.sys – (SANDRA)
DRV - [2009/07/28 02:55:00 | 000,143,360 | R— | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2009/06/04 02:48:12 | 001,177,624 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ha20x2k.sys – (ha20x2k)
DRV - [2009/06/04 02:48:00 | 000,095,768 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia)
DRV - [2009/06/04 02:47:50 | 000,158,744 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2009/06/04 02:47:42 | 000,014,360 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k)
DRV - [2009/06/04 02:47:34 | 000,130,072 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2009/06/04 02:47:24 | 000,347,080 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k)
DRV - [2009/06/04 02:47:14 | 000,526,232 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k) Creative Audio Driver (WDM)
DRV - [2009/06/04 02:47:06 | 000,511,000 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k)
DRV - [2009/06/04 02:46:56 | 001,324,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CTEXFIFX.SYS – (CTEXFIFX.SYS)
DRV - [2009/06/04 02:46:56 | 001,324,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CTEXFIFX.sys – (CTEXFIFX)
DRV - [2009/06/04 02:46:42 | 000,072,728 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CTHWIUT.SYS – (CTHWIUT.SYS)
DRV - [2009/06/04 02:46:42 | 000,072,728 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CTHWIUT.sys – (CTHWIUT)
DRV - [2009/06/04 02:46:34 | 000,171,032 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CT20XUT.SYS – (CT20XUT.SYS)
DRV - [2009/06/04 02:46:34 | 000,171,032 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CT20XUT.sys – (CT20XUT)
DRV - [2008/08/05 06:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/04/13 12:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/04/13 10:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/09/05 12:48:24 | 012,212,864 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\snp2sxp.sys – (SNP2STD) USB2.0 PC Camera (SNP2STD)
DRV - [2007/05/18 13:53:01 | 000,064,880 | —- | M] (CODEMASTERS) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\pe3ah4nc.sys – (pe3ah4nc) DiRT Environment Driver (pe3ah4nc)
DRV - [2007/05/18 13:52:38 | 000,055,160 | —- | M] (CODEMASTERS) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\ps6ah4nc.sys – (ps6ah4nc) DiRT Synchronization Driver (ps6ah4nc)
DRV - [2007/04/16 16:46:34 | 000,033,792 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdPPM.sys – (AmdPPM)
DRV - [2007/01/24 15:27:54 | 000,039,704 | —- | M] (Belcarra Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rcblan.sys – (RemoteControl-USBLAN)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/01/04 01:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2005/09/29 11:01:51 | 000,066,048 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfvfs02.sys – (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005/08/10 08:06:28 | 000,019,968 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfsync02.sys – (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005/08/10 06:44:04 | 000,050,688 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfdrv01.sys – (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/07/23 00:41:46 | 000,026,112 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LHidKE.Sys – (LHidKE)
DRV - [2005/07/23 00:41:42 | 000,068,864 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE)
DRV - [2005/05/16 07:20:39 | 000,006,656 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfhlp02.sys – (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005/03/10 15:08:16 | 000,013,056 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042Kbd.sys – (L8042Kbd)
DRV - [2004/04/14 10:08:00 | 000,044,064 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmXlCore.sys – (WmXlCore)
DRV - [2004/04/14 10:08:00 | 000,021,280 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmFilter.sys – (WmFilter)
DRV - [2004/04/14 10:08:00 | 000,014,432 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmHidLo.sys – (WmHidLo)
DRV - [2004/04/14 10:08:00 | 000,010,144 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmBEnum.sys – (WmBEnum)
DRV - [2004/04/14 10:08:00 | 000,005,600 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmVirHid.sys – (WmVirHid)
DRV - [2004/04/13 19:20:08 | 000,015,781 | R— | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2001/08/17 13:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sbc.yahoo.com/dsl
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.4.3
FF - prefs.js..extensions.enabledItems: [removed]:1.2.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..network.proxy.type: 2

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/27 02:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/27 02:50:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/26 03:09:03 | 000,000,000 | —D | M]

[2010/03/27 00:41:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Extensions
[2011/01/24 05:51:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions
[2010/06/26 21:49:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/12 22:30:09 | 000,000,000 | —D | M] (Smart Bookmarks Bar) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\[removed]
[2010/07/26 21:03:06 | 000,000,000 | —D | M] ("Broadband Speed Test and Diagnostics") – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\[removed]
[2010/10/27 23:30:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/27 02:50:17 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/07/31 12:06:48 | 001,654,784 | —- | M] (LizardTech) – C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()
O4 - HKLM..\Run: [GBTUpd] C:\Program Files\Gigabyte\GBTUpd\PreRun.exe (PreRun)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
O4 - HKLM..\RunOnce: [EasyTuneVI] C:\Program Files\Gigabyte\ET6\ETcall.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O15 - HKCU\..Trusted Domains: samsungportal.com ([]* in Trusted sites)
O16 - DPF: {01025D1C-BB03-4369-8344-732CD0DCCCF0} http://www.geforce.com/services_toolkit/Sh…/GPU_Reader.cab (NVIDIA GPU Reader Class)
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.gigabyte.com.tw/object/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {714E667D-360C-4BFB-8C1A-E4812B608CC1} http://service.samsungportal.com/EP/web/co…rustChecker.cab (ACUBETrustChecker Control)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/26 21:18:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/10/27 02:40:21 | 000,402,696 | R— | M] (Electronic Arts) - D:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:17 | 000,000,000 | R–D | M] - D:\Autorun – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:26 | 002,084,352 | R— | M] () - D:\autorun.dat – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:16 | 000,000,155 | R— | M] () - D:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2006/02/11 20:54:47 | 000,000,000 | -HS- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/09/03 23:44:23 | 000,000,000 | —D | M] - F:\AUTO – [ NTFS ]
O32 - AutoRun File - [2006/02/11 20:54:47 | 000,000,000 | -HS- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/11/28 11:44:10 | 008,188,928 | —- | M] () - F:\Autotap 3.00.msi – [ NTFS ]
O33 - MountPoints2\D\Shell - "" = AutoRun
O33 - MountPoints2\D\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Launch.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2011/01/27 01:34:31 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
[2011/01/25 14:56:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011/01/25 14:48:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/01/25 02:25:42 | 000,000,000 | RH-D | C] – C:\Documents and Settings\MIKE\Application Data\SecuROM
[2011/01/24 07:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Disney Interactive Studios
[2011/01/24 04:39:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/24 01:47:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SiSoftware
[2011/01/24 01:47:41 | 000,000,000 | —D | C] – C:\Program Files\SiSoftware
[2011/01/23 12:20:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2011/01/23 12:17:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Empire Interactive
[2011/01/23 02:52:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\MIKE\Desktop\Hijack This.exe
[2011/01/23 02:28:17 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/01/19 00:41:43 | 000,000,000 | —D | C] – C:\Program Files\Empire Interactive
[2011/01/18 23:04:44 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\Application Data\Disney Interactive Studios
[2011/01/18 23:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\Application Data\Leadertech
[2011/01/18 22:42:47 | 000,000,000 | —D | C] – C:\Program Files\Disney Interactive Studios
[2011/01/18 02:21:48 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\My Documents\NFS ProStreet
[2011/01/18 01:35:59 | 000,000,000 | —D | C] – C:\Program Files\Electronic Arts
[2011/01/04 09:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ubisoft
[2011/01/04 09:06:19 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2011/01/01 00:02:18 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\My Documents\RED LIGHT
[2010/03/31 14:28:05 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2std.dll
[2010/03/31 14:28:05 | 000,077,824 | —- | C] ( ) – C:\WINDOWS\System32\csnp2std.dll
[2005/08/07 16:13:46 | 000,060,928 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
[2011/01/27 01:32:37 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
[2011/01/27 01:32:36 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
[2011/01/27 01:16:32 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/27 01:15:39 | 000,436,228 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/01/27 01:15:39 | 000,068,680 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/01/27 01:12:04 | 000,024,944 | —- | M] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011/01/27 01:12:04 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\GVTunner.ref
[2011/01/27 01:11:44 | 000,012,664 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/27 01:11:30 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/27 01:11:30 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/01/27 01:11:29 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
[2011/01/27 01:11:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/26 12:36:22 | 000,055,080 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/26 12:36:22 | 000,055,080 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/26 12:36:22 | 000,000,788 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/26 08:55:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/26 08:52:58 | 000,022,328 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/01/25 14:49:35 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/01/24 07:14:55 | 000,001,048 | —- | M] () – C:\WINDOWS\disney.ini
[2011/01/24 07:14:25 | 000,001,767 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Pure.lnk
[2011/01/24 01:48:02 | 000,000,991 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SiSoftware Sandra Lite 2011b.lnk
[2011/01/24 00:03:39 | 000,241,476 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/24 00:03:39 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/24 00:03:38 | 000,241,472 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/23 17:58:09 | 000,001,857 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Need for Speed™ ProStreet.lnk
[2011/01/23 13:55:43 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/01/23 13:39:19 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/01/23 12:18:04 | 000,000,868 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FlatOut 2.lnk
[2011/01/23 11:40:22 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/01/23 02:52:12 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\MIKE\Desktop\Hijack This.exe
[2011/01/22 01:36:05 | 000,055,536 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/22 01:36:05 | 000,055,536 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/22 01:36:05 | 000,000,788 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/15 02:14:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
[2011/01/13 03:00:49 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/01/04 09:12:43 | 000,001,858 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Driver Parallel Lines.lnk
[2010/12/31 23:58:15 | 000,019,968 | —- | M] () – C:\Documents and Settings\MIKE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/29 05:16:52 | 000,002,391 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CalMAN Pattern Generator.lnk
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/25 14:54:31 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/25 14:49:35 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/01/25 00:03:58 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\GVTunner.ref
[2011/01/24 07:14:25 | 000,001,767 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Pure.lnk
[2011/01/24 07:11:58 | 000,001,048 | —- | C] () – C:\WINDOWS\disney.ini
[2011/01/24 01:48:02 | 000,000,991 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SiSoftware Sandra Lite 2011b.lnk
[2011/01/24 01:47:44 | 010,948,608 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sandra.mda
[2011/01/23 18:02:51 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/01/23 18:02:50 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/01/23 18:02:44 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/01/23 17:58:09 | 000,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Need for Speed™ ProStreet.lnk
[2011/01/23 13:11:49 | 000,055,080 | —- | C] () – C:\WINDOWS\System32\BMXStateBkp-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 13:11:49 | 000,055,080 | —- | C] () – C:\WINDOWS\System32\BMXState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 13:11:49 | 000,000,788 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 12:18:04 | 000,000,868 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FlatOut 2.lnk
[2011/01/23 11:40:22 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/01/04 09:12:43 | 000,001,858 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Driver Parallel Lines.lnk
[2010/10/26 21:31:24 | 000,155,712 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/06/22 15:49:25 | 000,114,688 | R— | C] () – C:\WINDOWS\System32\EDCode.dll
[2010/06/22 15:49:25 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CryptoSeed.dll
[2010/06/22 15:49:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\SftpApi.dll
[2010/06/22 15:49:25 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\ShttpApi.dll
[2010/04/19 07:30:49 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/04/05 14:28:18 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/04/01 22:06:01 | 000,053,063 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2010/04/01 22:06:01 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2010/04/01 22:05:51 | 000,002,038 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\HPSU_48BitScanUpdate.log
[2010/04/01 22:05:51 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2010/04/01 22:00:59 | 000,204,661 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2010/04/01 22:00:59 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2010/03/31 14:28:06 | 000,015,497 | —- | C] () – C:\WINDOWS\snp2std.ini
[2010/03/31 14:28:05 | 012,212,864 | —- | C] () – C:\WINDOWS\System32\drivers\snp2sxp.sys
[2010/03/31 14:28:05 | 000,025,472 | —- | C] () – C:\WINDOWS\System32\drivers\sncamd.sys
[2010/03/31 14:17:30 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/30 14:27:42 | 000,001,076 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/03/29 06:58:51 | 000,019,968 | —- | C] () – C:\Documents and Settings\MIKE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/27 15:18:29 | 000,000,138 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/03/26 23:10:16 | 000,024,944 | —- | C] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2010/03/26 22:56:38 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/03/26 22:52:16 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2010/03/26 14:38:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/06/04 01:37:08 | 000,021,093 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/06/04 01:37:06 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/06/04 00:55:20 | 000,002,560 | —- | C] () – C:\WINDOWS\System32\CtxfiRes.dll
[2009/06/04 00:55:20 | 000,002,560 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2007/04/12 21:44:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/08/07 16:19:00 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2005/06/07 07:10:50 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2003/03/21 03:56:12 | 000,000,285 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 14:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2010/04/04 13:53:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Codemasters
[2010/07/13 09:04:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MoTeC
[2010/05/08 10:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Music Coach
[2010/03/27 17:49:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/04/04 12:14:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrackMania
[2011/01/18 23:04:44 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\Disney Interactive Studios
[2010/12/08 03:20:28 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\FUEL
[2010/12/22 22:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\Image Zone Express
[2011/01/18 23:00:53 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\Leadertech
[2010/07/17 01:53:27 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\Music Coach
[2010/04/02 23:19:22 | 000,000,000 | —D | M] – C:\Documents and Settings\MIKE\Application Data\SpaceMonger
[2011/01/27 01:16:32 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/01/27 01:11:30 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/11/05 18:34:11 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2010/11/05 18:34:11 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010/03/26 14:31:39 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/03/26 14:31:39 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/03/26 14:31:39 | 000,933,888 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemdrive%\*.sys /90 /md5 >
[2011/01/27 01:11:14 | 2145,386,496 | -HS- | M] () Unable to obtain MD5 – C:\pagefile.sys

