This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Nasty Rootkit

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I am infected with a rootkit that has been very hard to kill. My google searches are being redirected and the rootkit is starting invisible instances of iexplore.exe that play random audio advertisements. I have tried to run TDSSKiller.exe from Kaspersky, this program shows up in task manger briefly (about 3 seconds) then is terminated. It does the same thing after I renamed it to a com file. I then tried to boot my computer into safe mode to attempt to run TDSSkiller. Windows loads the drivers for safe mode, but then I get a BSOD that simply tells me to 'scan for viruses' instead of a more specific error message most BSODs give. I hope you can help. Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:19:55 PM, on 2/11/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Windows\system32\mfevtps.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
C:\Windows\system32\vmnat.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\vmnetdhcp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\GridService\peer.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files\Orb Networks\Orb\bin\Orblauncher.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\Orb Networks\Orb\bin\Orb.exe
C:\Program Files\Orb Networks\Orb\bin\OrbjetManager.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Buddy\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:18810
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IE2EMBHO Class - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll
O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Grid Service] "C:\Program Files\GridService\peer.exe" -n Grid
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
O4 - Startup: setup_9.0.0.722_09.02.2011_20-07.lnk = C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\startup.exe
O4 - Startup: V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~2\ZIPSCA~1\zs_ie.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O15 - Trusted Zone: http://www.adobe.com
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AZVX - Sysinternals - www.sysinternals.com - C:\Users\Buddy\AppData\Local\Temp\AZVX.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ElevatorService - Unknown owner - C:\Program Files\RipTiger\ElevatorService.exe
O23 - Service: Google Update Service (gupdate1c9be2d1ac88a67) (gupdate1c9be2d1ac88a67) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Katchall Service - Unknown owner - C:\Program Files\InventThings\Katchall Archive\KatchallService.exe (file missing)
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Windows\system32\mfevtps.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Q - Sysinternals - www.sysinternals.com - C:\Users\Buddy\AppData\Local\Temp\Q.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: Antivirus 2010 (userinit) - Unknown owner - \\.\globalrootC:\Windows\system32\us?rinit.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

โ€“
End of file - 11496 bytes
Hi there could you run the following programmes for me in the order stated :)

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:

    ๐Ÿ–ผClick to load external image (Posted Image)

  • If you are prompted with options, enter N at the prompt and press Enter
  • Press Enter again
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please post the contents of that file.

THEN

Please read carefully and follow these steps.

FINALLY

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
Thanks for your prompt reply. MBRCheck and OTL ran fine and produced logs but as I stated in my original post, I cannot run TDSSKiller.exe. The process shows up briefly in task manger but is terminated; renaming the file to something different gives me the same results.
Here is the log from MBRCheck.

MBRCheck, version 1.2.3
ยฉ 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 1 (build 6001), 32-bit
Base Board Manufacturer: Intel Corporation
BIOS Manufacturer: Intel Corp.
System Manufacturer:
System Product Name: GM5446E
Logical Drives Mask: 0x00000f8c

Kernel Drivers (total 175):
0x82409000 \SystemRoot\system32\ntoskrnl.exe
0x827B3000 \SystemRoot\system32\hal.dll
0x83002000 \SystemRoot\system32\kdcom.dll
0x8300A000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8306A000 \SystemRoot\system32\PSHED.dll
0x8307B000 \SystemRoot\system32\BOOTVID.dll
0x83083000 \SystemRoot\system32\CLFS.SYS
0x830C4000 \SystemRoot\system32\CI.dll
0x831A4000 \SystemRoot\system32\DRIVERS\35858692.sys
0x831B1000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8322D000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x8323A000 \SystemRoot\system32\drivers\acpi.sys
0x83280000 \SystemRoot\system32\drivers\WMILIB.SYS
0x83289000 \SystemRoot\system32\drivers\msisadrv.sys
0x83291000 \SystemRoot\system32\drivers\pci.sys
0x832B8000 \SystemRoot\System32\drivers\partmgr.sys
0x832C7000 \SystemRoot\system32\drivers\volmgr.sys
0x832D6000 \SystemRoot\System32\drivers\volmgrx.sys
0x83320000 \SystemRoot\system32\drivers\intelide.sys
0x83327000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x83335000 \SystemRoot\System32\drivers\mountmgr.sys
0x83345000 \SystemRoot\system32\drivers\iastorv.sys
0x833E6000 \SystemRoot\system32\drivers\atapi.sys
0x88400000 \SystemRoot\system32\drivers\ataport.SYS
0x8841E000 \SystemRoot\system32\drivers\fltmgr.sys
0x88450000 \SystemRoot\system32\drivers\fileinfo.sys
0x88460000 \SystemRoot\System32\Drivers\ksecdd.sys
0x884D1000 \SystemRoot\system32\drivers\ndis.sys
0x885DC000 \SystemRoot\system32\drivers\msrpc.sys
0x88607000 \SystemRoot\system32\drivers\NETIO.SYS
0x88641000 \SystemRoot\System32\drivers\tcpip.sys
0x8872A000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x88800000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8890F000 \SystemRoot\system32\drivers\volsnap.sys
0x88948000 \SystemRoot\System32\Drivers\spldr.sys
0x88950000 \SystemRoot\System32\Drivers\mup.sys
0x8895F000 \SystemRoot\system32\drivers\mfehidk.sys
0x889B1000 \SystemRoot\System32\drivers\ecache.sys
0x889D8000 \SystemRoot\system32\drivers\disk.sys
0x889E9000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x88A0A000 \SystemRoot\system32\drivers\crcdisk.sys
0x88AC1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x88ACC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x88AD5000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8D406000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x8DE84000 \SystemRoot\system32\DRIVERS\nvBridge.kmd
0x8DE86000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8DF25000 \SystemRoot\System32\drivers\watchdog.sys
0x8DF32000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x8DF44000 \SystemRoot\system32\DRIVERS\AVerBas.sys
0x8DF52000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8DF5D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8DF9B000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x88AE4000 \SystemRoot\system32\DRIVERS\bcmwl6.sys
0x8DFAA000 \SystemRoot\system32\DRIVERS\HSXHWBS2.sys
0x88B59000 \SystemRoot\system32\DRIVERS\ks.sys
0x8E803000 \SystemRoot\system32\DRIVERS\HSX_DPV.sys
0x8E906000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys
0x8E9BB000 \SystemRoot\system32\drivers\modem.sys
0x8E9C8000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x8E9D8000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x8E9E6000 \SystemRoot\system32\DRIVERS\e100b325.sys
0x8EA0D000 \SystemRoot\system32\DRIVERS\parport.sys
0x8EA25000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EA38000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EA43000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EA4E000 \??\C:\Windows\system32\drivers\VMkbd.sys
0x8EA53000 \SystemRoot\system32\DRIVERS\serial.sys
0x8EA6D000 \SystemRoot\system32\DRIVERS\serenum.sys
0x8EA77000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8EAA5000 \SystemRoot\system32\DRIVERS\storport.sys
0x8EAE6000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8EAF1000 \SystemRoot\System32\Drivers\RootMdm.sys
0x8EAF9000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8EB10000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8EB1B000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8EB3E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8EB4D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8EB61000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8EB76000 \SystemRoot\system32\DRIVERS\RimSerial.sys
0x8EB7D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8EB8D000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8EB8F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8EB99000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8EBA6000 \SystemRoot\system32\DRIVERS\vmnetadapter.sys
0x8EBA9000 \SystemRoot\system32\DRIVERS\VMNET.SYS
0x88B83000 \SystemRoot\system32\DRIVERS\AVerCap.sys
0x8EBAC000 \SystemRoot\system32\DRIVERS\AVerTun.sys
0x8EBD5000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
0x88745000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8EBD8000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x88779000 \SystemRoot\system32\drivers\HdAudio.sys
0x887B8000 \SystemRoot\system32\drivers\portcls.sys
0x8F000000 \SystemRoot\system32\drivers\drmk.sys
0x8F03D000 \SystemRoot\system32\DRIVERS\3585869.sys
0x8F08D000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x8F096000 \SystemRoot\System32\Drivers\Null.SYS
0x8F09D000 \SystemRoot\System32\Drivers\Beep.SYS
0x8F0A4000 \SystemRoot\System32\drivers\vga.sys
0x8F0B0000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x8F0D1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8F0D9000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8F0E1000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8F0EC000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8F0FA000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x8F103000 \SystemRoot\system32\DRIVERS\tdx.sys
0x8F119000 \SystemRoot\system32\drivers\mfetdik.sys
0x8F127000 \SystemRoot\System32\DRIVERS\netbt.sys
0x8F159000 \SystemRoot\system32\DRIVERS\smb.sys
0x8F409000 \SystemRoot\system32\DRIVERS\kl1.sys
0x8F928000 \SystemRoot\system32\drivers\afd.sys
0x8F970000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x8F987000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8F989000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x8F992000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x8F99F000 \SystemRoot\system32\DRIVERS\pacer.sys
0x8F9B5000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x8F9BF000 \SystemRoot\system32\DRIVERS\netbios.sys
0x8F9CD000 \SystemRoot\system32\DRIVERS\dot4usb.sys
0x8F9DA000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8F9ED000 \SystemRoot\system32\DRIVERS\Dot4.sys
0x8FA12000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0x8FA20000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x8FA32000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x8FA6E000 \SystemRoot\system32\DRIVERS\Dot4Prt.sys
0x8FA77000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8FA81000 \??\C:\Windows\system32\drivers\lmqseyg.sys
0x8FACD000 \??\C:\Windows\system32\drivers\dhahelper.sys
0x8FAD4000 \SystemRoot\System32\Drivers\dfsc.sys
0x8FC05000 \SystemRoot\system32\DRIVERS\35858691.sys
0x90125000 \SystemRoot\System32\Drivers\fastfat.SYS
0x9014D000 \SystemRoot\System32\Drivers\crashdmp.sys
0x9015A000 \SystemRoot\System32\Drivers\dump_iaStorV.sys
0x99090000 \SystemRoot\System32\win32k.sys
0x901FB000 \SystemRoot\System32\drivers\Dxapi.sys
0x90205000 \SystemRoot\system32\DRIVERS\monitor.sys
0x992B0000 \SystemRoot\System32\TSDDD.dll
0x992D0000 \SystemRoot\System32\cdd.dll
0x992E0000 \SystemRoot\System32\ATMFD.DLL
0x90214000 \SystemRoot\system32\drivers\luafv.sys
0x90237000 \SystemRoot\system32\drivers\spsys.sys
0x902E6000 \SystemRoot\system32\DRIVERS\vmnetbridge.sys
0x902F4000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x90304000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x9032E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x90338000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x9034B000 \SystemRoot\system32\drivers\HTTP.sys
0x903B8000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x903D5000 \SystemRoot\system32\DRIVERS\bowser.sys
0x8FAEB000 \SystemRoot\System32\drivers\mpsdrv.sys
0x8FB00000 \SystemRoot\system32\drivers\mrxdav.sys
0x8FB20000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x8FB3F000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x8FB78000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x8FB90000 \SystemRoot\System32\DRIVERS\srv2.sys
0x8F16D000 \SystemRoot\System32\DRIVERS\srv.sys
0x903EE000 \??\C:\Windows\system32\drivers\hcmon.sys
0x903F8000 \SystemRoot\system32\DRIVERS\parvdm.sys
0x8FBB7000 \??\C:\Windows\system32\Drivers\vmci.sys
0x8FC00000 \??\C:\Windows\system32\Drivers\VMparport.sys
0x8F1BB000 \??\C:\Windows\system32\Drivers\vmx86.sys
0x8FBC7000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x8FBD0000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0x8F28A000 \SystemRoot\system32\drivers\peauth.sys
0x8FBD4000 \SystemRoot\System32\Drivers\secdrv.SYS
0x8FBDE000 \SystemRoot\System32\drivers\tcpipreg.sys
0x8FBEA000 \??\C:\Windows\system32\drivers\vmnetuserif.sys
0x8FC02000 \??\C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys
0x8FBEF000 \??\C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys
0x8FBF3000 \SystemRoot\system32\DRIVERS\xaudio.sys
0x8F368000 \SystemRoot\system32\DRIVERS\WUDFRd.sys
0x8F37D000 \SystemRoot\system32\DRIVERS\WUDFPf.sys
0x8F38F000 \SystemRoot\system32\drivers\mfeavfk.sys
0x9022F000 \SystemRoot\system32\drivers\MSPQM.sys
0x77C50000 \Windows\System32\ntdll.dll