< >

< End of report >
OTL Extras logfile created on: 1/27/2011 1:36:41 AM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MIKE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 80.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 868.16 Gb Free Space | 93.20% Space Free | Partition Type: NTFS
Drive D: | 4.64 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 69.23 Gb Total Space | 39.39 Gb Free Space | 56.89% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 179.49 Gb Free Space | 77.07% Space Free | Partition Type: NTFS

Computer Name: GCDI-F7150E40D8 | User Name: MIKE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [SpaceMonger] – "F:\Program Files\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3074:TCP" = 3074:TCP:*:Enabled:fuel
"3074:UDP" = 3074:UDP:*:Enabled:fuel

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Gigabyte\GBTUpd\GBTUpd.exe" = C:\Program Files\Gigabyte\GBTUpd\GBTUpd.exe:*:Enabled:GBTUpd.exe – (GIGABYTE)
"C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe" = C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe:*:Enabled:RunUpd – (Gigabyte)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"E:\Program Files\TmUnitedForever\TmForever.exe" = E:\Program Files\TmUnitedForever\TmForever.exe:*:Enabled:TmForever – ()
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe" = C:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe:*:Enabled:Xpand Rally
"C:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe" = C:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe:*:Enabled:Xpand Rally
"C:\Program Files\Gigabyte\ET6\UpdExe.exe" = C:\Program Files\Gigabyte\ET6\UpdExe.exe:*:Enabled:Exe File – (GIGABYTE)
"C:\Program Files\Gigabyte\ET6\GBTUpd.exe" = C:\Program Files\Gigabyte\ET6\GBTUpd.exe:*:Enabled:GBTUpd.exe – (GIGABYTE)
"E:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe" = E:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe:*:Enabled:Xpand Rally – (Techland)
"E:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe" = E:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe:*:Enabled:Xpand Rally – (Techland)
"E:\Program Files\Steam\steamapps\common\gti racing\GTIRacing.exe" = E:\Program Files\Steam\steamapps\common\gti racing\GTIRacing.exe:*:Enabled:GTI Racing – (Techland)
"C:\Program Files\Codemasters\GRID\GRID.exe" = C:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID – (Codemasters)
"C:\Program Files\Codemasters\DiRT\DiRT.exe" = C:\Program Files\Codemasters\DiRT\DiRT.exe:*:Enabled:DiRT Executable – (Codemasters)
"E:\Program Files\Activision Value\Baja 1000\Baja.exe" = E:\Program Files\Activision Value\Baja 1000\Baja.exe:*:Disabled:Baja – ()
"C:\Program Files\real\realplayer\realplay.exe" = C:\Program Files\real\realplayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service
"C:\Program Files\Codemasters\FUEL\FUEL.exe" = C:\Program Files\Codemasters\FUEL\FUEL.exe:*:Enabled:FUEL – (Codemasters)
"F:\GCDI\GCDI TECH\GCDI-TECH-INFO\PATTERN GENERATOR\PatGen.exe" = F:\GCDI\GCDI TECH\GCDI-TECH-INFO\PATTERN GENERATOR\PatGen.exe:*:Disabled:CalMAN Pattern Generator – (SpectraCal, LLC)
"C:\Program Files\Electronic Arts\Need for Speed ProStreet\nfs.exe" = C:\Program Files\Electronic Arts\Need for Speed ProStreet\nfs.exe:*:Enabled:nfs – ()
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service – (SiSoftware)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service – (SiSoftware)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{1064CABD-7390-4336-94E4-8A53DFBCB636}_is1" = GT Legends 1.1.0.0
"{1619204B-7F8C-4293-B342-5345721F4A1F}_is1" = GTR 2 1.0.0.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}" = Sound Blaster X-Fi
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{310609F9-5F1C-475C-A49D-8A2AC3D53022}" = Instant Play Electric Guitar 4 CD-ROM
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{31CB0D80-1866-462A-9455-88614410971F}" = Driver: Parallel Lines
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Cinfigurer
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0728.1
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B09.1008.1
"{4E6D2462-AB33-40BB-AA9F-3FA3E0DD0290}" = FlatOut 2
"{53CDAAAB-6D41-4A36-BAA4-90261DE31B13}" = NetZero For Cosmi
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57B89E30-0BBA-4F20-9F2C-8E8CDE1CEDB6}" = DiRT
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5EBAC9CB-97D7-44CD-A82D-4FCB37F582AC}" = World Racing 2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68CEE564-F0FE-4E69-8DBC-0DE23987AABA}" = Projector Calculator 1.23
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{71A7DBB4-D82B-4BC4-9FD4-0C1833E34784}" = CodeAxNew
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = Digital Viewer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{817DE62F-5787-43BB-8877-5F81FAE5A823}" = ACUBE UniSSOTray V1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{86076752-37A4-41E6-BFC4-73186683AF7B}" = Sprint Cars - Road to Knoxville
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.06
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.36
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B75A978D-A9B0-4344-871E-9145F237A237}" = Music Coach Player
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}" = Need for Speed™ SHIFT
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Lite 2011b
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CC419DDC-E0F0-4013-B25A-6FA036516F0D}" = Need for Speed™ ProStreet
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E33956B7-301C-429D-9E6C-2C12EACB8A62}" = NWZ-E340 WALKMAN Guide
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F51FF206-2273-4B3E-A90A-4752AE288C12}" = FUEL
"{FAC36425-4266-4DE4-9CB5-68FB4FB9385A}" = CalMAN Pattern Generator
"{FDC8065B-80DE-4466-B90B-2581F6D77DFF}" = Image Plugin
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}" = Pure
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AudioCS" = Creative Audio Control Panel
"Baja 1000" = SCORE International: Baja 1000
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"DriverAgent.exe" = DriverAgent by eSupport.com
"Google Chrome" = Google Chrome
"GTR Evolution_1.1.1.2_is1" = GTR Evolution
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0728.1
"InstallShield_{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B09.1008.1
"InstallShield_{5EBAC9CB-97D7-44CD-A82D-4FCB37F582AC}" = World Racing 2
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"RACE 07 Offline_1.0_is1" = RACE 07 Offline
"RealPlayer 12.0" = RealPlayer
"rFactor" = rFactor (remove only)
"Steam App 3000" = GTI Racing
"Steam App 3010" = Xpand Rally
"SysInfo" = Creative System Information
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/23/2011 2:14:01 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application officelivesignin.exe, version 2.0.2313.0, faulting
module officelivesignin.exe, version 2.0.2313.0, fault address 0x00003ce4.

Error - 1/23/2011 4:29:14 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/23/2011 6:58:23 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/24/2011 7:33:30 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:34:32 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:36:33 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:46:55 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 2:53:50 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x6ce19a67.

Error - 1/25/2011 4:22:33 AM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/25/2011 4:49:24 PM | Computer Name = GCDI-F7150E40D8 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 1/25/2011 2:03:23 AM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/25/2011 2:03:26 AM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/25/2011 4:32:52 PM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/25/2011 4:32:52 PM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/26/2011 5:09:16 AM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/26/2011 5:09:27 AM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/26/2011 2:31:23 PM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/26/2011 2:31:26 PM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/27/2011 3:11:37 AM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/27/2011 3:11:40 AM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058


< End of report >
RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #4 ============================================== >Drivers ============================================== 0xB241D000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 9625600 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 260.99 ) 0xBD012000 C:\WINDOWS\System32\nv4_disp.dll 6361088 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 260.99 ) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2150400 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2150400 bytes 0x804D7000 RAW 2150400 bytes 0x804D7000 WMIxWDM 2150400 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xAB28C000 C:\WINDOWS\System32\drivers\CTEXFIFX.SYS 1339392 bytes (Creative Technology Ltd., Creative XFi Effects) 0xAB935000 C:\WINDOWS\system32\drivers\ha20x2k.sys 1191936 bytes (Creative Technology Ltd, Creative 20X HAL (WDM)) 0xAB7FB000 C:\WINDOWS\system32\drivers\ctac32k.sys 638976 bytes (Creative Technology Ltd, Creative AC3 SW Decoder Device Driver (WDM)) 0xB7DDD000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB22FE000 C:\WINDOWS\system32\drivers\ctaud2k.sys 520192 bytes (Creative Technology Ltd, Creative WDM Audio Device Driver) 0xAB0CE000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB21EF000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xAB1D9000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xA9AC6000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xA9492000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB22A5000 C:\WINDOWS\system32\drivers\ctoss2k.sys 217088 bytes (Creative Technology Ltd., Creative OS Services Driver (WDM)) 0xAB905000 C:\WINDOWS\system32\drivers\emupia2k.sys 196608 bytes (Creative Technology Ltd, E-mu Plug-in Architecture Driver (WDM)) 0xB224D000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector) 0xB7F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xA9342000 C:\Program Files\GIGABYTE\ET6\i386\AODDriver.sys 188416 bytes (Advanced Micro Devices, AMD OverDrive Service Driver) 0xA9CD6000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB7DB0000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xAB3D3000 C:\WINDOWS\System32\drivers\CT20XUT.SYS 180224 bytes (Creative Technology Ltd., Creative 20X Utility Effects) 0xA91D8000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xAB13E000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xAB897000 C:\WINDOWS\system32\drivers\ctsfm2k.sys 167936 bytes (Creative Technology Ltd, SoundFont® Manager (WDM)) 0xAB1B1000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xAB265000 C:\WINDOWS\system32\DRIVERS\MpFilter.sys 159744 bytes (Microsoft Corporation, Microsoft antimalware file system filter driver) 0xB7F11000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver) 0xAB18B000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xA931E000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xB22DA000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB23A0000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB237D000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB23C4000 C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 143360 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xAB169000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xB23E7000 C:\WINDOWS\system32\DRIVERS\nusb3xhc.sys 139264 bytes (NEC Electronics Corporation, USB 3.0 Host Controller Driver) 0x806E4000 ACPI_HAL 134400 bytes 0x806E4000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB7EA6000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB7F37000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB7EF6000 jraid.sys 110592 bytes (JMicron Technology Corp., JMicron JMB36X RAID Driver) 0xB7D5D000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB7EC6000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xAB044000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB7EDE000 C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xB7E7D000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB228E000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xAB3FF000 C:\WINDOWS\System32\drivers\CTHWIUT.SYS 86016 bytes (Creative Technology Ltd., Creative Utility Effects) 0xAA259000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB7D9C000 sfvfs02.sys 81920 bytes (Protection Technology, StarForce Protection VFS Driver) 0xB2409000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xAB232000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xB7D77000 pe3ah4nc.sys 77824 bytes (CODEMASTERS, DiRT Environment Driver) 0xB7E6A000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBD000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB7F56000 ps6ah4nc.sys 73728 bytes (CODEMASTERS, DiRT Synchronization Driver) 0xB7D8A000 sfdrv01.sys 73728 bytes (Protection Technology, StarForce Protection Environment Driver) 0xB7E94000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xAB095000 C:\WINDOWS\system32\DRIVERS\LMouKE.Sys 69632 bytes (Logitech, Inc., Logitech Filter Driver for Mouse Class.) 0xB7F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB227D000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xAB05C000 C:\WINDOWS\System32\Drivers\Udfs.SYS 69632 bytes (Microsoft Corporation, UDF File System Driver) 0xB8218000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xB8248000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager) 0xB80B8000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xB8258000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xAB639000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client) 0xB8238000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xB8228000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xAFC85000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xB354F000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xB80C8000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xB355F000 C:\WINDOWS\system32\DRIVERS\nusb3hub.sys 57344 bytes (NEC Electronics Corporation, USB 3.0 Hub Driver) 0xB81F8000 C:\WINDOWS\system32\DRIVERS\AmdPPM.sys 53248 bytes (Advanced Micro Devices, AMD Processor Driver) 0xB8118000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xAB562000 C:\WINDOWS\system32\DRIVERS\HPZid412.sys 53248 bytes (HP, IEEE-1284.4-1999 Driver (Windows 2000)) 0xB8268000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xB8278000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xB80F8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xB8298000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xAB5D2000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xB8208000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xB80D8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xB8288000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xB82C8000 C:\WINDOWS\system32\drivers\WmXlCore.sys 45056 bytes (Logitech Inc., Logitech WingMan Translation Driver) 0xB80A8000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xB8318000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xB82B8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xB8108000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xAB582000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xB82A8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xAB649000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xA96C6000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xB80E8000 sfsync02.sys 36864 bytes (Protection Technology, StarForce Protection Synchronization Driver) 0xAB659000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xB8488000 C:\WINDOWS\system32\drivers\ctprxy2k.sys 32768 bytes (Creative Technology Ltd, Creative Proxy Device Driver (WDM)) 0xB84A0000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xAB796000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xB8338000 sfhlp02.sys 32768 bytes (Protection Technology, StarForce Protection Helper Driver) 0xB8470000 C:\WINDOWS\system32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xB8480000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xB8490000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xB83B8000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xAB776000 C:\WINDOWS\system32\DRIVERS\LHidKE.Sys 28672 bytes (Logitech, Inc., Logitech HID Filter Driver.) 0xB8328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xAB78E000 C:\WINDOWS\system32\DRIVERS\usbprint.sys 28672 bytes (Microsoft Corporation, USB Printer driver) 0xAB786000 C:\WINDOWS\system32\DRIVERS\HPZius12.sys 24576 bytes (HP, 1284.4<->Usb Datalink Driver (Windows 2000)) 0xB8498000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xB83A0000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xAB4F8000 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A32EC7-2EC3-4C22-8ABC-546DCD6D468C}\MpKsl96232e8d.sys 24576 bytes (Microsoft Corporation, KSLDriver) 0xAB7A6000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xAB77E000 C:\WINDOWS\system32\drivers\WmFilter.sys 24576 bytes (Logitech Inc., Logitech WingMan Hid Filter Driver) 0xB8458000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xAB79E000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xB8330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xB84B0000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xB8358000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xB84A8000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xB8478000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0xAB76E000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xA95A6000 C:\WINDOWS\system32\Drivers\GVTDrv.sys 16384 bytes 0xB7D21000 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys 16384 bytes (HP, IEEE-1284.4-1999 Print Class Driver) 0xAA27E000 C:\WINDOWS\system32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB3B6F000 C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys 16384 bytes (Logitech, Inc., Logitech PS2 Keyboard Filter Driver.) 0xAA436000 C:\WINDOWS\system32\DRIVERS\mdc8021x.sys 16384 bytes (Meetinghouse Data Communications, IEEE 802.1X Protocol Driver) 0xB8558000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xAA42A000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xB3B73000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xB7D2D000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver) 0xAB8DD000 C:\WINDOWS\system32\drivers\WmHidLo.sys 16384 bytes (Logitech Inc., Logitech WingMan Hid Lower Filter Driver) 0xB84B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB2D67000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xA95C2000 C:\WINDOWS\gdrv.sys 12288 bytes (Windows ® 2000 DDK provider, GIGABYTE Tools) 0xB85A0000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xB7D29000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xB3B6B000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB8594000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xB855C000 C:\WINDOWS\system32\drivers\WmBEnum.sys 12288 bytes (Logitech Inc., Logitech WingMan Virtual Bus Enumerator Driver ) 0xB3B7F000 C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xB85E4000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xB85AC000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver) 0xB8608000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xB85E2000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xB85A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xB85E6000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xB85E8000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xB85F6000 C:\WINDOWS\System32\Drivers\RootMdm.sys 8192 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver) 0xB85F8000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xB85F4000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xB85AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xB8658000 C:\WINDOWS\system32\drivers\WmVirHid.sys 8192 bytes (Logitech Inc., Logitech WingMan Virtual Hid Device Driver) 0xB8760000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xB8765000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xB87A0000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xB8670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
Hi,

Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



——————————————————————–

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
ComboFix 11-01-27.01 - MIKE 01/27/2011 13:10:02.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2525 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\schrauber.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-12-27 to 2011-01-27 )))))))))))))))))))))))))))))))
.

2011-01-27 18:50 . 2011-01-27 18:50 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2011-01-27 18:50 . 2011-01-27 18:50 ——– d—–w- c:\program files\McAfee Security Scan
2011-01-27 18:38 . 2011-01-27 18:38 28752 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A32EC7-2EC3-4C22-8ABC-546DCD6D468C}\MpKsl5e8e21ba.sys
2011-01-27 07:22 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A32EC7-2EC3-4C22-8ABC-546DCD6D468C}\mpengine.dll
2011-01-25 20:48 . 2011-01-13 09:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-01-25 20:48 . 2011-01-25 20:49 ——– d—–w- c:\program files\Microsoft Security Client
2011-01-25 08:25 . 2011-01-25 08:25 ——– d–h–r- c:\documents and settings\MIKE\Application Data\SecuROM
2011-01-24 10:39 . 2011-01-24 11:47 ——– d—–w- c:\windows\system32\NtmsData
2011-01-24 07:49 . 2011-01-24 07:49 2263 ——w- c:\documents and settings\All Users\Application Data\xml30A.tmp
2011-01-24 07:49 . 2011-01-24 07:49 7291 ——w- c:\documents and settings\All Users\Application Data\xml308.tmp
2011-01-24 07:49 . 2011-01-24 07:49 13678 ——w- c:\documents and settings\All Users\Application Data\xml309.tmp
2011-01-24 07:49 . 2010-06-02 10:55 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll
2011-01-24 07:49 . 2010-06-02 10:55 527192 —-a-w- c:\windows\system32\XAudio2_7.dll
2011-01-24 07:49 . 2010-06-02 10:55 239960 —-a-w- c:\windows\system32\xactengine3_7.dll
2011-01-24 07:49 . 2010-05-26 17:41 2106216 —-a-w- c:\windows\system32\D3DCompiler_43.dll
2011-01-24 07:49 . 2010-05-26 17:41 248672 —-a-w- c:\windows\system32\d3dx11_43.dll
2011-01-24 07:49 . 2010-05-26 17:41 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll
2011-01-24 07:49 . 2010-05-26 17:41 470880 —-a-w- c:\windows\system32\d3dx10_43.dll
2011-01-24 07:49 . 2010-05-26 17:41 1998168 —-a-w- c:\windows\system32\D3DX9_43.dll
2011-01-24 07:47 . 2011-01-24 07:47 ——– d—–w- c:\program files\SiSoftware
2011-01-24 00:02 . 2011-01-24 06:04 66872 —-a-w- c:\windows\system32\PnkBstrA.exe
2011-01-24 00:02 . 2011-01-26 14:52 22328 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-01-24 00:02 . 2011-01-27 11:25 103736 —-a-w- c:\windows\system32\PnkBstrB.exe
2011-01-23 18:20 . 2011-01-23 18:20 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2011-01-23 18:18 . 2004-08-09 12:03 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
2011-01-23 18:18 . 2004-08-09 12:03 368640 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\_isusres.dll
2011-01-23 18:18 . 2004-08-09 12:03 512000 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\agent.exe
2011-01-23 18:18 . 2004-08-09 12:02 217088 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISDM.exe
2011-01-23 18:17 . 2004-10-22 08:17 69715 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2011-01-23 18:17 . 2004-10-22 08:17 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2011-01-23 18:17 . 2004-10-22 08:16 180224 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2011-01-23 18:17 . 2004-10-22 08:16 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2011-01-23 18:17 . 2004-10-22 08:18 749568 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2011-01-23 18:17 . 2011-01-23 18:17 192644 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2011-01-23 18:17 . 2011-01-23 18:17 323716 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2011-01-23 07:14 . 2011-01-23 07:14 ——– d—–w- c:\windows\system32\wbem\Repository
2011-01-19 06:41 . 2011-01-19 06:41 ——– d—–w- c:\program files\Empire Interactive
2011-01-19 05:04 . 2011-01-19 05:04 ——– d—–w- c:\documents and settings\MIKE\Application Data\Disney Interactive Studios
2011-01-19 05:00 . 2011-01-19 05:00 ——– d—–w- c:\documents and settings\MIKE\Application Data\Leadertech
2011-01-19 04:42 . 2011-01-19 04:42 ——– d—–w- c:\program files\Disney Interactive Studios
2011-01-18 07:35 . 2011-01-18 07:35 ——– d—–w- c:\program files\Electronic Arts
2011-01-04 15:06 . 2011-01-04 15:06 ——– d—–w- c:\program files\Ubisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-27 19:06 . 2010-03-27 05:10 24944 —-a-w- c:\windows\system32\drivers\GVTDrv.sys
2011-01-27 18:38 . 2010-03-31 22:55 17488 —-a-w- c:\windows\gdrv.sys
2011-01-24 14:02 . 2010-03-27 07:02 17488 —-a-w- c:\windows\etdrv.sys
2011-01-23 17:32 . 2010-03-31 18:00 2263 -c—-w- c:\documents and settings\All Users\Application Data\xml52.tmp
2011-01-23 17:32 . 2010-03-31 18:00 13678 -c—-w- c:\documents and settings\All Users\Application Data\xml51.tmp
2011-01-23 17:32 . 2010-03-31 18:00 7291 -c—-w- c:\documents and settings\All Users\Application Data\xml50.tmp
2011-01-13 09:41 . 2010-10-27 03:43 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2010-12-27 08:49 . 2010-03-27 21:17 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-12-27 08:49 . 2010-03-27 21:17 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-12-08 08:55 . 2010-03-29 10:53 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-12-08 08:55 . 2010-03-29 10:53 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-11-29 23:38 . 2010-11-29 23:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2010-03-27 03:16 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-16 08:25 . 2009-08-18 17:24 17816 ——w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2010-11-09 14:52 . 2004-08-04 12:00 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:34 . 2004-08-04 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:34 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-11-06 00:34 . 2004-08-04 12:00 1830912 ——w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:34 . 2004-08-04 12:00 17408 ——w- c:\windows\system32\corpol.dll
2010-11-03 12:25 . 2004-08-04 12:00 389120 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2004-04-23 77824]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"tsnp2std"="c:\windows\tsnp2std.exe" [2007-08-31 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2007-08-07 348160]
"RTHDCPL"="RTHDCPL.EXE" [2009-10-16 18782720]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-08-26 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
"NUSB3MON"="c:\program files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-09-25 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-23 28160]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-08 176128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"GBTUpd"="c:\program files\GIGABYTE\GBTUpd\PreRun.exe" [2008-04-03 297480]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2009-08-26 1970176]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-04 25600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-12-27 202256]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"EasyTuneVI"="c:\program files\GIGABYTE\ET6\ETCall.exe" [2007-07-26 20480]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gigabyte\\GBTUpd\\GBTUpd.exe"=
"c:\\Program Files\\Gigabyte\\GBTUpd\\RunUpd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"e:\\Program Files\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Gigabyte\\ET6\\UpdExe.exe"=
"c:\\Program Files\\Gigabyte\\ET6\\GBTUpd.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\xpand rally\\xpandrally.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\xpand rally\\ChromEd.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\gti racing\\GTIRacing.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Codemasters\\DiRT\\DiRT.exe"=
"e:\\Program Files\\Activision Value\\Baja 1000\\Baja.exe"=
"c:\\Program Files\\real\\realplayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Codemasters\\FUEL\\FUEL.exe"=
"f:\\GCDI\\GCDI TECH\\GCDI-TECH-INFO\\PATTERN GENERATOR\\PatGen.exe"=
"c:\\Program Files\\Electronic Arts\\Need for Speed ProStreet\\nfs.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011b\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2011b\\WNt500x86\\RpcSandraSrv.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3074:TCP"= 3074:TCP:fuel
"3074:UDP"= 3074:UDP:fuel