Processes (total 74):
0 System Idle Process
4 System
552 C:\Windows\System32\smss.exe
648 C:\Windows\System32\csrss.exe
700 C:\Windows\System32\wininit.exe
712 C:\Windows\System32\csrss.exe
744 C:\Windows\System32\services.exe
784 C:\Windows\System32\lsass.exe
792 C:\Windows\System32\lsm.exe
888 C:\Windows\System32\winlogon.exe
1016 C:\Windows\System32\svchost.exe
1084 C:\Windows\System32\svchost.exe
1152 C:\Windows\System32\svchost.exe
1176 C:\Windows\System32\svchost.exe
1252 C:\Windows\System32\nvvsvc.exe
1272 C:\Windows\System32\nvvsvc.exe
1368 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\svchost.exe
1424 C:\Windows\System32\svchost.exe
1500 C:\Windows\System32\audiodg.exe
1540 C:\Windows\System32\svchost.exe
1564 C:\Windows\System32\SLsvc.exe
1948 C:\Windows\System32\spoolsv.exe
1972 C:\Windows\System32\svchost.exe
656 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
816 C:\Program Files\Bonjour\mDNSResponder.exe
1004 C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
1768 C:\Program Files\McAfee\Common Framework\FrameworkService.exe
2068 C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
2096 C:\Program Files\Common Files\microsoft shared\VS7Debug\MDM.EXE
2144 C:\Windows\System32\mfevtps.exe
2188 C:\Windows\System32\svchost.exe
2208 C:\Windows\System32\svchost.exe
2236 C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
2256 C:\Windows\System32\svchost.exe
2468 C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
2488 C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
2512 C:\Windows\System32\vmnat.exe
2532 C:\Windows\System32\svchost.exe
2568 C:\Windows\System32\SearchIndexer.exe
2616 C:\Windows\System32\drivers\XAudio.exe
2636 C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
2676 C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
2776 C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
2836 C:\Windows\System32\WUDFHost.exe
2844 C:\Windows\System32\vmnetdhcp.exe
3132 C:\Windows\System32\taskeng.exe
3472 C:\Windows\System32\dwm.exe
3504 C:\Windows\System32\taskeng.exe
3536 C:\Windows\explorer.exe
328 C:\Program Files\PowerISO\PWRISOVM.EXE
2608 C:\Program Files\iTunes\iTunesHelper.exe
964 C:\Program Files\GridService\peer.exe
2668 C:\Program Files\McAfee\Common Framework\UdaterUI.exe
2480 C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
1360 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
1000 C:\Program Files\Unlocker\UnlockerAssistant.exe
2252 C:\Windows\ehome\ehtray.exe
2220 C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
4092 C:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe
976 C:\Program Files\McAfee\Common Framework\McTray.exe
3560 C:\Windows\ehome\ehmsas.exe
4008 C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\setup_9.0.0.722_09.02.2011_20-07.exe
3712 C:\Program Files\Mozilla Firefox\firefox.exe
1672 C:\Program Files\iPod\bin\iPodService.exe
4432 C:\Windows\ehome\ehrecvr.exe
5752 C:\Program Files\Orb Networks\Orb\bin\Orb.exe
5860 C:\Program Files\Orb Networks\Orb\bin\OrbjetManager.exe
4940 C:\Users\Buddy\Desktop\HiJackThis.exe
5632 C:\Windows\System32\notepad.exe
2360 C:\Windows\System32\wbem\WmiPrvSE.exe
820 C:\Windows\System32\SearchProtocolHost.exe
4528 C:\Windows\System32\SearchFilterHost.exe
5904 C:\Users\Buddy\Desktop\MBRCheck.exe

\\.\C: โ€“> \\.\PhysicalDrive0 at offset 0x00000002`75028600 (NTFS)
\\.\D: โ€“> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (FAT32)

PhysicalDrive0 Model Number: WDCWD5000AAKS-22TMA0, Rev: 12.01C01

Size Device Name MBR Status
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“
465 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!

Here are the logs from OTL.

the first one:
OTL logfile created on: 2/11/2011 3:58:03 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 57.22 Gb Free Space | 12.55% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32

Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/11 15:57:34 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
PRC - [2011/01/19 16:05:57 | 000,910,296 | โ€”- | M] (Mozilla Corporation) โ€“ C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2010/06/29 20:35:20 | 000,755,312 | โ€”- | M] (Orb Networks) โ€“ C:\Program Files\Orb Networks\Orb\bin\OrbLauncher.exe
PRC - [2010/06/29 20:35:16 | 000,286,720 | โ€”- | M] () โ€“ C:\Program Files\Orb Networks\Orb\bin\OrbjetManager.exe
PRC - [2010/06/29 20:34:50 | 000,198,144 | โ€”- | M] (Orb Networks, Inc.) โ€“ C:\Program Files\Orb Networks\Orb\bin\Orb.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | โ€”- | M] (PowerISO Computing, Inc.) โ€“ C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2010/03/29 19:26:00 | 000,227,712 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/01/18 13:33:03 | 000,198,160 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/01/06 19:07:00 | 000,147,472 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2010/01/06 19:07:00 | 000,124,240 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2010/01/06 19:07:00 | 000,070,728 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Windows\System32\mfevtps.exe
PRC - [2010/01/06 19:07:00 | 000,066,896 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2010/01/06 19:07:00 | 000,027,960 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
PRC - [2010/01/06 19:07:00 | 000,022,816 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
PRC - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnat.exe
PRC - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009/10/01 13:55:56 | 000,330,256 | โ€”- | M] (Kaspersky Lab) โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\setup_9.0.0.722_09.02.2011_20-07.exe
PRC - [2008/12/30 12:45:08 | 004,993,024 | โ€”- | M] (FS2YOU) โ€“ C:\Program Files\GridService\peer.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\explorer.exe
PRC - [2008/03/14 03:00:00 | 000,226,624 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008/03/14 03:00:00 | 000,136,512 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2008/03/14 03:00:00 | 000,103,744 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2008/03/14 03:00:00 | 000,091,456 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe


========== Modules (SafeList) ==========

MOD - [2011/02/11 15:57:34 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
MOD - [2010/07/04 16:32:36 | 000,004,608 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/01/19 02:26:34 | 001,684,480 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] โ€“ โ€“ (Katchall Service)
SRV - [2011/02/08 16:07:43 | 000,510,848 | โ€”- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] โ€“ C:\Users\Buddy\AppData\Local\Temp\Q.exe โ€“ (Q)
SRV - [2011/02/08 16:06:50 | 000,400,256 | โ€”- | M] (Sysinternals - www.sysinternals.com) [On_Demand | Stopped] โ€“ C:\Users\Buddy\AppData\Local\Temp\AZVX.exe โ€“ (AZVX)
SRV - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe โ€“ (Apple Mobile Device)
SRV - [2010/03/25 09:25:22 | 030,969,208 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Program Files\Microsoft Office\Office14\GROOVE.EXE โ€“ (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/03/18 12:16:28 | 000,753,504 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe โ€“ (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | โ€”- | M] (Microsoft Corporation) [Auto | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe โ€“ (clr_optimization_v4.0.30319_32)
SRV - [2010/01/06 19:07:00 | 000,147,472 | โ€”- | M] (McAfee, Inc.) [Auto | Paused] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe โ€“ (McShield)
SRV - [2010/01/06 19:07:00 | 000,070,728 | โ€”- | M] (McAfee, Inc.) [Unknown | Running] โ€“ C:\Windows\System32\mfevtps.exe โ€“ (mfevtp)
SRV - [2010/01/06 19:07:00 | 000,066,896 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe โ€“ (McTaskManager)
SRV - [2010/01/06 19:07:00 | 000,022,816 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe โ€“ (McAfeeEngineService)
SRV - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnat.exe โ€“ (VMware NAT Service)
SRV - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe โ€“ (VMAuthdService)
SRV - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnetdhcp.exe โ€“ (VMnetDHCP)
SRV - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe โ€“ (VMUSBArbService)
SRV - [2009/10/12 14:32:24 | 000,191,024 | โ€”- | M] (VMware, Inc.) [On_Demand | Stopped] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe โ€“ (ufad-ws60)
SRV - [2009/07/14 08:22:46 | 000,180,224 | โ€”- | M] () [On_Demand | Stopped] โ€“ C:\Program Files\RipTiger\ElevatorService.exe โ€“ (ElevatorService)
SRV - [2009/01/26 14:31:10 | 001,153,368 | โ€”- | M] (Safer Networking Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe โ€“ (SBSDWSCService)
SRV - [2008/06/25 08:54:10 | 000,654,848 | โ€”- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe โ€“ (FLEXnet Licensing Service)
SRV - [2008/03/14 03:00:00 | 000,103,744 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\Common Framework\FrameworkService.exe โ€“ (McAfeeFramework)
SRV - [2008/01/19 02:38:24 | 000,272,952 | โ€”- | M] (Microsoft Corporation) [Auto | Stopped] โ€“ C:\Program Files\Windows Defender\MpSvc.dll โ€“ (WinDefend)
SRV - [2008/01/19 02:33:33 | 000,136,192 | โ€”- | M] () [Auto | Stopped] โ€“ \\.\globalroot\systemroot\system32\usะตrinit.exe [WARNING: \\.\globalroot\systemroot\system32\us?rinit.exe] โ€“ (userinit)
SRV - [2007/11/14 20:46:00 | 000,131,072 | โ€”- | M] (Brio) [Disabled | Stopped] โ€“ C:\Program Files\FolderSize\FolderSizeSvc.exe โ€“ (FolderSize)
SRV - [2007/11/06 15:22:26 | 000,092,792 | โ€”- | M] (CACE Technologies) [On_Demand | Stopped] โ€“ C:\Program Files\WinPcap\rpcapd.exe โ€“ (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe โ€“ (vmount2)