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 pe3ah4nc;DiRT Environment Driver (pe3ah4nc);c:\windows\system32\drivers\pe3ah4nc.sys [5/18/2007 1:53 PM 64880]
R0 ps6ah4nc;DiRT Synchronization Driver (ps6ah4nc);c:\windows\system32\drivers\ps6ah4nc.sys [5/18/2007 1:52 PM 55160]
R1 MpKsl5e8e21ba;MpKsl5e8e21ba;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{98A32EC7-2EC3-4C22-8ABC-546DCD6D468C}\MpKsl5e8e21ba.sys [1/27/2011 12:38 PM 28752]
R2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [3/26/2010 10:53 PM 219360]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [3/26/2010 10:52 PM 68136]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 2:46 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 2:46 AM 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 2:46 AM 72728]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [9/25/2009 8:57 AM 56576]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [9/25/2009 8:57 AM 138240]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/25/2010 12:34 AM 136176]
S2 pr2ah4nc;DiRT Drivers Auto Removal (pr2ah4nc);c:\windows\system32\pr2ah4nc.exe svc –> c:\windows\system32\pr2ah4nc.exe svc [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3/26/2010 10:53 PM 1684736]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [12/8/2010 2:56 AM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 2:46 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 2:46 AM 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 2:46 AM 72728]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [7/4/2010 5:41 AM 23456]
S3 etdrv;etdrv;c:\windows\etdrv.sys [3/27/2010 1:02 AM 17488]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 6:49 AM 227232]
S3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\drivers\rcblan.sys [3/28/2010 12:46 PM 39704]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe [1/24/2011 1:47 AM 93848]
SUnknown GVTDrv;GVTDrv; [x]

— Other Services/Drivers In Memory —

*NewlyCreated* - AODDRIVER
*NewlyCreated* - MPKSL5E8E21BA
*Deregistered* - AODDriver
.
Contents of the 'Scheduled Tasks' folder

2011-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-25 06:33]

2011-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-25 06:33]

2011-01-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]

2011-01-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]

2011-01-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]

2011-01-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]

2011-01-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]

2011-01-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 17:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://sbc.yahoo.com/dsl
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
Trusted Zone: samsungportal.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {01025D1C-BB03-4369-8344-732CD0DCCCF0} - hxxp://www.geforce.com/services_toolkit/ShimGen/1.1.28.1/GPU_Reader.cab
DPF: {714E667D-360C-4BFB-8C1A-E4812B608CC1} - hxxp://service.samsungportal.com/EP/web/common/cabfiles/ACUBETrustChecker.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
FF - ProfilePath - c:\documents and settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Smart Bookmarks Bar: [removed] - %profile%\extensions\[removed]
FF - Ext: Broadband Speed Test and Diagnostics: [removed] - %profile%\extensions\[removed]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\FlashUtil10k_Plugin.exe
AddRemove-{31CB0D80-1866-462A-9455-88614410971F} - c:\program files\InstallShield Installation Information\{31CB0D80-1866-462A-9455-88614410971F}\setup.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-27 13:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-01-27 13:15:40
ComboFix-quarantined-files.txt 2011-01-27 19:15

Pre-Run: 931,900,207,104 bytes free
Post-Run: 932,784,693,248 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 14EA4DDF892CAA9B653B45AB329CD7F8
Hi,

How is it running now?


Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic



Please open OTL, set the extra registry tab to use safe list and hit the run scan button, post back with the 2 logfiles.
Seems to be running okay, really doesn't seem different than before.
Have you seen things so far that should have made a difference?

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.17093 (vista_gdr.101017-1200)
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=f76605431b3e9b4089caac30374c2826
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-01-29 06:37:28
# local_time=2011-01-29 12:37:28 (-0600, Central Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776869 42 87 0 7376441 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=424672
# found=3
# cleaned=3
# scan_time=7871
C:\WINDOWS\FixCamera.exe a variant of Win32/KillProc.A application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
F:\MOVED FROM E\Ascentive\Performance Center\ApcMain.exe Win32/Adware.Ascentive application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
F:\MY VARIOUS STUFF\My Downloads\SpeedScan.setup.exe Win32/Adware.Ascentive application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C


OTL logfile created on: 1/29/2011 1:05:44 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MIKE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 868.89 Gb Free Space | 93.28% Space Free | Partition Type: NTFS
Drive D: | 4.64 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 69.23 Gb Total Space | 39.42 Gb Free Space | 56.94% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 179.49 Gb Free Space | 77.07% Space Free | Partition Type: NTFS

Computer Name: GCDI-F7150E40D8 | User Name: MIKE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
PRC - [2010/12/27 02:49:25 | 000,202,256 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/11/30 13:20:36 | 000,997,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/01/15 06:49:20 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2009/11/19 17:15:46 | 000,583,016 | —- | M] (Sony Corporation) – C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
PRC - [2009/09/25 08:59:18 | 000,106,496 | —- | M] (NEC Electronics Corporation) – C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
PRC - [2009/08/24 14:38:06 | 000,068,136 | —- | M] () – C:\Program Files\Gigabyte\EasySaver\essvr.exe
PRC - [2009/08/04 17:29:54 | 000,219,360 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2009/08/04 17:29:52 | 000,346,320 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2009/07/17 13:47:44 | 000,322,088 | —- | M] (Gigabyte) – C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe
PRC - [2009/06/04 00:55:16 | 000,025,600 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\Ctxfihlp.exe
PRC - [2009/06/04 00:49:56 | 001,213,440 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTxfispi.exe
PRC - [2009/02/23 11:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/25 16:21:56 | 000,219,656 | —- | M] () – C:\Program Files\Gigabyte\ET6\GUI.exe
PRC - [2007/08/31 09:48:28 | 000,262,144 | —- | M] () – C:\WINDOWS\tsnp2std.exe
PRC - [2007/08/09 01:27:52 | 000,073,728 | —- | M] (HP) – C:\WINDOWS\system32\HPZipm12.exe
PRC - [2007/08/07 12:49:18 | 000,348,160 | —- | M] (Sonix) – C:\WINDOWS\vsnp2std.exe
PRC - [2006/12/12 10:46:52 | 000,019,456 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CtHelper.exe
PRC - [2005/03/07 22:42:09 | 000,176,128 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
PRC - [2004/12/02 17:23:34 | 000,102,400 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PRC - [2004/04/23 13:28:00 | 000,077,824 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Profiler\LWEMon.exe


========== Modules (SafeList) ==========

MOD - [2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
MOD - [2010/12/27 02:50:17 | 000,040,960 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2010/08/23 10:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2005/08/07 16:10:18 | 000,007,168 | —- | M] (Creative Technology Ltd) – C:\WINDOWS\system32\CTAGENT.DLL
MOD - [2004/04/23 13:26:48 | 000,053,248 | —- | M] (Logitech Inc.) – C:\Program Files\Logitech\Profiler\LWEHook.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/12/08 02:56:30 | 000,079,360 | —- | M] (Creative Labs) [On_Demand | Stopped] – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe – (Creative Audio Engine Licensing Service)
SRV - [2010/11/11 12:26:40 | 000,011,736 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV - [2010/01/15 06:49:20 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2009/08/24 14:38:06 | 000,068,136 | —- | M] () [Auto | Running] – C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE – (ES lite Service)
SRV - [2009/08/10 14:58:28 | 000,093,848 | —- | M] (SiSoftware) [On_Demand | Stopped] – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe – (SandraAgentSrv)
SRV - [2009/08/04 17:29:54 | 000,219,360 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2009/02/23 11:43:54 | 000,307,200 | —- | M] (Creative Technology Ltd) [Auto | Running] – C:\Program Files\Creative\Shared Files\CTAudSvc.exe – (CTAudSvcService)
SRV - [2007/08/09 01:27:52 | 000,073,728 | —- | M] (HP) [Auto | Running] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/05/18 13:53:29 | 000,407,152 | —- | M] (CODEMASTERS) [Auto | Stopped] – C:\WINDOWS\System32\pr2ah4nc.exe – (pr2ah4nc) DiRT Drivers Auto Removal (pr2ah4nc)


========== Driver Services (SafeList) ==========

DRV - [2011/01/28 22:05:21 | 000,028,752 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EF3D7C33-F6FE-4A68-BBE0-072B746E0F80}\MpKslf83ed0e7.sys – (MpKslf83ed0e7)
DRV - [2011/01/28 21:55:05 | 000,024,944 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\GVTDrv.sys – (GVTDrv)
DRV - [2011/01/28 21:54:34 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\gdrv.sys – (gdrv)
DRV - [2011/01/24 08:02:14 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\etdrv.sys – (etdrv)
DRV - [2010/10/16 12:55:00 | 009,623,680 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2010/07/04 05:41:23 | 000,023,456 | —- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\DrvAgent32.sys – (DrvAgent32)
DRV - [2010/03/12 04:35:48 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Program Files\Gigabyte\ET6\i386\AODDriver.sys – (AODDriver)
DRV - [2009/10/21 08:28:42 | 005,934,592 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/10/07 05:26:18 | 000,099,440 | R— | M] (JMicron Technology Corp.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\jraid.sys – (JRAID)
DRV - [2009/09/25 08:57:40 | 000,138,240 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nusb3xhc.sys – (nusb3xhc)
DRV - [2009/09/25 08:57:36 | 000,056,576 | —- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nusb3hub.sys – (nusb3hub)
DRV - [2009/08/07 23:46:56 | 000,023,112 | —- | M] (SiSoftware) [Kernel | On_Demand | Stopped] – C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\sandra.sys – (SANDRA)
DRV - [2009/07/28 02:55:00 | 000,143,360 | R— | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Rtenicxp.sys – (RTLE8023xp)
DRV - [2009/06/04 02:48:12 | 001,177,624 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ha20x2k.sys – (ha20x2k)
DRV - [2009/06/04 02:48:00 | 000,095,768 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\emupia2k.sys – (emupia)
DRV - [2009/06/04 02:47:50 | 000,158,744 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctsfm2k.sys – (ctsfm2k)
DRV - [2009/06/04 02:47:42 | 000,014,360 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctprxy2k.sys – (ctprxy2k)
DRV - [2009/06/04 02:47:34 | 000,130,072 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctoss2k.sys – (ossrv)
DRV - [2009/06/04 02:47:24 | 000,347,080 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ctdvda2k.sys – (ctdvda2k)
DRV - [2009/06/04 02:47:14 | 000,526,232 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctaud2k.sys – (ctaud2k) Creative Audio Driver (WDM)
DRV - [2009/06/04 02:47:06 | 000,511,000 | —- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ctac32k.sys – (ctac32k)
DRV - [2009/06/04 02:46:56 | 001,324,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CTEXFIFX.SYS – (CTEXFIFX.SYS)
DRV - [2009/06/04 02:46:56 | 001,324,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CTEXFIFX.sys – (CTEXFIFX)
DRV - [2009/06/04 02:46:42 | 000,072,728 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CTHWIUT.SYS – (CTHWIUT.SYS)
DRV - [2009/06/04 02:46:42 | 000,072,728 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CTHWIUT.sys – (CTHWIUT)
DRV - [2009/06/04 02:46:34 | 000,171,032 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\System32\drivers\CT20XUT.SYS – (CT20XUT.SYS)
DRV - [2009/06/04 02:46:34 | 000,171,032 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\CT20XUT.sys – (CT20XUT)
DRV - [2008/08/05 06:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/04/13 12:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\gameenum.sys – (gameenum)
DRV - [2008/04/13 10:36:05 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2007/09/05 12:48:24 | 012,212,864 | —- | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\snp2sxp.sys – (SNP2STD) USB2.0 PC Camera (SNP2STD)
DRV - [2007/05/18 13:53:01 | 000,064,880 | —- | M] (CODEMASTERS) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\pe3ah4nc.sys – (pe3ah4nc) DiRT Environment Driver (pe3ah4nc)
DRV - [2007/05/18 13:52:38 | 000,055,160 | —- | M] (CODEMASTERS) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\ps6ah4nc.sys – (ps6ah4nc) DiRT Synchronization Driver (ps6ah4nc)
DRV - [2007/04/16 16:46:34 | 000,033,792 | —- | M] (Advanced Micro Devices) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\AmdPPM.sys – (AmdPPM)
DRV - [2007/01/24 15:27:54 | 000,039,704 | —- | M] (Belcarra Technologies) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rcblan.sys – (RemoteControl-USBLAN)
DRV - [2006/07/01 22:39:40 | 000,036,864 | —- | M] (Advanced Micro Devices) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2006/01/04 01:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)
DRV - [2005/09/29 11:01:51 | 000,066,048 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfvfs02.sys – (sfvfs02) StarForce Protection VFS Driver (version 2.x)
DRV - [2005/08/10 08:06:28 | 000,019,968 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfsync02.sys – (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2005/08/10 06:44:04 | 000,050,688 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfdrv01.sys – (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/07/23 00:41:46 | 000,026,112 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LHidKE.Sys – (LHidKE)
DRV - [2005/07/23 00:41:42 | 000,068,864 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\LMouKE.Sys – (LMouKE)
DRV - [2005/05/16 07:20:39 | 000,006,656 | —- | M] (Protection Technology) [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\sfhlp02.sys – (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005/03/10 15:08:16 | 000,013,056 | R— | M] (Logitech, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\L8042Kbd.sys – (L8042Kbd)
DRV - [2004/04/14 10:08:00 | 000,044,064 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmXlCore.sys – (WmXlCore)
DRV - [2004/04/14 10:08:00 | 000,021,280 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmFilter.sys – (WmFilter)
DRV - [2004/04/14 10:08:00 | 000,014,432 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmHidLo.sys – (WmHidLo)
DRV - [2004/04/14 10:08:00 | 000,010,144 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmBEnum.sys – (WmBEnum)
DRV - [2004/04/14 10:08:00 | 000,005,600 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\WmVirHid.sys – (WmVirHid)
DRV - [2004/04/13 19:20:08 | 000,015,781 | R— | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2001/08/17 13:00:04 | 000,002,944 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\msmpu401.sys – (ms_mpu401)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sbc.yahoo.com/dsl
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.4.3
FF - prefs.js..extensions.enabledItems: [removed]:1.2.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..network.proxy.type: 2

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/12/27 02:50:17 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/27 02:50:10 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/27 13:06:08 | 000,000,000 | —D | M]

[2010/03/27 00:41:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Extensions
[2011/01/24 05:51:46 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions
[2010/06/26 21:49:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/12 22:30:09 | 000,000,000 | —D | M] (Smart Bookmarks Bar) – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\[removed]
[2010/07/26 21:03:06 | 000,000,000 | —D | M] ("Broadband Speed Test and Diagnostics") – C:\Documents and Settings\MIKE\Application Data\Mozilla\Firefox\Profiles\e4v1b08e.default\extensions\[removed]
[2010/10/27 23:30:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/12/27 02:50:17 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2009/11/19 15:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/07/31 12:06:48 | 001,654,784 | —- | M] (LizardTech) – C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
[2009/11/19 15:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