========== Driver Services (SafeList) ==========

DRV - [2011/02/09 15:18:23 | 000,007,168 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\utqyntkz.sys โ€“ (utqyntkz)
DRV - [2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\rk_remover.sys โ€“ (rk_remover-boot)
DRV - [2010/07/10 04:37:00 | 011,008,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\nvlddmkm.sys โ€“ (nvlddmkm)
DRV - [2010/06/18 12:21:34 | 000,691,696 | โ€”- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\System32\Drivers\sptd.sys โ€“ (sptd)
DRV - [2010/04/12 03:44:34 | 000,059,388 | โ€”- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\scdemu.sys โ€“ (SCDEmu)
DRV - [2010/04/08 20:46:06 | 000,007,168 | โ€”- | M] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\dhahelper.sys โ€“ (DhaHelper)
DRV - [2010/01/21 00:59:58 | 000,020,864 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbdiag.sys โ€“ (UsbDiag)
DRV - [2010/01/21 00:59:56 | 000,024,960 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbmodem.sys โ€“ (USBModem)
DRV - [2010/01/21 00:59:56 | 000,013,056 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbbus.sys โ€“ (usbbus)
DRV - [2010/01/06 19:07:00 | 000,343,920 | โ€”- | M] (McAfee, Inc.) [Kernel | Boot | Running] โ€“ C:\Windows\system32\drivers\mfehidk.sys โ€“ (mfehidk)
DRV - [2010/01/06 19:07:00 | 000,091,832 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\mfeavfk.sys โ€“ (mfeavfk)
DRV - [2010/01/06 19:07:00 | 000,075,704 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mfeapfk.sys โ€“ (mfeapfk)
DRV - [2010/01/06 19:07:00 | 000,066,600 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mferkdet.sys โ€“ (mferkdet)
DRV - [2010/01/06 19:07:00 | 000,064,208 | โ€”- | M] (McAfee, Inc.) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\mfetdik.sys โ€“ (mfetdik)
DRV - [2010/01/06 19:07:00 | 000,043,288 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mfebopk.sys โ€“ (mfebopk)
DRV - [2009/10/22 12:54:18 | 000,037,392 | โ€”- | M] (Kaspersky Lab) [Kernel | Boot | Running] โ€“ C:\Windows\system32\DRIVERS\35858692.sys โ€“ (35858692)
DRV - [2009/10/22 05:00:46 | 000,853,936 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmx86.sys โ€“ (vmx86)
DRV - [2009/10/22 05:00:44 | 000,070,704 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmci.sys โ€“ (vmci)
DRV - [2009/10/22 05:00:44 | 000,026,288 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetuserif.sys โ€“ (VMnetuserif)
DRV - [2009/10/22 05:00:44 | 000,023,216 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\VMkbd.sys โ€“ (vmkbd)
DRV - [2009/10/22 04:59:48 | 000,014,896 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmparport.sys โ€“ (VMparport)
DRV - [2009/10/22 03:47:52 | 000,032,304 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\hcmon.sys โ€“ (hcmon)
DRV - [2009/10/22 00:13:36 | 000,031,280 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\vmusb.sys โ€“ (vmusb)
DRV - [2009/10/22 00:13:32 | 000,036,400 | Rโ€” | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetbridge.sys โ€“ (VMnetBridge)
DRV - [2009/10/22 00:13:32 | 000,016,560 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\vmnetadapter.sys โ€“ (VMnetAdapter)
DRV - [2009/10/12 14:31:52 | 000,022,448 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys โ€“ (vstor2-ws60)
DRV - [2009/10/09 22:31:02 | 000,311,312 | โ€”- | M] (Kaspersky Lab) [File_System | System | Running] โ€“ C:\Windows\System32\drivers\3585869.sys โ€“ (setup_9.0.0.722_09.02.2011_20-07drv)
DRV - [2009/09/25 16:59:42 | 000,128,016 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\35858691.sys โ€“ (35858691)
DRV - [2009/07/07 18:53:02 | 000,028,160 | โ€”- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\libusb0.sys โ€“ (libusb0)
DRV - [2009/02/02 06:56:14 | 000,165,248 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerTun.sys โ€“ (AVMNgTunM780)
DRV - [2009/02/02 06:56:12 | 000,366,976 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerCap.sys โ€“ (AVMNgCapM780)
DRV - [2009/02/02 06:56:10 | 000,057,216 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerBas.sys โ€“ (AVMNgBasM780)
DRV - [2008/07/21 18:34:36 | 000,121,872 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\kl1.sys โ€“ (kl1)
DRV - [2008/01/19 02:43:40 | 000,309,664 | โ€”- | M] () [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\lmqseyg.sys โ€“ (lmqseyg)
DRV - [2008/01/19 02:42:51 | 000,235,064 | โ€”- | M] (Intel Corporation) [Kernel | Boot | Running] โ€“ C:\Windows\system32\drivers\iastorv.sys โ€“ (iaStorV)
DRV - [2008/01/19 00:53:23 | 000,073,088 | โ€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\USBAUDIO.sys โ€“ (usbaudio) USB Audio Driver (WDM)
DRV - [2007/11/06 15:22:06 | 000,034,064 | โ€”- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\npf.sys โ€“ (NPF)
DRV - [2007/06/29 08:11:02 | 000,008,704 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\XAudio.sys โ€“ (XAudio)
DRV - [2007/06/20 02:29:56 | 000,984,064 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_DPV.sys โ€“ (HSF_DPV)
DRV - [2007/06/20 02:28:38 | 000,267,264 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSXHWBS2.sys โ€“ (HSXHWBS2)
DRV - [2007/06/20 02:28:22 | 000,660,480 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_CNXT.sys โ€“ (winachsf)
DRV - [2007/03/23 11:03:00 | 000,018,480 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys โ€“ (vstor2)
DRV - [2006/11/02 04:51:45 | 000,900,712 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql2300.sys โ€“ (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adp94xx.sys โ€“ (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | โ€”- | M] (Emulex) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\elxstor.sys โ€“ (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpahci.sys โ€“ (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | โ€”- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\uliahci.sys โ€“ (uliahci)
DRV - [2006/11/02 04:51:00 | 000,147,048 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu320.sys โ€“ (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata2.sys โ€“ (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | โ€”- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\vsmraid.sys โ€“ (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql40xx.sys โ€“ (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata.sys โ€“ (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu160m.sys โ€“ (adpu160m)
DRV - [2006/11/02 04:50:24 | 000,088,680 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvraid.sys โ€“ (nvraid)
DRV - [2006/11/02 04:50:19 | 000,045,160 | โ€”- | M] (IBM Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nfrd960.sys โ€“ (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | โ€”- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iirsp.sys โ€“ (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | โ€”- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid4.sys โ€“ (SiSRaid4)
DRV - [2006/11/02 04:50:13 | 000,040,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvstor.sys โ€“ (nvstor)
DRV - [2006/11/02 04:50:11 | 000,071,272 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\djsvs.sys โ€“ (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arcsas.sys โ€“ (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_scsi.sys โ€“ (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | โ€”- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid2.sys โ€“ (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | โ€”- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\hpcisss.sys โ€“ (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arc.sys โ€“ (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteraid.sys โ€“ (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteatapi.sys โ€“ (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_sas.sys โ€“ (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\symc8xx.sys โ€“ (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_fc.sys โ€“ (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_u3.sys โ€“ (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\mraid35x.sys โ€“ (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_hi.sys โ€“ (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\megasas.sys โ€“ (megasas)
DRV - [2006/11/02 04:49:30 | 000,017,512 | โ€”- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\viaide.sys โ€“ (viaide)
DRV - [2006/11/02 04:49:28 | 000,016,488 | โ€”- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\cmdide.sys โ€“ (cmdide)
DRV - [2006/11/02 04:49:20 | 000,014,952 | โ€”- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\aliide.sys โ€“ (aliide)
DRV - [2006/11/02 03:25:24 | 000,071,808 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserid.sys โ€“ (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | โ€”- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brusbser.sys โ€“ (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltup.sys โ€“ (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltlo.sys โ€“ (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserwdm.sys โ€“ (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brusbmdm.sys โ€“ (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | โ€”- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ntrigdigi.sys โ€“ (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,117,760 | โ€”- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\E1G60I32.sys โ€“ (E1G60) Intelยฎ
DRV - [2006/11/02 02:30:53 | 000,464,384 | โ€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\BCMWL6.SYS โ€“ (BCM43XV)
DRV - [2005/12/18 19:42:12 | 000,008,801 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Program Files\DScaler\DSDrv4.sys โ€“ (DSDrv4)
DRV - [2004/02/04 09:27:56 | 000,049,536 | โ€”- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\tiehdusb.sys โ€“ (TIEHDUSB)
DRV - [2003/10/15 16:52:50 | 000,174,530 | โ€”- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\ov519vid.sys โ€“ (ovt519)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/19 16:06:06 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/19 16:06:07 | 000,000,000 | โ€”D | M]

[2009/12/23 13:37:34 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Extensions
[2011/02/10 17:42:33 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (1-Click YouTube Video Downloader) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\[removed]
[2011/02/10 17:42:33 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 13:33:28 | 000,000,000 | โ€”D | M] (RealPlayer Browser Record Plugin) โ€“ C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/01/06 19:07:00 | 000,023,864 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\Mozilla Firefox\components\Scriptff.dll

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IE2EMBHO Class) - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll (VeryCD.com)
O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Grid Service] C:\Program Files\GridService\peer.exe (FS2YOU)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [facgupox] File not found
O4 - HKCU..\Run: [klboleds] File not found
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk = C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\startup.exe ()
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe (Smith Micro, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with &ZipScan; - C:\Program Files\ZipScan Evaluation\zs_ie.htm ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: adobe.com ([www] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O24 - Desktop BackupWallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | โ€”- | M] () - C:\autoexec.bat โ€“ [ NTFS ]
O33 - MountPoints2\{47119b37-d2c9-11de-8e41-005056c00008}\Shell\AutoRun\command - "" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe
O33 - MountPoints2\{632b21b5-5ce4-11df-9256-005056c00008}\Shell\AutoRun\command - "" = O:\PMBP_Win.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\amplayer.exe autorun.dat
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKCU\โ€ฆexe [@ = exefile] โ€“ Reg Error: Key error. File not found

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/02/11 15:57:33 | 000,602,624 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/11 15:19:40 | 000,388,608 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Users\Buddy\Desktop\HiJackThis.exe
[2011/02/11 15:11:16 | 000,000,000 | Rโ€“D | C] โ€“ C:\32788R22FWJFW
[2011/02/10 17:41:22 | 001,366,104 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/10 15:37:51 | 000,472,064 | โ€”- | C] ( ) โ€“ C:\Users\Buddy\Desktop\RootRepeal.exe
[2011/02/10 15:26:46 | 000,611,624 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Users\Buddy\Desktop\GetSystemInfo.exe
[2011/02/09 14:00:11 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Kaspersky Lab
[2011/02/09 13:58:11 | 000,311,312 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\3585869.sys
[2011/02/09 13:58:11 | 000,128,016 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35858691.sys
[2011/02/09 13:58:11 | 000,037,392 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35858692.sys
[2011/02/09 13:58:10 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool
[2011/02/09 13:56:27 | 091,126,696 | โ€”- | C] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 13:46:22 | 001,360,472 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | C] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:53:06 | 000,056,400 | โ€”- | C] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 16:02:39 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\ESET
[2011/02/04 16:18:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\R&R; Playlist
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/11 15:57:34 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/11 15:56:24 | 000,080,384 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\MBRCheck.exe
[2011/02/11 15:43:01 | 000,000,886 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/11 15:19:41 | 000,388,608 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Users\Buddy\Desktop\HiJackThis.exe
[2011/02/11 15:15:07 | 000,084,013 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.dat
[2011/02/11 15:15:07 | 000,084,013 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.001
[2011/02/11 15:14:47 | 000,000,882 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/11 15:14:37 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/11 15:14:37 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/11 15:14:26 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2011/02/11 15:14:21 | 284,916,510 | โ€”- | M] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/11 15:11:02 | 004,266,810 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\alg.exe
[2011/02/11 14:58:08 | 000,000,418 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job
[2011/02/11 14:58:02 | 000,000,000 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 18:05:16 | 000,000,680 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2011/02/10 17:45:52 | 000,133,632 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\RKUnhookerLE.EXE
[2011/02/10 16:49:55 | 014,710,331 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/10 15:26:47 | 000,611,624 | โ€”- | M] (Kaspersky Lab) โ€“ C:\Users\Buddy\Desktop\GetSystemInfo.exe
[2011/02/10 04:08:00 | 001,366,104 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/09 15:18:23 | 000,007,168 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:07:31 | 000,002,478 | โ€”- | M] () โ€“ C:\Windows\hegames.ini
[2011/02/09 14:00:09 | 000,002,153 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:57:53 | 091,126,696 | โ€”- | M] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/09 12:46:26 | 000,056,400 | โ€”- | M] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:50:20 | 000,609,852 | โ€”- | M] () โ€“ C:\Windows\System32\perfh009.dat
[2011/02/08 16:50:20 | 000,106,018 | โ€”- | M] () โ€“ C:\Windows\System32\perfc009.dat
[2011/02/08 16:27:31 | 162,309,026 | โ€”- | M] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:26 | 000,000,020 | โ€”- | M] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | M] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:44:05 | 000,000,758 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 16:46:50 | 001,824,872 | โ€”- | M] () โ€“ C:\Windows\System32\FNTCACHE.DAT
[2011/02/06 16:28:22 | 000,000,930 | โ€”- | M] () โ€“ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/02 19:04:49 | 000,013,043 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/02/02 18:54:32 | 000,723,956 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/02/01 10:36:10 | 001,360,472 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/01/16 13:38:04 | 000,013,259 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\PRICE LIST.docx
[2011/01/16 13:19:07 | 000,020,480 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:35 | 000,092,863 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/16 12:47:24 | 000,001,097 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/01/13 13:39:42 | 000,030,208 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\Mary Collins[1].doc
[2011/01/13 12:59:00 | 000,371,808 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\Untitled3.jpg
[2011/01/13 12:57:16 | 000,312,201 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\Untitled.jpg
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/11 15:56:24 | 000,080,384 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\MBRCheck.exe
[2011/02/11 15:10:59 | 004,266,810 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\alg.exe
[2011/02/11 14:58:02 | 000,000,000 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 17:45:51 | 000,133,632 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\RKUnhookerLE.EXE
[2011/02/09 15:18:18 | 000,007,168 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:00:09 | 000,002,153 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:07:46 | 284,916,510 | โ€”- | C] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/08 16:11:53 | 162,309,026 | โ€”- | C] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:09 | 000,000,020 | โ€”- | C] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | C] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:43:38 | 000,000,758 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 17:04:36 | 018,300,670 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\02 Kind Lady-2008- Extended Mix-.mp3
[2011/02/06 17:04:36 | 014,710,331 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/06 17:04:36 | 011,506,751 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\04 Saturday Night Love -Phunk Disco Mix-.mp3
[2011/02/02 19:04:48 | 000,013,043 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/01/25 16:59:09 | 000,723,956 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/01/16 13:19:10 | 000,020,480 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:33 | 000,092,863 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/13 13:39:42 | 000,030,208 | โ€”- | C] () โ€“ C:\Users\Buddy\Documents\Mary Collins[1].doc
[2011/01/13 12:59:00 | 000,371,808 | โ€”- | C] () โ€“ C:\Users\Buddy\Documents\Untitled3.jpg
[2011/01/13 12:57:16 | 000,312,201 | โ€”- | C] () โ€“ C:\Users\Buddy\Documents\Untitled.jpg
[2011/01/09 18:10:21 | 000,000,064 | โ€“S- | C] () โ€“ C:\Windows\ttyxa.sys
[2010/09/19 13:17:41 | 000,087,552 | โ€”- | C] () โ€“ C:\Windows\System32\cpwmon2k.dll
[2010/09/15 14:40:39 | 000,000,005 | โ€”- | C] () โ€“ C:\Windows\treeskp.sys
[2010/08/30 16:46:35 | 000,084,013 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.001
[2010/08/30 16:35:20 | 000,084,013 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.dat
[2010/08/29 17:49:26 | 000,002,640 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\9F5CC62F-036C-4906-A900-0D8AE1702BBC.txt
[2010/07/12 13:22:56 | 000,000,019 | โ€”- | C] () โ€“ C:\Windows\System32\Apache.ini
[2010/05/24 14:33:00 | 004,670,829 | โ€”- | C] () โ€“ C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | โ€”- | C] () โ€“ C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | โ€”- | C] () โ€“ C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,810,113 | โ€”- | C] () โ€“ C:\Windows\System32\xvidcore.dll
[2010/05/24 14:33:00 | 000,336,384 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | โ€”- | C] () โ€“ C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | โ€”- | C] () โ€“ C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | โ€”- | C] () โ€“ C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | โ€”- | C] () โ€“ C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | โ€”- | C] () โ€“ C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | โ€”- | C] () โ€“ C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | โ€”- | C] () โ€“ C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | โ€”- | C] () โ€“ C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | โ€”- | C] () โ€“ C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | โ€”- | C] () โ€“ C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | โ€”- | C] () โ€“ C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | โ€”- | C] () โ€“ C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | โ€”- | C] () โ€“ C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | โ€”- | C] () โ€“ C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | โ€”- | C] () โ€“ C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | โ€”- | C] () โ€“ C:\Windows\System32\mkunicode.dll
[2010/03/21 13:58:38 | 000,002,202 | -HS- | C] () โ€“ C:\ProgramData\VH56DJI7u87yo
[2010/02/21 13:19:42 | 000,000,107 | โ€”- | C] () โ€“ C:\Windows\VobEdit.INI
[2009/07/31 11:51:02 | 000,237,568 | โ€”- | C] () โ€“ C:\Windows\System32\rmc_rtspdl.dll
[2009/07/10 13:34:59 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\libssl32.dll
[2009/07/08 16:25:22 | 000,000,092 | โ€”- | C] () โ€“ C:\Windows\ka.ini
[2009/07/04 16:49:09 | 000,001,374 | โ€”- | C] () โ€“ C:\Windows\disney.ini
[2009/06/17 12:11:55 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DirSize.dll
[2009/06/07 11:24:04 | 000,180,224 | โ€”- | C] () โ€“ C:\Windows\System32\xvidvfw.dll
[2009/04/06 13:35:27 | 000,000,038 | โ€”- | C] () โ€“ C:\Windows\avisplitter.INI
[2009/03/16 14:43:31 | 000,001,222 | โ€”- | C] () โ€“ C:\Windows\AZPR3.INI
[2009/01/30 20:08:03 | 000,002,478 | โ€”- | C] () โ€“ C:\Windows\hegames.ini
[2009/01/29 17:29:25 | 000,004,767 | โ€”- | C] () โ€“ C:\Windows\Irremote.ini
[2009/01/10 17:15:44 | 000,159,744 | โ€”- | C] () โ€“ C:\Windows\System32\mmfinfo.dll
[2008/11/08 11:01:58 | 000,000,000 | โ€”- | C] () โ€“ C:\Windows\Transmogrifier.INI
[2008/11/06 10:37:32 | 003,596,288 | โ€”- | C] () โ€“ C:\Windows\System32\qt-dx331.dll
[2008/10/12 16:52:32 | 000,000,680 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2008/08/17 15:48:14 | 000,000,032 | โ€”- | C] () โ€“ C:\Windows\CD_Start.INI
[2008/08/05 16:18:13 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DGRip.dll
[2008/08/05 16:18:08 | 000,053,248 | โ€”- | C] () โ€“ C:\Windows\System32\imslevel.dll
[2008/07/24 14:07:11 | 000,000,376 | โ€”- | C] () โ€“ C:\Windows\ODBC.INI
[2008/07/23 12:16:53 | 000,000,258 | RHS- | C] () โ€“ C:\ProgramData\ntuser.pol
[2008/06/25 10:05:43 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\nvRegDev.dll
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\ProgramData\T2
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\Program Files\STLL Notifier
[2008/06/17 07:38:16 | 000,164,352 | โ€”- | C] () โ€“ C:\Windows\System32\unrar.dll
[2008/06/14 03:34:18 | 000,309,664 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\lmqseyg.sys
[2008/06/14 03:32:52 | 000,735,664 | โ€”- | C] () โ€“ C:\Windows\System32\msjehlno.dll
[2007/11/06 15:19:28 | 000,053,299 | โ€”- | C] () โ€“ C:\Windows\System32\pthreadVC.dll
[2007/10/13 04:30:20 | 000,000,137 | โ€”- | C] () โ€“ C:\Windows\System32\Registration.ini
[2007/06/16 21:40:13 | 000,110,592 | โ€”- | C] () โ€“ C:\Windows\System32\imsispd.dll
[2006/11/02 07:35:32 | 000,005,632 | โ€”- | C] () โ€“ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | โ€”- | C] () โ€“ C:\Windows\System32\pacerprf.ini
[2004/03/18 17:40:32 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\ssleay32.dll
[2004/03/18 17:40:24 | 000,667,648 | โ€”- | C] () โ€“ C:\Windows\System32\libeay32.dll
[2003/05/09 17:36:30 | 000,151,744 | โ€”- | C] () โ€“ C:\Windows\System32\ir32.dll
[2002/06/06 01:01:58 | 000,029,696 | โ€”- | C] () โ€“ C:\Windows\System32\asutl8.dll