O1 HOSTS File: ([2011/01/27 13:14:09 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe (Gigabyte Technology Corp.)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [GBTUpd] C:\Program Files\Gigabyte\GBTUpd\PreRun.exe (PreRun)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe ()
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
O4 - HKLM..\RunOnce: [EasyTuneVI] C:\Program Files\Gigabyte\ET6\ETcall.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O15 - HKCU\..Trusted Domains: samsungportal.com ([]* in Trusted sites)
O16 - DPF: {01025D1C-BB03-4369-8344-732CD0DCCCF0} http://www.geforce.com/services_toolkit/Sh…/GPU_Reader.cab (NVIDIA GPU Reader Class)
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.gigabyte.com.tw/object/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {714E667D-360C-4BFB-8C1A-E4812B608CC1} http://service.samsungportal.com/EP/web/co…rustChecker.cab (ACUBETrustChecker Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15113/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/26 21:18:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/10/27 02:40:21 | 000,402,696 | R— | M] (Electronic Arts) - D:\AutoRun.exe – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:17 | 000,000,000 | R–D | M] - D:\Autorun – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:26 | 002,084,352 | R— | M] () - D:\autorun.dat – [ UDF ]
O32 - AutoRun File - [2007/10/27 02:40:16 | 000,000,155 | R— | M] () - D:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2006/02/11 20:54:47 | 000,000,000 | -HS- | M] () - E:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/09/03 23:44:23 | 000,000,000 | —D | M] - F:\AUTO – [ NTFS ]
O32 - AutoRun File - [2006/02/11 20:54:47 | 000,000,000 | -HS- | M] () - F:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/11/28 11:44:10 | 008,188,928 | —- | M] () - F:\Autotap 3.00.msi – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/01/28 22:21:06 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/27 13:09:13 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/01/27 13:06:56 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/01/27 13:06:56 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/01/27 13:06:56 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/01/27 13:06:56 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/01/27 13:06:50 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/01/27 13:06:17 | 000,000,000 | —D | C] – C:\Qoobox
[2011/01/27 12:50:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
[2011/01/27 12:50:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
[2011/01/27 12:50:06 | 000,000,000 | —D | C] – C:\Program Files\McAfee Security Scan
[2011/01/27 01:34:31 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
[2011/01/25 14:56:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2011/01/25 14:48:54 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/01/25 02:25:42 | 000,000,000 | RH-D | C] – C:\Documents and Settings\MIKE\Application Data\SecuROM
[2011/01/24 07:14:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Disney Interactive Studios
[2011/01/24 04:39:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/01/24 01:49:19 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAudio2_7.dll
[2011/01/24 01:49:19 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\XAPOFX1_5.dll
[2011/01/24 01:49:18 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DCompiler_43.dll
[2011/01/24 01:49:18 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xactengine3_7.dll
[2011/01/24 01:49:17 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dcsx_43.dll
[2011/01/24 01:49:17 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx11_43.dll
[2011/01/24 01:49:16 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\D3DX9_43.dll
[2011/01/24 01:49:16 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx10_43.dll
[2011/01/24 01:47:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SiSoftware
[2011/01/24 01:47:41 | 000,000,000 | —D | C] – C:\Program Files\SiSoftware
[2011/01/23 12:20:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2011/01/23 12:17:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Empire Interactive
[2011/01/23 02:52:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\MIKE\Desktop\Hijack This.exe
[2011/01/23 02:28:17 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2011/01/19 00:41:43 | 000,000,000 | —D | C] – C:\Program Files\Empire Interactive
[2011/01/18 23:04:44 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\Application Data\Disney Interactive Studios
[2011/01/18 23:00:53 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\Application Data\Leadertech
[2011/01/18 22:42:47 | 000,000,000 | —D | C] – C:\Program Files\Disney Interactive Studios
[2011/01/18 02:21:48 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\My Documents\NFS ProStreet
[2011/01/18 01:35:59 | 000,000,000 | —D | C] – C:\Program Files\Electronic Arts
[2011/01/04 09:11:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Ubisoft
[2011/01/04 09:06:19 | 000,000,000 | —D | C] – C:\Program Files\Ubisoft
[2011/01/01 00:02:18 | 000,000,000 | —D | C] – C:\Documents and Settings\MIKE\My Documents\RED LIGHT
[2010/03/31 14:28:05 | 000,151,552 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2std.dll
[2010/03/31 14:28:05 | 000,077,824 | —- | C] ( ) – C:\WINDOWS\System32\csnp2std.dll
[2005/08/07 16:13:46 | 000,060,928 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/29 00:55:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/28 21:59:32 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/28 21:58:41 | 000,436,228 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/01/28 21:58:41 | 000,068,680 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/01/28 21:55:05 | 000,024,944 | —- | M] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011/01/28 21:55:05 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\GVTunner.ref
[2011/01/28 21:54:47 | 000,012,664 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/28 21:54:34 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2011/01/28 21:54:34 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/28 21:54:33 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
[2011/01/28 21:54:33 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2011/01/28 21:54:32 | 000,000,276 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
[2011/01/28 21:54:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/28 14:08:34 | 000,055,080 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/28 14:08:34 | 000,055,080 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/28 14:08:34 | 000,000,788 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/28 14:08:17 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1003.job
[2011/01/28 14:06:30 | 000,002,391 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CalMAN Pattern Generator.lnk
[2011/01/28 00:41:27 | 000,022,328 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/01/27 13:44:59 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/01/27 13:14:09 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011/01/27 13:09:17 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/01/27 13:05:44 | 004,262,339 | R— | M] () – C:\Documents and Settings\MIKE\Desktop\schrauber.exe
[2011/01/27 12:50:07 | 000,001,619 | —- | M] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/01/27 12:50:07 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/01/27 02:00:23 | 000,133,632 | —- | M] () – C:\Documents and Settings\MIKE\Desktop\RKUnhookerLE.EXE
[2011/01/27 01:34:34 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Documents and Settings\MIKE\Desktop\OTL.exe
[2011/01/25 14:49:35 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2011/01/24 08:02:14 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\etdrv.sys
[2011/01/24 07:14:55 | 000,001,048 | —- | M] () – C:\WINDOWS\disney.ini
[2011/01/24 07:14:25 | 000,001,767 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Pure.lnk
[2011/01/24 01:48:02 | 000,000,991 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SiSoftware Sandra Lite 2011b.lnk
[2011/01/24 00:03:39 | 000,241,476 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/24 00:03:39 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/24 00:03:38 | 000,241,472 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/23 17:58:09 | 000,001,857 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Need for Speed™ ProStreet.lnk
[2011/01/23 13:55:43 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/01/23 12:18:04 | 000,000,868 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FlatOut 2.lnk
[2011/01/23 11:40:22 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/01/23 02:52:12 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\MIKE\Desktop\Hijack This.exe
[2011/01/22 01:36:05 | 000,055,536 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/22 01:36:05 | 000,055,536 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/22 01:36:05 | 000,000,788 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000007-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/15 02:14:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-2000478354-839522115-1005.job
[2011/01/13 03:00:49 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/01/04 09:12:43 | 000,001,858 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Driver Parallel Lines.lnk
[2010/12/31 23:58:15 | 000,019,968 | —- | M] () – C:\Documents and Settings\MIKE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[6 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/27 23:54:28 | 000,000,004 | —- | C] () – C:\WINDOWS\System32\GVTunner.ref
[2011/01/27 13:09:17 | 000,000,223 | —- | C] () – C:\Boot.bak
[2011/01/27 13:09:14 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/01/27 13:06:56 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/01/27 13:06:56 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/01/27 13:06:56 | 000,089,088 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/01/27 13:06:56 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/01/27 13:06:56 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/01/27 13:05:43 | 004,262,339 | R— | C] () – C:\Documents and Settings\MIKE\Desktop\schrauber.exe
[2011/01/27 12:50:07 | 000,001,619 | —- | C] () – C:\Documents and Settings\All Users\Desktop\McAfee Security Scan Plus.lnk
[2011/01/27 12:50:07 | 000,001,611 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2011/01/27 02:00:23 | 000,133,632 | —- | C] () – C:\Documents and Settings\MIKE\Desktop\RKUnhookerLE.EXE
[2011/01/25 14:54:31 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/25 14:49:35 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2011/01/24 07:14:25 | 000,001,767 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Pure.lnk
[2011/01/24 07:11:58 | 000,001,048 | —- | C] () – C:\WINDOWS\disney.ini
[2011/01/24 01:48:02 | 000,000,991 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SiSoftware Sandra Lite 2011b.lnk
[2011/01/24 01:47:44 | 010,948,608 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sandra.mda
[2011/01/23 18:02:51 | 000,066,872 | —- | C] () – C:\WINDOWS\System32\PnkBstrA.exe
[2011/01/23 18:02:50 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/01/23 18:02:44 | 000,103,736 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2011/01/23 17:58:09 | 000,001,857 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Need for Speed™ ProStreet.lnk
[2011/01/23 13:11:49 | 000,055,080 | —- | C] () – C:\WINDOWS\System32\BMXStateBkp-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 13:11:49 | 000,055,080 | —- | C] () – C:\WINDOWS\System32\BMXState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 13:11:49 | 000,000,788 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000006-00000000-00000006-00001102-00000005-00231102}.rfx
[2011/01/23 12:18:04 | 000,000,868 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FlatOut 2.lnk
[2011/01/23 11:40:22 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/01/04 09:12:43 | 000,001,858 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Driver Parallel Lines.lnk
[2010/10/26 21:31:24 | 000,155,712 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2010/06/22 15:49:25 | 000,114,688 | R— | C] () – C:\WINDOWS\System32\EDCode.dll
[2010/06/22 15:49:25 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\CryptoSeed.dll
[2010/06/22 15:49:25 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\SftpApi.dll
[2010/06/22 15:49:25 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\ShttpApi.dll
[2010/04/19 07:30:49 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/04/05 14:28:18 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/04/01 22:06:01 | 000,053,063 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2010/04/01 22:06:01 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2010/04/01 22:05:51 | 000,002,038 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\HPSU_48BitScanUpdate.log
[2010/04/01 22:05:51 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2010/04/01 22:00:59 | 000,204,661 | —- | C] () – C:\Documents and Settings\MIKE\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2010/04/01 22:00:59 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2010/03/31 14:28:06 | 000,015,497 | —- | C] () – C:\WINDOWS\snp2std.ini
[2010/03/31 14:28:05 | 012,212,864 | —- | C] () – C:\WINDOWS\System32\drivers\snp2sxp.sys
[2010/03/31 14:28:05 | 000,025,472 | —- | C] () – C:\WINDOWS\System32\drivers\sncamd.sys
[2010/03/31 14:17:30 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/03/30 14:27:42 | 000,001,076 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2010/03/29 06:58:51 | 000,019,968 | —- | C] () – C:\Documents and Settings\MIKE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/27 15:18:29 | 000,000,138 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/03/26 23:10:16 | 000,024,944 | —- | C] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2010/03/26 22:56:38 | 000,073,728 | R— | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/03/26 22:52:16 | 000,000,010 | —- | C] () – C:\WINDOWS\GSetup.ini
[2010/03/26 14:38:51 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/06/04 01:37:08 | 000,021,093 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/06/04 01:37:06 | 000,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/06/04 00:55:20 | 000,002,560 | —- | C] () – C:\WINDOWS\System32\CtxfiRes.dll
[2009/06/04 00:55:20 | 000,002,560 | —- | C] () – C:\WINDOWS\CTXFIRES.DLL
[2007/04/12 21:44:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/08/07 16:19:00 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2005/06/07 07:10:50 | 000,070,656 | —- | C] () – C:\WINDOWS\System32\CTMMACTL.DLL
[2003/03/21 03:56:12 | 000,000,285 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2003/01/07 14:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/06 14:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

< End of report >
Hi, You posted OTL.txt, but there should be also an Extras.txt, please post this in your next reply. Logs looking good so far, please explain any problems you still have with the system :).
Seems to be running okay although I'm seeing some things that I don't think I requested, like a message thanks for choosing RealPlayer and some from McAfee, also some videos give error Viewing of this video requires a flash plug in click here to download, I download, restart and go back to the video and it has the same message?