========== LOP Check ==========

[2010/07/05 13:18:58 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\adma
[2009/02/05 14:26:12 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Amazon
[2009/10/08 17:21:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Anvil Studio
[2008/06/16 12:07:30 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Backyard Baseball 2007
[2009/07/22 16:19:52 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\BitTorrent
[2008/08/10 14:29:48 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Bullzip
[2010/07/06 12:37:20 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\calibre
[2009/05/18 18:42:43 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Computer Aces
[2009/06/19 16:45:57 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\dBpoweramp
[2009/07/10 12:29:53 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\DiskAid
[2010/01/13 16:27:35 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\DVDCreator
[2009/12/10 17:39:10 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\FileZilla
[2009/07/22 15:00:17 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\FlashgetSetup
[2010/01/04 16:09:41 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\GrabPro
[2009/04/16 15:52:32 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ICAClient
[2010/06/18 13:23:21 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ImgBurn
[2010/06/02 15:49:05 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\JAM Software
[2009/01/27 12:36:05 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Leadertech
[2008/06/12 17:29:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\LimeWire
[2010/08/15 15:10:42 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\MPEG Streamclip
[2010/08/08 12:20:03 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\MusicBrainz
[2009/08/29 15:32:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Netscape
[2010/11/25 13:51:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Neuratron
[2009/08/09 18:49:55 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Opera
[2010/01/04 16:25:33 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Orbit
[2008/07/24 13:26:53 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\PTS Charts
[2010/01/26 17:40:34 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Red Kawa
[2009/04/16 15:52:27 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Runaware
[2010/09/12 16:57:11 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Smith Micro
[2010/03/20 15:02:07 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Thinstall
[2009/09/14 16:02:26 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Trillian
[2011/02/08 15:31:08 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\TuneUpMedia
[2011/02/06 16:41:52 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\uTorrent
[2009/01/07 18:19:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ViStart
[2009/01/30 17:10:22 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\VitySoft
[2010/08/11 13:53:01 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\WinFF
[2010/08/24 15:18:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\WNR
[2010/01/13 16:40:19 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Xilisoft Corporation
[2009/02/16 17:18:54 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\XnView
[2011/02/10 16:52:52 | 000,032,526 | โ€”- | M] () โ€“ C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/11 14:58:08 | 000,000,418 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job

========== Purity Check ==========



========== Custom Scans ==========


< >

< %SYSTEMDRIVE%\*.exe >
[1998/10/26 09:50:26 | 000,012,288 | โ€”- | M] (Kristy Turlington) โ€“ C:\bin2iso.exe
[2004/10/15 11:17:32 | 002,322,511 | โ€”- | M] () โ€“ C:\DVDScan37.exe
[2010/07/15 15:36:12 | 000,031,275 | โ€”- | M] () โ€“ C:\iso2usbld.exe
[2007/08/22 16:02:00 | 000,032,768 | โ€”- | M] () โ€“ C:\mspformat.exe
[2008/08/25 22:15:57 | 027,160,064 | โ€”- | M] () โ€“ C:\RainMMS.exe
[2009/06/18 00:52:10 | 000,430,592 | โ€”- | M] () โ€“ C:\setup.exe
[2005/04/14 11:02:20 | 000,019,456 | โ€”- | M] () โ€“ C:\ui_install.exe
[2005/03/22 12:55:24 | 000,200,767 | โ€”- | M] () โ€“ C:\ul_format.exe
[2010/07/21 14:56:07 | 000,049,152 | โ€”- | M] () โ€“ C:\ul_install.exe
[2007/10/30 18:17:16 | 001,810,432 | โ€”- | M] () โ€“ C:\ZenoReader.exe


< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | โ€”- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | โ€”- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D โ€“ C:\Windows\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | โ€”- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | โ€”- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | โ€”- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | โ€”- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | โ€”- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F โ€“ C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | โ€”- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 โ€“ C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2009/06/15 10:53:24 | 000,021,504 | โ€”- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF โ€“ C:\Windows\System32\svchost.exe
[2009/06/15 10:53:24 | 000,021,504 | โ€”- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF โ€“ C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | โ€”- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 โ€“ C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | โ€”- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 โ€“ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | โ€”- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 โ€“ C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2006/11/02 04:45:57 | 000,308,224 | โ€”- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD โ€“ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | โ€”- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 โ€“ C:\Windows\System32\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | โ€”- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 โ€“ C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /mp /s >

========== Files - Unicode (All) ==========
[2008/06/14 03:32:52 | 000,136,192 | โ€”- | C] ()(C:\Windows\System32\us?rinit.exe) โ€“ C:\Windows\System32\usะตrinit.exe
[2008/01/19 02:33:33 | 000,136,192 | โ€”- | M] ()(C:\Windows\System32\us?rinit.exe) โ€“ C:\Windows\System32\usะตrinit.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A5682AEF

< End of report >

and the second one:
OTL Extras logfile created on: 2/11/2011 3:58:03 PM - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 57.22 Gb Free Space | 12.55% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32

Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] โ€“ C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] โ€“ rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] โ€“ Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] โ€“ "%1" %*
helpfile [open] โ€“ Reg Error: Key error.
hlpfile [open] โ€“ %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile โ€“ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] โ€“ "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] โ€“ %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] โ€“ rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] โ€“ "C:\Program Files\VideoLAN\VLC\vlc.exe" โ€“started-from-file โ€“playlist-enqueue "%1" ()
Directory [Browse with XnView] โ€“ "C:\Program Files\XnView\xnview.exe" "%1" (XnView, http://www.xnview.com)
Directory [cmd] โ€“ cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] โ€“ "C:\Program Files\VideoLAN\VLC\vlc.exe" โ€“started-from-file โ€“no-playlist-enqueue "%1" ()
Directory [runas] โ€“ cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type โ€“ File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-884816068-2633634329-2448390406-1000]
"EnableNotificationsRef" = 0
"EnableNotifications" = 3

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0038710A-A6B6-41CD-9DB5-A9E8FC939FAE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{02675B35-6399-4C07-8605-28A27FAB8F4A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{04133178-D39B-4A65-916D-EF882EE16693}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{072FFBCE-AC60-4519-A652-038EC17D4592}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{07FA89AF-722E-45C6-A102-424F2D4DDD5B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{082487FF-3623-415A-82BA-7C4A1D1F0D27}" = lport=2869 | protocol=6 | dir=in | app=system |
"{08D737F0-30B4-403A-982F-2831F36D4688}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0BF9F76E-F446-41FB-B23B-43C850F26023}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0E2E9FF6-64A0-43B5-9D6E-2A9FFA59DBFC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{1011D1DD-4D45-4CC1-902A-378B8ABA3DAF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{12AC736D-6305-4D82-B430-8FED7A6F7E66}" = lport=2869 | protocol=6 | dir=in | app=system |
"{12B67DA8-447E-45BE-BC3F-585E090C15E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{141F209E-778A-4223-94C9-08444295D16A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1BD51608-D53B-4F27-8C67-2B761076781A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1BE556D5-9DCE-451B-AF23-922CEF84FFB7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1D0C565D-0815-44F8-8D08-4380267B9D9C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{222BBB4D-2316-4644-9D3A-511E81159012}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2432BCA9-56CF-42F1-AB5C-1B560E3497D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{25B9B28A-B1F2-4042-B535-16BF3E4988C3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{26900A16-6E42-428C-95D4-6D16AB8686DB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{26B7913D-0EAC-45BA-AD6B-FBF3E94B04F6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{27210CAC-2490-4F9F-8B7B-A7998A28B254}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2D4E0C06-62C4-4FEF-9BB8-F6323A28D160}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3418E948-D7AC-45EB-A252-E645F072D1CF}" = rport=138 | protocol=17 | dir=out | app=system |
"{3652DF46-DFB8-4803-9D5C-5B740A14D04E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3A27482B-AC15-47E9-BA26-D8E5C11213F6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3B0524FF-0E24-49A6-87DA-7310FA677D80}" = lport=2869 | protocol=6 | dir=in | app=system |
"{3B4875B2-968F-4E83-BA0A-CCFC11201E09}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{3F19CCC9-1F24-443F-9ADE-7CBC240A0D17}" = lport=2869 | protocol=6 | dir=in | app=system |
"{40341610-A6E1-432D-82D1-035130DB172E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42BD5233-7CCE-4A71-9248-44BD5F243B5B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{44BF84F3-D6DF-4E08-8144-BC4867354E1B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{47ABCA2D-B361-4F0B-9781-1DE7966E67FA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{485E353C-882C-4170-90D3-597B949D2C5D}" = rport=139 | protocol=6 | dir=out | app=system |
"{4A8F6F5D-8C37-45DA-9B90-B87C3874E735}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4AA32FB7-2E84-4D2B-892B-600F3CF4FAF9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4C4D17DE-7047-44F0-B642-B0B49B1BD880}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{4D0BF242-8B44-45CE-B178-D0A976080AE8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4D861D62-181C-48A2-943D-4041EB6BB425}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4E937579-16FF-42B8-AD55-9549E19E1AD0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{4EE0F3AF-FFC7-47F2-AA37-6B6A12D8CCFA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{547B4C16-DB5A-4FC5-8110-45F9DCD43B66}" = lport=2869 | protocol=6 | dir=in | app=system |
"{54C55CFB-6293-457A-B43A-81BCC30F2B0F}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5593ED7E-4CB6-4D67-9037-7C26DBD6C21D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{56230CEB-54A5-42C0-A0C7-60E499F53CC6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{57CBB570-C089-4E01-8393-FF189D14A3E5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{5A37A3B2-7E34-42D9-BF38-2E2EB6CC360D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5B3E831B-D7D9-423C-986B-83EB89786CB4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5F1937FB-B4A3-4BD8-A70C-B75990268984}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6285B48E-6869-451E-B064-C681DAE83376}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{633CB5E8-E304-4ED9-8C63-A6015B48600A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{689A76D7-BC75-4AD0-85E3-F88BE5421D9C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6B59CAFE-47D7-4C2E-91EB-44E8A48F1FEE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6B62AB14-1D08-493D-BD0E-0AD64A22287E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6BC3C9AF-29C8-41C2-A77D-B30E99DE7477}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6F3D7B3C-080E-4C8A-AB49-293CCC9D6DDA}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6FE7EBF4-A4C9-4B1F-8D5B-EFE6A153A677}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{740C96D5-D77D-4C1E-9ED5-E728350438BB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{77047727-C053-45EA-AA07-0A831476AE0E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{78E775E3-4D5F-43A3-A941-78F8D0CAD798}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{79C37851-A5DF-4A64-94AD-C3A25A84BC6B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7A3C952B-9BC5-4AA2-B7A4-3D691D8465DD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7D7DB8FB-FF5E-4D58-8CBD-C2AEF42558BE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{7F260A66-7C53-4F1A-84B2-B39367A016B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{85720613-BFD6-4559-B0FD-E7203A487FE9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{86B113EF-61DF-4BB2-BB3A-F0287913E044}" = lport=2869 | protocol=6 | dir=in | app=system |
"{87AABC01-6786-4301-A35E-CEA6964F10D4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{892AB5BD-81E3-4CB9-975D-93DC2AED8A81}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{89727718-0FA9-4456-90D4-98013475A896}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{89D06362-4696-4A50-B6BA-B1EB20E95010}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8AB6A6F3-1342-4D0A-82E1-378EC086BA5C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8ADF727D-65EC-46C4-ADBF-92019CAFDC64}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8B52B786-07AA-429E-8EB0-C10FBCE6417A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8C851D2C-4DC2-4C9F-8B40-1746086883B9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{8DA17614-6ABE-422F-845D-FF48A47756F4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{8F2C9246-A70E-4B6F-B298-6791329EF3F1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9256340F-BFEA-429E-B575-C9807DC6D00C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{97DA4303-EE85-44B8-8E8A-DECF77E40D39}" = lport=2869 | protocol=6 | dir=in | app=system |
"{99D758BA-9850-46F4-B157-FA5FF680E63C}" = lport=139 | protocol=6 | dir=in | app=system |
"{9BC64A32-EA00-49D4-8C67-187C2D6EF13A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9D803016-E55E-466B-AEA0-CB61D281D616}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9FAA681D-0480-41B7-B98D-B63F80309315}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A1F271AC-F435-4B74-86A0-3B39265A61B8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A3570CDD-52A4-4C72-983B-95FBF614B011}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A371BB45-DD44-4DF9-BED3-A664AD8792A6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A3BE162D-01E6-468D-84BB-911F9A236D3B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A4035793-D268-431F-99B4-C1D69E0F1654}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AA5C8AE6-5AFA-4322-B80D-661CE2129B80}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{ABF30DA0-DE75-4263-A7C6-D6906CB706CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{AC03C9B7-6A8E-4AC5-99FD-5BA203428FD2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AD94DCBC-1A47-43F5-810D-4D50ABCA5D51}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{AF13D2BD-373C-49CF-8B99-5408AE4AE955}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B0094948-604A-4E91-BB4F-D5E99FAE77B0}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B0859248-C48D-47DC-9132-BA82FD59D26E}" = lport=138 | protocol=17 | dir=in | app=system |
"{B984A4A9-9886-435A-A3AD-8795F27CBA2C}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB534745-2E50-492E-A050-BF3215383548}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BE18AB25-DBDF-4481-95E3-1884962B5555}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{BFD94C60-7E55-4265-8D69-726A87B2AF39}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C42B860D-01EF-4774-817E-32F2BFBABB98}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{C4D519BA-E541-4C08-B781-EDCF2541EAA7}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CBF46718-0AF4-4BC7-8E74-AD181DE67C5C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{CE12DAF4-1593-4373-BB94-858ED82B91ED}" = lport=2869 | protocol=6 | dir=in | app=system |
"{CF57F923-0EF8-49E5-AE22-98E4217AB2D2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D220EF44-A4A5-43A9-B250-F27987C7E2F2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D31B48CD-77F8-48BB-BBE0-ACE96A6C06DC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D6318E45-23A2-4EB9-A13B-25C6F48D303A}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D692E065-3752-4BE6-A4DD-65E76A60991A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D92CCEAB-4B09-4D1B-8DDB-1131D7854ABE}" = rport=137 | protocol=17 | dir=out | app=system |
"{DCE53EA0-B44C-4773-A152-E0B5DEBDB63D}" = lport=445 | protocol=6 | dir=in | app=system |
"{DD477C1D-A3B3-4A46-BDE2-C48764F942A5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DDE3E533-88DA-4EDF-BA55-6C7CBA3C1897}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE6906EC-51DB-437F-801B-2E2922355DAF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DE7DE82C-AC63-4241-9BB6-737B3D5EB9B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{DED0A12E-B4FE-42AF-91F5-E31E7E94A8CD}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E095AD90-F621-4DF5-B2D2-213E5A7E2BDE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E342BD32-C732-498D-87DF-A60BF8DB4100}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E373046A-154E-445C-8BED-6ECDCA63E13E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E3F0BDB0-E6F3-4ADF-A8AA-6524EE83FCC3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E4097165-9D17-4165-A54E-7116EB08A9D6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E4F96B15-939B-4FD4-BA65-863C233210B1}" = rport=445 | protocol=6 | dir=out | app=system |
"{E57396D3-5A48-4B07-9E57-54194C3F89A2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E66DF4A3-600E-4664-BECA-2F927EC4BDA9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{E960FB48-5982-4AA9-A793-B31671DDE852}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA699B67-7AB1-4340-9DA4-D42BEA75CA21}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA69A46B-E70D-4196-B988-11B568F83332}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EA840964-07B6-4819-B401-54904E20E3D2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F10059AD-2D68-47C3-9D2E-B2A7537F3E6D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{F2C66EE3-4CD9-4432-88B7-3C30AD0A6302}" = lport=137 | protocol=17 | dir=in | app=system |
"{F2DCF78E-EB79-4A57-AE75-E69EFD78F000}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F74302DF-97E0-4415-B5CF-CD5B5A3196E4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{F8B8ED35-9EAC-4FE1-87DC-2E2F492F59FE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F9194DC5-0BE9-4E0D-BE94-3FDBDA78F110}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FB14F465-FDF5-471B-BF8C-F284E0D26743}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FC2C7EE4-7A98-41C1-8FA5-D869B70C2381}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FD785925-6D3C-442D-8834-95F9704AF216}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FFB0AEA1-4489-4371-9608-E6A458C1D940}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{028C1277-0547-42D2-901F-B314F41F63F9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{04071031-E0D4-42C8-81AC-1E54473F5E7F}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{04775E9C-7606-449E-BABC-4D73864D67CE}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{05B338FA-3BA1-40DA-B8F7-E2406993DE76}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{061FEC75-9762-4855-A26E-9AC410FDC8A5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{06A9C4EE-E0B1-438A-B1ED-503E72D3FA24}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{0830BA37-BC0D-4EF8-8E1E-4F381BBE3289}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbir.exe |
"{084F7C45-86AD-49F5-AA9C-0E0A440EE313}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{089D0100-58A1-4F6D-B0DA-9A50F16A95F4}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{094201E1-2B1F-4834-BF93-06784EFFBF0B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{0CF1E1B4-9A2D-4799-B643-CA7E34391D25}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{0E133A97-1974-47E0-B3C7-4B3660346F5C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{102F8A87-DF45-4F03-A863-97B0013E71E4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{106ED8B4-1F00-45A2-A277-93B7097E8A7C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1176750E-798D-4C55-845A-C6B715190D7C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{11A8DD28-6B44-4145-96B7-C2BB57490124}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{11FDF9FA-CB09-41A2-A1C9-1FC09C1CDAD5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{13C9FBB3-D57C-4D63-B7C8-49BCFF71B8E3}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14914349-68CE-4544-A818-2EF28D9601DF}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14C18A59-3B00-4CEE-9A9D-C8FCB807997B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{14DD9F83-9C0A-4615-9107-235DD7BDED44}" = protocol=6 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe |
"{150E2550-D576-454D-ADDF-59DA271A525D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{151E3E54-2ABA-41F9-BB52-C71A394DBC2C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{158B6896-8A9B-475F-B41C-A4F96503FADA}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{16256B54-E8C4-47DF-B230-D32AC90CD43A}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbsetupwizard.exe |
"{18987352-7F44-442B-8745-ECE1258C19B8}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1B0AB08A-6720-4229-8B51-F010CA435876}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1C2597C8-AB83-4D5D-A6F5-027443C23F18}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orblauncher.exe |
"{1DEC7882-8F2C-4F5D-86C5-DA01C21E0A5C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{1EA6F1FE-C1E4-4077-A09C-3010E3081493}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{1F3C8F75-8323-4636-846F-A24073B7B5FB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{204D7BB7-92F5-447C-A48D-F415EE8986CF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{24ECE452-DF94-4312-9E19-C4C979994373}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{25497AFF-C892-439C-9E45-54B5953EF72C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{27A10407-3FC3-4633-B33A-62B7D76DAF08}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{27E2E497-8777-4C2E-B67F-CD1E212A7CF4}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{2A3222CF-2F03-488C-90BB-26A1E37C6274}" = protocol=17 | dir=in | app=c:\program files\gridservice\peer.exe |
"{2A431852-FBE9-47D2-91CF-F6255957D720}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2CC2A91C-0CA7-4873-8F85-DED7891BEE1F}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{2D68F57B-BB98-422F-A041-B42B19B88C27}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2D6A2F7A-A071-4E54-8D3D-F7F4BA57B341}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{2DA5AF1B-B18D-4F89-B044-A9B9478635DB}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2EC2BA18-0349-4BF3-8D58-4F7682763DE8}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{2FDA6AA1-5589-4A46-B6B2-9D6D36FFD326}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{31BA544E-C4C5-446B-B6A2-492D514496C2}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orb.exe |
"{33E17E6B-B2CA-4F2B-AC5A-2277D3EB49C3}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbjetmanager.exe |
"{35B48F4C-5892-4F02-9FDC-1157F50D3C5D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{3915E601-4155-4B56-80BF-52F5C15AEE1B}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{39E3A514-3258-421C-9A16-5233DD858585}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{3AF24F69-40FD-4E92-8577-6D002C6B62D5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{3BB475D3-1B94-464C-837D-E1B37AF064B0}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{3BB53E58-DFBF-43F8-B47D-D02124B8A6C4}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{3BFEF07B-031A-4040-969F-4C80CBB3513E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{3DC499E5-80B6-4972-8237-B4A653E03501}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4207DCCA-13B4-4F46-B22D-6EF90C56C4C0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{438BEEA7-F74C-4524-BDAF-5A2BB657B359}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{43F775D8-3E7B-4A88-8AF6-260214E510DA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4465BAAB-137F-4423-9AE8-1C4A79084D53}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{44EC5020-7BD1-459C-B560-5189CCC29D46}" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{477BB934-476E-4E3B-8440-428FC0766140}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{49DF4CEF-2F87-473E-88F5-C131F7B6736A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4A99AA79-BBED-407B-8CE4-E9DF9F474B22}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{4BA9D218-7FDD-4EC3-AF10-3D36BDAAC3B4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{513ADD08-48F6-41EC-B7F5-CD1A2BDB0E34}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{52BAB8F8-2648-4794-9A68-8FEFC4F01547}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{52C39967-1A5F-4734-A333-17D45719DE8B}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{52F3B807-9207-4552-9ABB-8C392603A3D4}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{53011F87-1243-451A-9B85-ACE66B5FFDA1}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{53521128-1B67-4A75-9ABD-30A32DFFDEEB}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{5465A2AF-500C-47D4-BCDB-050107A40E3A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{557064EB-02D6-4CE7-820B-8DD5ABAE74DD}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{56115686-40F0-4CF7-A617-A0290FA00A07}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{57179EEC-A10E-4A9C-ACED-EC388C2C545B}" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"{59137205-D94A-4D11-AFA1-EC337E333023}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{5955078B-D9CA-437C-B897-6837534E5578}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{5AD1A5D3-1690-4436-9790-221425851D6F}" = protocol=17 | dir=in | app=c:\program files\vmware\vmware workstation\vmware-authd.exe |
"{5BC8DBEC-36EF-40B1-BDC0-D14AFCBFA618}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{5DA0CE24-56E0-450A-897A-36FF7EFC877A}" = protocol=6 | dir=in | app=c:\program files\gridservice\peer.exe |
"{5EE3B6CE-C13C-4A26-A7EF-572BDA921004}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60FB3409-C5BE-4E06-834B-89DE75CFB9A4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{616FE863-1F4E-4F1F-960C-05918921B6F6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{61837AC6-CA35-4448-9EFF-E012FF6FE659}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{625F90E7-B013-443D-9EF3-FAB0618659F4}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{626DBC38-97B2-455D-8597-569E73939740}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{62755CAF-9F8F-42B3-8FDA-328A8E5E853C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{63106BCA-3862-4064-A3B8-DB5A2B516270}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{63AF5338-60FF-42AB-BD1D-13DD8908539E}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orb.exe |
"{6519DBF6-28BF-4A8E-A88C-76409D8DCEDA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6587D758-F9E6-4561-8789-DC1D95E6E1FF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{6588FE6C-1470-4D3B-B4B7-CD980A6FF613}" = protocol=17 | dir=in | app=c:\program files\proxy switcher standard\proxyswitcher.exe |
"{6AB4C37C-A52E-4DE7-A462-F408D9D23AAA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{6AE57194-59A7-40A9-8317-E0E9D91793EC}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{6C8F7314-AC03-4E07-B3E9-3F3EB6CE2EE6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{6FAC0B7C-9FDA-4698-8F46-5D380A56B2BE}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{703184A4-2BAD-4DC5-BBE2-F2F7EDEE09E4}" = protocol=6 | dir=in | app=c:\program files\vmware\vmware workstation\vmware-authd.exe |
"{74A363AE-3478-4E27-9F46-47DE8248C516}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{74B25ADC-66CE-4F2E-882F-2E1155C072CF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{78D43445-74B2-4D10-9C75-57CBE92B8C1A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{79376691-CDE4-4C19-9BD0-B31D82139114}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{7C405808-C0F6-46CB-BFEB-75936215AFB7}" = protocol=17 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{7C4CD6E9-D1B9-4FD1-A039-B2FC5592F946}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{7CE1F3AF-A141-42A2-8BF5-684DFB5CEC65}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{7E98F96C-E3CF-48B9-9AA9-ABAABE9E4A4D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{7FFFA1DF-0F6D-4B7D-82FB-8D1B9BCC0422}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{817D71C0-FC58-4531-8C68-0CE4857B293A}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{81C741B2-22B8-47EA-BFAD-1188585F4A00}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{8450D329-B889-4928-B3F6-5A964EBE7F4D}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orblauncher.exe |
"{850ED9D6-DA6C-4419-9493-A9CE1AD12DB0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{88ABCE84-A4AE-4A25-804F-6EDD0E3204F7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{89E64CCF-8688-46D1-8569-29A489ACA18E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{8A069829-BDE8-4C0E-BA46-0EEF355F6C87}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{8B5F969D-DB68-4AF7-B067-1DF74FA9B9BF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{8C89145F-FA46-479E-89F1-1D57F90A2311}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9029534B-11C6-4F24-9963-D7D1C3B8E99E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{90FCF779-F77D-4ACE-85AA-7F7FEB2013FC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{925104C8-6AA4-41B6-8AEA-B6E826B196EC}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{92EE15B6-6643-408B-8CDE-50FFE6514E8B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{937C4CE6-0B91-40A3-9280-BBE6CD945A68}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{98591E0F-F9F3-4BF8-AF00-EFD623F7D9A0}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{99298F5D-B351-4019-8F2C-CBFE3FD2FB28}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbtray.exe |
"{99448B74-6509-4699-9D4B-826DA7403ACB}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9A0094EE-306D-4E7E-8731-24350D31FEB6}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9BEBBE0C-1322-4615-8E9E-077982D1D077}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{9D8B838C-A664-4BB9-A06E-91331D3859ED}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9F0ADE44-F342-43C8-84D9-5418D1E7E676}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{9F219DB4-C7CF-4474-A85B-25B886B48D45}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A1FFEED7-F5E0-41E2-9FDF-C76620BD1809}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A2449480-EA2F-4787-960E-67B9296E8B87}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A29270A5-8E78-419E-A1A5-6C5B91434BF5}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A59CA635-EAF4-4B9C-B556-92EC1B91E654}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A6490E52-C09A-4CF4-B214-F85C7AB04262}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbstreamerclient.exe |
"{A993DEBD-7925-4750-AA46-F020DDE15A9E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{B0777501-548D-4827-95F8-EB9C75F2433C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{B14569F3-8ED6-4DCA-9463-6D18F67E6F7D}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbir.exe |
"{B4077713-4BFC-4CF6-ACF6-477535B74421}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{B4B06BA9-EDFB-470F-86FB-C08AA5E828FE}" = protocol=6 | dir=in | app=c:\windows\system32\services.exe |
"{B696C256-C633-436D-AC8A-373F31F84BB5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{B9201CC2-2748-46F4-9920-7175EC647790}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbstreamerclient.exe |
"{B9D4BF43-4328-4826-8F9E-93BA3E363481}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{BEA9361E-B752-40EC-8EC4-E213AAAFB03B}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbtray.exe |
"{C245BB6E-88ED-4E0C-8EF2-3D1D50AE3246}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C260B664-6CA3-4A9C-8D3B-1EDDA76ACBF9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C391C8D2-DC00-4450-8FFE-A97FAE869E31}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C47F06B5-42EB-454E-B18E-462A6FB5DB58}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C47FAFEC-E1B7-4710-B072-41026F8A3695}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{C5169B7B-E1BE-4637-A68B-6A0FA1ECBB1B}" = protocol=17 | dir=in | app=c:\users\buddy\appdata\local\asam.exe |
"{C522D02E-6D1B-45FC-9273-1983FEF0DF58}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C61B0329-078F-49F6-A32A-19C94C8DE62E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{C63DEDBD-89D7-4A57-B4BA-1DB8FE813F8B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C720CEAE-B0F7-4F9B-BC5F-2E6D7CE7E706}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C8CEC9A7-6B78-4231-B195-B5401BDB7D21}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{C91184B9-ED64-4022-9B25-71E571C2EED7}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{CA0CA2D8-C2D0-46B9-90BC-DDCAE24C715B}" = protocol=6 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{CB2C717A-9B8D-4619-B1CE-09D74302B82C}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CB48E0F2-91E6-45FF-8DB6-4C8B4CE5E5F0}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CBC57300-65EC-425D-B1C6-2E6951BD859E}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{CE331336-CE9B-4E10-A403-C80D5A5A8271}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{CE5DD0B3-AFAA-41CD-866C-7743B07CBD13}" = protocol=17 | dir=in | app=c:\windows\system32\services.exe |
"{D03A6B8C-0B94-41DB-A426-BDC03BB9897C}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4B80243-D24A-47C7-86CB-5622A8843CAA}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4CD1C15-A348-4C14-90F1-B07E5D0BE7B9}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{D4DF6F5D-660D-4914-BB5D-1FBC8CC54343}" = protocol=6 | dir=in | app=c:\program files\msn messenger\msnmsgr.exe |
"{D68B2B8D-DCBF-4472-8188-7E91B7588B8E}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbcontrolpanel.exe |
"{DC78CDDE-745D-4B69-8E0B-1C3E3CFEB6F9}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{DCD506BE-22EE-46DE-81E4-D7A174750169}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E0226679-D331-4C0F-A207-CFB594883845}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbjetmanager.exe |
"{E0C0736E-932F-4A1A-A3BD-C6C5A60BF68B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E0D51666-8C60-42C2-A154-714C5E710018}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E1AEABA8-7391-4E61-B9E4-960123A1C8A4}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E26F5185-01C2-4933-BC4E-19CA92E02A2F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E4C492F4-C6F1-46BE-AAB1-8F04C3A996C4}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E4CCDFEE-0D6F-4B88-9992-E5B61B77894B}" = protocol=17 | dir=in | app=c:\program files\mcafee\common framework\frameworkservice.exe |
"{E5F4FE5F-F396-4AB1-8FFD-1B9FBE0117AF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{E73C6628-CACE-4AE1-BAA1-D2FE88F37255}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{E85289FD-794E-4439-84CD-478FE8E6022B}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{EBFF72C6-0202-47EA-9AE2-6FB82F695B87}" = protocol=17 | dir=in | app=c:\program files\orb networks\orb\bin\orbsetupwizard.exe |
"{EF1FDDDF-3FDE-4FCD-BD87-ED6D2CDA0F3F}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{F20FC67E-D2C0-4D08-9280-A03A62E764D2}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F43BC183-A780-4AF5-A9E6-8D7EBC1BA88A}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{F4D13C11-B2D1-4981-96DF-AFE47B456898}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F5E9F260-B9E8-4BA1-B744-874665E8E2DB}" = protocol=6 | dir=in | app=c:\users\buddy\appdata\local\asam.exe |
"{F63F7673-1D5A-440F-8A4C-C315F06CBE62}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F798CE31-DDEB-4A8D-AC4C-9C935E634366}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F8E93EA3-0CDA-4CB0-A167-48CB10A79CC9}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{F9400835-349E-4239-9F0E-78506BC44903}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FC16A81B-631E-4285-9E36-2ED043B1E03A}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{FED2EC95-4B39-4AF2-874C-0CA7EDA95BC3}" = protocol=6 | dir=in | app=c:\program files\orb networks\orb\bin\orbcontrolpanel.exe |
"{FEE64386-291C-4E98-82B0-BECC590035BF}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{FF1762E4-A361-4B57-8A8A-392CACEBF5CC}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{FFA52EAE-3741-48FF-86B5-02813D1F2003}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"TCP Query User{273DF01A-B650-4132-B3B3-AFACB84A8A74}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{2E1A58C4-D54C-4562-9931-C0272791F9AF}C:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{30B0E3D7-A7D2-4859-88A3-023496653A5D}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{4F304581-CD7E-441D-9FBB-B8029DBC05C8}C:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe" = protocol=6 | dir=in | app=c:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe |
"TCP Query User{50396E98-187C-4735-A6A4-63CABE0ED212}C:\windows\system32\java.exe" = protocol=6 | dir=in | app=c:\windows\system32\java.exe |
"TCP Query User{5BF43656-E979-4CB8-8367-230A6DE106BD}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{5CA16B13-9C13-4562-B239-8EE931E11EE4}C:\windows\system32\msupdate.exe" = protocol=6 | dir=in | app=c:\windows\system32\msupdate.exe |
"TCP Query User{64CB1F41-EB96-4345-B6E2-8E486467FF0C}C:\program files\musicbrainz picard\picard.exe" = protocol=6 | dir=in | app=c:\program files\musicbrainz picard\picard.exe |
"TCP Query User{6732AF4E-43C7-4106-867D-96C4FFA05C9E}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"TCP Query User{6BEB4DEE-8DF5-4ACD-A382-9F5397EC1BE0}C:\program files\easymule\emule.exe" = protocol=6 | dir=in | app=c:\program files\easymule\emule.exe |
"TCP Query User{7775C53E-1ED2-4E68-BB13-7619CD288610}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{7FAFBD81-939A-4B4B-917D-A231FBB257AA}C:\users\buddy\flashget_9973_1.exe" = protocol=6 | dir=in | app=c:\users\buddy\flashget_9973_1.exe |
"TCP Query User{816AB801-B93F-474B-A769-C8F6F85B1B15}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{CEBA1429-3B70-4C60-B6F4-D8ACD70A38CA}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"TCP Query User{D2050883-34B3-46E4-9163-2108DCBBEB7B}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{D75CA748-9AA1-47E3-82AA-EA97F6650468}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe" = protocol=6 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe |
"TCP Query User{FC79F710-187B-4F98-8EAD-7A54F34E2B83}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{06E88B6C-2D3C-4D39-A54C-58406EED118D}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{2DE2C14F-F900-4E99-9E9E-BDE617F5FC91}C:\users\buddy\flashget_9973_1.exe" = protocol=17 | dir=in | app=c:\users\buddy\flashget_9973_1.exe |
"UDP Query User{33EE43B4-F7ED-48B7-BF5F-2381E0740FC9}C:\program files\musicbrainz picard\picard.exe" = protocol=17 | dir=in | app=c:\program files\musicbrainz picard\picard.exe |
"UDP Query User{41F0EB9A-6964-46EE-8BCD-5402724C9542}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{43C7B7BE-2A39-4326-B7CE-19E88A4FAB66}C:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\buddy\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{4C1247DA-87E8-488E-919A-EEEA7C0353F4}C:\program files\easymule\emule.exe" = protocol=17 | dir=in | app=c:\program files\easymule\emule.exe |
"UDP Query User{4F8F1E4D-CE3B-4908-AB4D-0657CBC5DBB3}C:\windows\system32\msupdate.exe" = protocol=17 | dir=in | app=c:\windows\system32\msupdate.exe |
"UDP Query User{55179B5A-1474-47B5-BCA9-16C3192E5809}C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\english\setup.exe |
"UDP Query User{62440872-4C4B-42A3-B02D-1ACC3B018480}C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe" = protocol=17 | dir=in | app=c:\programdata\kaspersky lab setup files\kaspersky internet security 2009\english\setup.exe |
"UDP Query User{990C0DED-2BE7-477E-BEEE-2425ABB96DF2}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"UDP Query User{B5168D4C-2609-4B46-9365-14EF9A9F07D6}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{CD25C382-A4A1-41F0-8E1A-4213771373FB}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{D24D7225-C5C0-4E85-807A-DF7EF385A836}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{E6EE78A1-126F-4F94-9D54-A9AD0C5EFD4E}C:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe" = protocol=17 | dir=in | app=c:\users\buddy\appdata\local\microsoft\windows\temporary internet files\content.ie5\3z5ookz7\flashget_9973_1[1].exe |
"UDP Query User{E8C30749-253D-49EC-BE24-3C5F24D8A65C}C:\windows\system32\java.exe" = protocol=17 | dir=in | app=c:\windows\system32\java.exe |
"UDP Query User{F39C1798-555F-41E0-B99B-046FF9E46A0D}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
"UDP Query User{FDE81636-31CD-4646-AC4F-90CC25AAE05D}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08DEC21F-F7E5-46F9-81D1-3ED30BD3AEC9}" = CASIO USB Driver V1.2.2474.0623
"{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour
"{0E2B767B-EA6A-489B-BF83-8083FE1DB661}" = Pcsx2 0.9.6
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{147BCE03-C0F1-4C9F-8157-6A89B6D2D973}" = McAfee VirusScan Enterprise
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Javaโ„ข 6 Update 13
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Javaโ„ข 6 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Javaโ„ข 6 Update 7
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36C9E08A-BE2B-40A0-83C5-576748F7B777}" = TestDrive Client
"{37003C6E-DC86-4233-B5CE-665D82DFA7EB}" = Backyard Skateboarding
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}" = Adobe Photoshop CS3
"{3D9892BB-A751-4E48-ADC8-E4289956CE1D}" = QuickTime
"{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{47609E69-4C5E-48B1-A889-24C6B82B5C04}" = Vista Shortcut Manager
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{495B6040-801F-474C-ADB8-309F132CF5F9}" = iPhoneBrowser
"{51846830-E7B2-4218-8968-B77F0FF475B8}" = Adobe Color EU Extra Settings
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F}" = GetDataBack for NTFS
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Simsโ„ข 2 Teen Style Stuff
"{5D51C5DC-3604-4C3B-981B-309340755447}" = Pantech Handset Driver
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5DC0DF76-3B2F-4C38-BE34-58627949BC1A}" = Mega Manager
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{601D774D-0D04-4CB1-9E3B-5394FAAFA1FB}" = VMware DiskMount Utility
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64963F0E-03F2-4B59-8D1B-1806545E7092}" = NVIDIA DDS Utilities
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Simsโ„ข 2 Kitchen & Bath Interior Design Stuff
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6DF94034-2D3C-4D67-ABE7-1C728399B963}_is1" = PDF Rider 0.4
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Simsโ„ข 2 IKEAยฎ Home Stuff
"{6E7F1130-F68A-46A1-96ED-5BFE51A3A605}" = Backyard Baseball 2005
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Simsโ„ข 2 H&M;ยฎ Fashion Stuff
"{85991ED2-010C-4930-96FA-52F43C2CE98A}" = Apple Mobile Device Support
"{85F4CBCB-9BBC-4B50-A7D8-E1106771498D}" = Orca
"{86488BFF-6368-4EB9-8567-BA2E2E2BDB20}_is1" = ZipScan Evaluation 2.2c
"{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Simsโ„ข 2 FreeTime
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90120000-00B0-0409-0000-0000000FF1CE}" = Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{68D57797-481D-4FAA-A53A-060E8EE67654}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{91F7F3F3-CE80-48C3-8327-7D24A0A5716A}" = iTunes
"{945126B3-E790-45FE-A5B4-D108DB681B61}" = Sibelius Scorch (ActiveX Only)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{95655ED4-7CA5-46DF-907F-7144877A32E5}" = Adobe Color NA Recommended Settings
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A20DF6AC-0300-45E2-8152-7D677E4E8CF5}" = HotFile AutoDownloader
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A3BC1DBD-64D6-4EBC-0091-24C811662D40}" = Madden NFL 08
"{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation
"{A5CD6670-1F48-45A3-B3E4-8238FECD1FA5}" = File Downloader
"{A638557B-1F13-40A0-9627-C892FBCA6960}" = McAfee Agent
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A90C03D6-08E1-4C59-B93B-6919A6C0AC19}" = TSP_CODEC
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}" = PDF Settings
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AFD4597D-56CC-447F-AA68-C1BF1AEA448E}_is1" = RipTiger 2.7.4
"{B0B46A1F-EC96-44A4-A9FB-62FE33BAF7DE}" = Rapidshare Auto Downloader 4.1
"{B1526BF0-3991-4899-9998-78BCC746C256}" = Help 1.0
"{B1EDEBF1-B4DA-46A5-B346-D1B580548EAA}" = iPhone Folders
"{B2AB8AF6-AE06-438F-A3D5-C9FBFBDB0AC0}" = Backyard Basketball 2004
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BEE7766E-C99F-4735-A42B-77924324F253}" = Backyard Soccer 2004
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Simsโ„ข 3
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem Driver
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C6AA3FB7-804F-4808-AD91-B62D6ED9B788}" = Windows Vista Upgrade Advisor
"{CBF9963A-C3CB-4676-BDEA-78C2BC1055E8}" = calibre
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}" = WinZip 11.2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D6D4828F-A5B2-11D4-8F73-0050DA0F6297}" = The Sims File Cop
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}" = Adobe Color JA Extra Settings
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Simsโ„ข 2 Seasons
"{E0B289FB-8053-099A-59E4-CC825EA4F3CB}" = MDownloader
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E56D39F8-2A9F-44B4-B068-A72E45A073E6}" = Safari
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E7269FD6-34EA-4617-8752-6739AA384080}" = V CAST Media Manager
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Simsโ„ข 2 Celebration! Stuff
"{F00A3A54-C293-8F64-7C6D-9A4C09106FD8}" = Antivirus 2010
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0EB3969-C007-4ABE-9245-990C5E021A8F}_is1" = Sibelius Sounds Essentials for Sibelius 6
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Simsโ„ข 2 Bon Voyage
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7
"{FB068BA4-C6EA-4D47-A491-C40E23E77F89}" = Motorola Driver Installation 3.9.0
"{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}" = Folder Size for Windows
"{FDF64A37-4842-48CD-A424-2C38444D36FD}" = LG Android Drivers
"{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}" = Adobe Setup
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"7-Zip" = 7-Zip 4.57
"A7563CE811A177DD86E2680F4A65B8D083CE4D72" = Windows Driver Package - ViXS Systems Inc. ViXS PureTV-U (12/07/2007 6.2.100.12)
"ABC Amber LIT Converter" = ABC Amber LIT Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe_719d6f144d0c086a0dfa7ff76bb9ac1" = Adobe Photoshop CS3
"Advanced FTP Password Recovery" = Advanced FTP Password Recovery (remove only)
"Advanced ZIP Password Recovery" = Advanced ZIP Password Recovery
"AFPL Ghostscript 8.53" = AFPL Ghostscript 8.53
"AFPL Ghostscript Fonts" = AFPL Ghostscript Fonts
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AsUninst.exe" = Anvil Studio
"Audacity_is1" = Audacity 1.2.6
"AviSynth" = AviSynth 2.5
"Backyard Baseball 2003" = Backyard Baseball 2003
"Backyard Basketball" = Backyard Basketball
"Backyard Football" = Backyard Football
"Backyard Soccer MLS Edition" = Backyard Soccer MLS Edition
"Barbieโ„ข Beach Vacationโ„ข" = Barbie Beach Vacation
"BitrateView" = BitrateView
"BlackBerry_{86B32074-0F48-4CF9-BA4B-529B470FB47F}" = BlackBerry Desktop Software 5.0
"blueprint ObjectEditor_is1" = blueprint ObjectEditor 1.0.0
"CEP - Colour Enable Packages_is1" = CEP - Color Enable Package
"CNXT_MODEM_PCI_HSF" = Soft Data Fax Modem with SmartCP
"CodecInstaller" = CodecInstaller 2.10.1
"Color Correction Wizard_is1" = Color Correction Wizard 1.1
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Digital Ear4" = Digital Ear
"DivX Setup.divx.com" = DivX Setup
"D-Link VGA Webcam" = D-Link VGA Webcam
"Download Manager" = Download Manager 2.3.9
"DragonUnPACKer5_is1" = Dragon UnPACKer 5
"DScaler 4.1.15_is1" = DScaler 4.1.15
"Duplicate Music Files Finder_is1" = Duplicate Music Files Finder 1.5.5
"DVD Shrink_is1" = DVD Shrink 3.2
"easyMule" = easyMule
"Elecard MPEG-2 PlugIn for WMP 4.1.100318" = Elecard MPEG-2 PlugIn for WMP
"Emicsoft HD Video Converter_is1" = Emicsoft HD Video Converter
"eMule" = eMule
"ESET Online Scanner" = ESET Online Scanner v3
"FAR Edit Version 1.0_is1" = FAR Edit Version 1.0
"ffdshow_is1" = ffdshow [rev 2975] [2009-05-28]
"FileZilla Client" = FileZilla Client [removed]
"FLAC" = FLAC 1.2.1b (remove only)
"FLV to AVI MPEG WMV 3GP MP4 iPod Converter_is1" = FLV to AVI MPEG WMV 3GP MP4 iPod Converter 5.2.0603
"FLVCodec" = PlayFLV
"Game Extractor" = Game Extractor 2.0
"Google Earth Pro 4.2" = Google Earth Pro 4.2
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Gtk+ Runtime Environment" = Gtk+ Runtime Environment 2.12.9-2
"ImgBurn" = ImgBurn
"ImTOO iPod Manager" = ImTOO iPod Computer Transfer
"InstallShield_{B2AB8AF6-AE06-438F-A3D5-C9FBFBDB0AC0}" = Backyard Basketball 2004
"InstallShield_{BEE7766E-C99F-4735-A42B-77924324F253}" = Backyard Soccer 2004
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"IsoBuster_is1" = IsoBuster 2.8
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.0.0 (Full)
"Magic Video Converter_is1" = Magic Video Converter 8.7.10.189
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Anti-Spyware Enterprise Module" = McAfee AntiSpyware Enterprise Module
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"MediaPortal" = MediaPortal
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MixMeister BPM Analyzer_is1" = MixMeister BPM Analyzer 1.0
"Mozilla Firefox (3.5.15)" = Mozilla Firefox (3.5.15)
"MusicBrainz Picard" = MusicBrainz Picard
"Musicnotes Player_is1" = Musicnotes Player V1.23.2
"Netscape Navigator ([removed])" = Netscape Navigator ([removed])
"Network Play System (Patching)" = Network Play System (Patching)
"Neuratron AudioScore Lite" = Neuratron AudioScore Lite
"Neuratron AudioScore Ultimate Demo" = Neuratron AudioScore Ultimate Demo
"Neuratron PhotoScore Lite" = Neuratron PhotoScore Lite
"Neuratron PhotoScore Ultimate" = Neuratron PhotoScore Ultimate
"Neuratron PhotoScore Ultimate Demo" = Neuratron PhotoScore Ultimate Demo
"Nick-O-Matic Design Factory 1.0" = Nick-O-Matic Design Factory
"NirSoft ShellExView" = NirSoft ShellExView
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"nzb" = nzb
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Ogg Codecs" = Ogg Codecs 0.81.15562
"oggcodecs" = oggcodecs 0.71.0946
"OpenSSL_is1" = OpenSSL 0.9.6m
"Orb" = Orb
"pdfsam" = pdfsam
"plist Editor for Windows" = plist Editor for Windows 1.0.2
"PowerISO" = PowerISO
"ProxySwitcher Standard_is1" = ProxySwitcher Standard
"PSP Video 9" = PSP Video 9 5.03
"PTS Box and Whisker Charter_is1" = PTS Box and Whisker Charter 1.03
"RADVideo" = RAD Video Tools
"RaySource" = RaySource 2.1.10.8366
"RealAlt_is1" = Real Alternative 1.9.0
"RealPlayer 12.0" = RealPlayer
"Replay Media Catcher 3.02" = Replay Media Catcher 3.02
"ShadowExplorer_is1" = ShadowExplorer 0.4
"Sibelius 6_is1" = Sibelius [removed]
"Sibelius Sounds Essentials" = Sibelius Sounds Essentials
"SimPE_is1" = SimPE 0.68 (alpha)
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer
"StepMania" = StepMania (remove only)
"SystemRequirementsLab" = System Requirements Lab
"Tau Producer" = Tau Producer (remove only)
"TiLP2_is1" = TiLP2 1.14
"TreeSize Free_is1" = TreeSize Free V2.4
"True Audio DirectShow Codecs Suite" = True Audio DirectShow Codecs Suite (remove only)
"TuneUpMedia" = TuneUp Companion 1.9.0
"Tunnelier" = Bitvise Tunnelier 4.35 (remove only)
"Unlocker" = Unlocker 1.9.0
"vghd" = VirtuaGuy HD
"Videora iPod touch Converter" = Videora iPod touch Converter 5.04
"VLC media player" = VLC media player 1.1.2
"VMware_Workstation" = VMware Workstation
"Who Wants To Be A Millionaire Kids Edition" = Who Wants To Be A Millionaire Kids Edition
"Willowrd.exe" = Willow Road Screen Art
"WinFF_is1" = WinFF 1.2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.0.2
"Wondershare HD Video Converter_is1" = Wondershare HD Video Converter(Build [removed])
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"XnView_is1" = XnView 1.95.4
"Xvid_is1" = Xvid 1.2.1 final uninstall
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"aaa" = aaa
"Advanced Archive Password Recovery" = Advanced Archive Password Recovery
"BitTorrent" = BitTorrent
"f031ef6ac137efc5" = Dell Driver Download Manager
"intelliScore Polyphonic WAV to MIDI Converter Demo" = intelliScore Polyphonic WAV to MIDI Converter Demo
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"uTorrent" = ยตTorrent
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.7.1

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
I see that you have AVP tool on your system - does that run ? Have you tried it from safe mode

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810
    O2 - BHO: (no name) - {140BD8E3-C167-11D4-B4A3-080000180323} - No CLSID value found.
    O4 - HKCU..\Run: [facgupox] File not found
    O4 - HKCU..\Run: [klboleds] File not found
    [2008/06/14 03:32:52 | 000,136,192 | โ€”- | C] ()(C:\Windows\System32\us?rinit.exe) โ€“ C:\Windows\System32\usะตrinit.exe
    [2008/01/19 02:33:33 | 000,136,192 | โ€”- | M] ()(C:\Windows\System32\us?rinit.exe) โ€“ C:\Windows\System32\usะตrinit.exe


    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download Combofix from any of the links below. You must rename it before saving rename it to Gotcha before saving it to your desktop.

Link 1
Link 2


==================================
[external image: Posted Image]

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
I sincerely apologize for the late reply, I was away from my computer longer than I had expected. I followed your instructions for OTL. Everything went smooth on that end. However, Combofix failed to load. I saved it as "Gotcha" as your instructions implied, and double clicked. A progress bar appeared and got about 98% full, but then my computer completely froze. I left it for about a half hour, thinking it might eventually continue. It didn't, and I was forced to reboot my computer. Yes, I have run AVP, it detected a few malicious files, mostly Java exploits. Here is the log from OTL.

OTL logfile created on: 2/12/2011 3:30:36 PM - Run 2
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 64.22 Gb Free Space | 14.09% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32

Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
PRC - [2011/01/19 16:05:57 | 000,910,296 | โ€”- | M] (Mozilla Corporation) โ€“ C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | โ€”- | M] (PowerISO Computing, Inc.) โ€“ C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2010/03/29 19:26:00 | 000,227,712 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/01/18 13:33:03 | 000,198,160 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/01/06 19:07:00 | 000,147,472 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
PRC - [2010/01/06 19:07:00 | 000,124,240 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
PRC - [2010/01/06 19:07:00 | 000,070,728 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Windows\System32\mfevtps.exe
PRC - [2010/01/06 19:07:00 | 000,066,896 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
PRC - [2010/01/06 19:07:00 | 000,027,960 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mfeann.exe
PRC - [2010/01/06 19:07:00 | 000,022,816 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe
PRC - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnat.exe
PRC - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2009/10/01 13:55:56 | 000,330,256 | โ€”- | M] (Kaspersky Lab) โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\setup_9.0.0.722_09.02.2011_20-07.exe
PRC - [2008/12/30 12:45:08 | 004,993,024 | โ€”- | M] (FS2YOU) โ€“ C:\Program Files\GridService\peer.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\explorer.exe
PRC - [2008/03/14 03:00:00 | 000,226,624 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2008/03/14 03:00:00 | 000,136,512 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2008/03/14 03:00:00 | 000,103,744 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2008/03/14 03:00:00 | 000,091,456 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe


========== Modules (SafeList) ==========

MOD - [2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
MOD - [2010/07/04 16:32:36 | 000,004,608 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/01/19 02:26:34 | 001,684,480 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] โ€“ โ€“ (userinit)
SRV - File not found [On_Demand | Stopped] โ€“ โ€“ (Q)
SRV - File not found [Auto | Stopped] โ€“ โ€“ (Katchall Service)
SRV - File not found [On_Demand | Stopped] โ€“ โ€“ (AZVX)
SRV - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe โ€“ (Apple Mobile Device)
SRV - [2010/03/25 09:25:22 | 030,969,208 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Program Files\Microsoft Office\Office14\GROOVE.EXE โ€“ (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/03/18 12:16:28 | 000,753,504 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe โ€“ (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | โ€”- | M] (Microsoft Corporation) [Auto | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe โ€“ (clr_optimization_v4.0.30319_32)
SRV - [2010/01/06 19:07:00 | 000,147,472 | โ€”- | M] (McAfee, Inc.) [Auto | Paused] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe โ€“ (McShield)
SRV - [2010/01/06 19:07:00 | 000,070,728 | โ€”- | M] (McAfee, Inc.) [Unknown | Running] โ€“ C:\Windows\System32\mfevtps.exe โ€“ (mfevtp)
SRV - [2010/01/06 19:07:00 | 000,066,896 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe โ€“ (McTaskManager)
SRV - [2010/01/06 19:07:00 | 000,022,816 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\VirusScan Enterprise\engineserver.exe โ€“ (McAfeeEngineService)
SRV - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnat.exe โ€“ (VMware NAT Service)
SRV - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe โ€“ (VMAuthdService)
SRV - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnetdhcp.exe โ€“ (VMnetDHCP)
SRV - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe โ€“ (VMUSBArbService)
SRV - [2009/10/12 14:32:24 | 000,191,024 | โ€”- | M] (VMware, Inc.) [On_Demand | Stopped] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe โ€“ (ufad-ws60)
SRV - [2009/07/14 08:22:46 | 000,180,224 | โ€”- | M] () [On_Demand | Stopped] โ€“ C:\Program Files\RipTiger\ElevatorService.exe โ€“ (ElevatorService)
SRV - [2009/01/26 14:31:10 | 001,153,368 | โ€”- | M] (Safer Networking Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe โ€“ (SBSDWSCService)
SRV - [2008/06/25 08:54:10 | 000,654,848 | โ€”- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe โ€“ (FLEXnet Licensing Service)
SRV - [2008/03/14 03:00:00 | 000,103,744 | โ€”- | M] (McAfee, Inc.) [Auto | Running] โ€“ C:\Program Files\McAfee\Common Framework\FrameworkService.exe โ€“ (McAfeeFramework)
SRV - [2008/01/19 02:38:24 | 000,272,952 | โ€”- | M] (Microsoft Corporation) [Auto | Stopped] โ€“ C:\Program Files\Windows Defender\MpSvc.dll โ€“ (WinDefend)
SRV - [2007/11/14 20:46:00 | 000,131,072 | โ€”- | M] (Brio) [Disabled | Stopped] โ€“ C:\Program Files\FolderSize\FolderSizeSvc.exe โ€“ (FolderSize)
SRV - [2007/11/06 15:22:26 | 000,092,792 | โ€”- | M] (CACE Technologies) [On_Demand | Stopped] โ€“ C:\Program Files\WinPcap\rpcapd.exe โ€“ (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe โ€“ (vmount2)


========== Driver Services (SafeList) ==========

DRV - [2011/02/09 15:18:23 | 000,007,168 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\utqyntkz.sys โ€“ (utqyntkz)
DRV - [2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\rk_remover.sys โ€“ (rk_remover-boot)
DRV - [2010/07/10 04:37:00 | 011,008,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\nvlddmkm.sys โ€“ (nvlddmkm)
DRV - [2010/06/18 12:21:34 | 000,691,696 | โ€”- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\System32\Drivers\sptd.sys โ€“ (sptd)
DRV - [2010/04/12 03:44:34 | 000,059,388 | โ€”- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\scdemu.sys โ€“ (SCDEmu)
DRV - [2010/04/08 20:46:06 | 000,007,168 | โ€”- | M] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\dhahelper.sys โ€“ (DhaHelper)
DRV - [2010/01/21 00:59:58 | 000,020,864 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbdiag.sys โ€“ (UsbDiag)
DRV - [2010/01/21 00:59:56 | 000,024,960 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbmodem.sys โ€“ (USBModem)
DRV - [2010/01/21 00:59:56 | 000,013,056 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbbus.sys โ€“ (usbbus)
DRV - [2010/01/06 19:07:00 | 000,343,920 | โ€”- | M] (McAfee, Inc.) [Kernel | Boot | Running] โ€“ C:\Windows\system32\drivers\mfehidk.sys โ€“ (mfehidk)
DRV - [2010/01/06 19:07:00 | 000,091,832 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\mfeavfk.sys โ€“ (mfeavfk)
DRV - [2010/01/06 19:07:00 | 000,075,704 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mfeapfk.sys โ€“ (mfeapfk)
DRV - [2010/01/06 19:07:00 | 000,066,600 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mferkdet.sys โ€“ (mferkdet)
DRV - [2010/01/06 19:07:00 | 000,064,208 | โ€”- | M] (McAfee, Inc.) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\mfetdik.sys โ€“ (mfetdik)
DRV - [2010/01/06 19:07:00 | 000,043,288 | โ€”- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\mfebopk.sys โ€“ (mfebopk)
DRV - [2009/10/22 12:54:18 | 000,037,392 | โ€”- | M] (Kaspersky Lab) [Kernel | Boot | Running] โ€“ C:\Windows\system32\DRIVERS\35858692.sys โ€“ (35858692)
DRV - [2009/10/22 05:00:46 | 000,853,936 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmx86.sys โ€“ (vmx86)
DRV - [2009/10/22 05:00:44 | 000,070,704 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmci.sys โ€“ (vmci)
DRV - [2009/10/22 05:00:44 | 000,026,288 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetuserif.sys โ€“ (VMnetuserif)
DRV - [2009/10/22 05:00:44 | 000,023,216 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\VMkbd.sys โ€“ (vmkbd)
DRV - [2009/10/22 04:59:48 | 000,014,896 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmparport.sys โ€“ (VMparport)
DRV - [2009/10/22 03:47:52 | 000,032,304 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\hcmon.sys โ€“ (hcmon)
DRV - [2009/10/22 00:13:36 | 000,031,280 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\vmusb.sys โ€“ (vmusb)
DRV - [2009/10/22 00:13:32 | 000,036,400 | Rโ€” | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetbridge.sys โ€“ (VMnetBridge)
DRV - [2009/10/22 00:13:32 | 000,016,560 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\vmnetadapter.sys โ€“ (VMnetAdapter)
DRV - [2009/10/12 14:31:52 | 000,022,448 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys โ€“ (vstor2-ws60)
DRV - [2009/10/09 22:31:02 | 000,311,312 | โ€”- | M] (Kaspersky Lab) [File_System | System | Running] โ€“ C:\Windows\System32\drivers\3585869.sys โ€“ (setup_9.0.0.722_09.02.2011_20-07drv)
DRV - [2009/09/25 16:59:42 | 000,128,016 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\35858691.sys โ€“ (35858691)
DRV - [2009/07/07 18:53:02 | 000,028,160 | โ€”- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\libusb0.sys โ€“ (libusb0)
DRV - [2009/02/02 06:56:14 | 000,165,248 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerTun.sys โ€“ (AVMNgTunM780)
DRV - [2009/02/02 06:56:12 | 000,366,976 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerCap.sys โ€“ (AVMNgCapM780)
DRV - [2009/02/02 06:56:10 | 000,057,216 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerBas.sys โ€“ (AVMNgBasM780)
DRV - [2008/07/21 18:34:36 | 000,121,872 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\kl1.sys โ€“ (kl1)
DRV - [2008/01/19 02:43:40 | 000,309,664 | โ€”- | M] () [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\lmqseyg.sys โ€“ (lmqseyg)
DRV - [2008/01/19 02:42:51 | 000,235,064 | โ€”- | M] (Intel Corporation) [Kernel | Boot | Running] โ€“ C:\Windows\system32\drivers\iastorv.sys โ€“ (iaStorV)
DRV - [2008/01/19 00:53:23 | 000,073,088 | โ€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\USBAUDIO.sys โ€“ (usbaudio) USB Audio Driver (WDM)
DRV - [2007/11/06 15:22:06 | 000,034,064 | โ€”- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\npf.sys โ€“ (NPF)
DRV - [2007/06/29 08:11:02 | 000,008,704 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\XAudio.sys โ€“ (XAudio)
DRV - [2007/06/20 02:29:56 | 000,984,064 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_DPV.sys โ€“ (HSF_DPV)
DRV - [2007/06/20 02:28:38 | 000,267,264 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSXHWBS2.sys โ€“ (HSXHWBS2)
DRV - [2007/06/20 02:28:22 | 000,660,480 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_CNXT.sys โ€“ (winachsf)
DRV - [2007/03/23 11:03:00 | 000,018,480 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys โ€“ (vstor2)
DRV - [2006/11/02 04:51:45 | 000,900,712 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql2300.sys โ€“ (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adp94xx.sys โ€“ (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | โ€”- | M] (Emulex) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\elxstor.sys โ€“ (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpahci.sys โ€“ (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | โ€”- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\uliahci.sys โ€“ (uliahci)
DRV - [2006/11/02 04:51:00 | 000,147,048 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu320.sys โ€“ (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata2.sys โ€“ (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | โ€”- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\vsmraid.sys โ€“ (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql40xx.sys โ€“ (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata.sys โ€“ (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu160m.sys โ€“ (adpu160m)
DRV - [2006/11/02 04:50:24 | 000,088,680 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvraid.sys โ€“ (nvraid)
DRV - [2006/11/02 04:50:19 | 000,045,160 | โ€”- | M] (IBM Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nfrd960.sys โ€“ (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | โ€”- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iirsp.sys โ€“ (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | โ€”- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid4.sys โ€“ (SiSRaid4