Sorry I forgot the extras.

OTL Extras logfile created on: 1/29/2011 1:05:44 AM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\MIKE\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 73.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 931.50 Gb Total Space | 868.89 Gb Free Space | 93.28% Space Free | Partition Type: NTFS
Drive D: | 4.64 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 69.23 Gb Total Space | 39.42 Gb Free Space | 56.94% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 179.49 Gb Free Space | 77.07% Space Free | Partition Type: NTFS

Computer Name: GCDI-F7150E40D8 | User Name: MIKE | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [SpaceMonger] – "F:\Program Files\SpaceMonger\SpaceMonger.exe" ; show-free-space false ; show-system-space false ; set-root "%l" (Sixty-Five Software, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3074:TCP" = 3074:TCP:*:Enabled:fuel
"3074:UDP" = 3074:UDP:*:Enabled:fuel

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Gigabyte\GBTUpd\GBTUpd.exe" = C:\Program Files\Gigabyte\GBTUpd\GBTUpd.exe:*:Enabled:GBTUpd.exe – (GIGABYTE)
"C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe" = C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe:*:Enabled:RunUpd – (Gigabyte)
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 – ()
"E:\Program Files\TmUnitedForever\TmForever.exe" = E:\Program Files\TmUnitedForever\TmForever.exe:*:Enabled:TmForever – ()
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Gigabyte\ET6\UpdExe.exe" = C:\Program Files\Gigabyte\ET6\UpdExe.exe:*:Enabled:Exe File – (GIGABYTE)
"C:\Program Files\Gigabyte\ET6\GBTUpd.exe" = C:\Program Files\Gigabyte\ET6\GBTUpd.exe:*:Enabled:GBTUpd.exe – (GIGABYTE)
"E:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe" = E:\Program Files\Steam\steamapps\common\xpand rally\xpandrally.exe:*:Enabled:Xpand Rally – (Techland)
"E:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe" = E:\Program Files\Steam\steamapps\common\xpand rally\ChromEd.exe:*:Enabled:Xpand Rally – (Techland)
"E:\Program Files\Steam\steamapps\common\gti racing\GTIRacing.exe" = E:\Program Files\Steam\steamapps\common\gti racing\GTIRacing.exe:*:Enabled:GTI Racing – (Techland)
"C:\Program Files\Codemasters\GRID\GRID.exe" = C:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID – (Codemasters)
"C:\Program Files\Codemasters\DiRT\DiRT.exe" = C:\Program Files\Codemasters\DiRT\DiRT.exe:*:Enabled:DiRT Executable – (Codemasters)
"E:\Program Files\Activision Value\Baja 1000\Baja.exe" = E:\Program Files\Activision Value\Baja 1000\Baja.exe:*:Disabled:Baja – ()
"C:\Program Files\real\realplayer\realplay.exe" = C:\Program Files\real\realplayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Codemasters\FUEL\FUEL.exe" = C:\Program Files\Codemasters\FUEL\FUEL.exe:*:Enabled:FUEL – (Codemasters)
"F:\GCDI\GCDI TECH\GCDI-TECH-INFO\PATTERN GENERATOR\PatGen.exe" = F:\GCDI\GCDI TECH\GCDI-TECH-INFO\PATTERN GENERATOR\PatGen.exe:*:Disabled:CalMAN Pattern Generator – (SpectraCal, LLC)
"C:\Program Files\Electronic Arts\Need for Speed ProStreet\nfs.exe" = C:\Program Files\Electronic Arts\Need for Speed ProStreet\nfs.exe:*:Enabled:nfs – ()
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\RpcAgentSrv.exe:*:Enabled:SiSoftware Deployment Agent Service – (SiSoftware)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011b\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service – (SiSoftware)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{1064CABD-7390-4336-94E4-8A53DFBCB636}_is1" = GT Legends 1.1.0.0
"{1619204B-7F8C-4293-B342-5345721F4A1F}_is1" = GTR 2 1.0.0.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18F11181-EA1A-42AE-AF89-4867C7F7A6FA}" = Sound Blaster X-Fi
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{310609F9-5F1C-475C-A49D-8A2AC3D53022}" = Instant Play Electric Guitar 4 CD-ROM
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Cinfigurer
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0728.1
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B09.1008.1
"{4E6D2462-AB33-40BB-AA9F-3FA3E0DD0290}" = FlatOut 2
"{53CDAAAB-6D41-4A36-BAA4-90261DE31B13}" = NetZero For Cosmi
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57B89E30-0BBA-4F20-9F2C-8E8CDE1CEDB6}" = DiRT
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{5EBAC9CB-97D7-44CD-A82D-4FCB37F582AC}" = World Racing 2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68CEE564-F0FE-4E69-8DBC-0DE23987AABA}" = Projector Calculator 1.23
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{71A7DBB4-D82B-4BC4-9FD4-0C1833E34784}" = CodeAxNew
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75438C0E-9925-412E-AD85-D0E71C6CE2ED}" = Digital Viewer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774088D4-0777-4D78-904D-E435B318F5D2}" = Microsoft Antimalware
"{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}" = Microsoft Security Client
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
"{817DE62F-5787-43BB-8877-5F81FAE5A823}" = ACUBE UniSSOTray V1.0
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{86076752-37A4-41E6-BFC4-73186683AF7B}" = Sprint Cars - Road to Knoxville
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AC76BA86-7AD7-5760-0000-900000000003}" = Japanese Fonts Support For Adobe Reader 9
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.06
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.36
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B75A978D-A9B0-4344-871E-9145F237A237}" = Music Coach Player
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BBF0A67B-5DBA-452F-9D2E-6F168BC226E4}" = Need for Speed™ SHIFT
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Lite 2011b
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CC419DDC-E0F0-4013-B25A-6FA036516F0D}" = Need for Speed™ ProStreet
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{E33956B7-301C-429D-9E6C-2C12EACB8A62}" = NWZ-E340 WALKMAN Guide
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F51FF206-2273-4B3E-A90A-4752AE288C12}" = FUEL
"{FAC36425-4266-4DE4-9CB5-68FB4FB9385A}" = CalMAN Pattern Generator
"{FDC8065B-80DE-4466-B90B-2581F6D77DFF}" = Image Plugin
"{FE64AE29-0883-4C70-8388-DC026019C900}" = HP Image Zone Express
"{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}" = Pure
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AudioCS" = Creative Audio Control Panel
"Baja 1000" = SCORE International: Baja 1000
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"DriverAgent.exe" = DriverAgent by eSupport.com
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"GTR Evolution_1.1.1.2_is1" = GTR Evolution
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B10.0728.1
"InstallShield_{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B09.1008.1
"InstallShield_{5EBAC9CB-97D7-44CD-A82D-4FCB37F582AC}" = World Racing 2
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NeroMultiInstaller!UninstallKey" = Nero Suite
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"RACE 07 Offline_1.0_is1" = RACE 07 Offline
"RealPlayer 12.0" = RealPlayer
"rFactor" = rFactor (remove only)
"Steam App 3000" = GTI Racing
"Steam App 3010" = Xpand Rally
"SysInfo" = Creative System Information
"TmUnitedForever_is1" = TmUnitedForever Update 2010-03-15
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/23/2011 2:14:01 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application officelivesignin.exe, version 2.0.2313.0, faulting
module officelivesignin.exe, version 2.0.2313.0, fault address 0x00003ce4.

Error - 1/23/2011 4:29:14 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/23/2011 6:58:23 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/24/2011 7:33:30 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:34:32 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:36:33 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 7:46:55 AM | Computer Name = GCDI-F7150E40D8 | Source = NTBackup | ID = 8019
Description = End Operation: Warnings or errors were encountered. Consult the backup
report for more details.

Error - 1/24/2011 2:53:50 PM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x6ce19a67.

Error - 1/25/2011 4:22:33 AM | Computer Name = GCDI-F7150E40D8 | Source = Application Error | ID = 1000
Description = Faulting application flatout2.exe, version 0.0.0.0, faulting module
, version 0.0.0.0, fault address 0x00000000.

Error - 1/25/2011 4:49:24 PM | Computer Name = GCDI-F7150E40D8 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 3.0.8107.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

[ System Events ]
Error - 1/27/2011 3:11:37 AM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/27/2011 3:11:40 AM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/27/2011 2:38:37 PM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/27/2011 2:38:40 PM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/28/2011 1:53:59 AM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/28/2011 1:54:03 AM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/28/2011 4:00:37 PM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/28/2011 4:00:38 PM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 1/28/2011 11:54:40 PM | Computer Name = GCDI-F7150E40D8 | Source = ps6ah4nc | ID = 262145
Description = Protection Synchronization Driver detected an internal error, contact
the customer support service.

Error - 1/28/2011 11:54:42 PM | Computer Name = GCDI-F7150E40D8 | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI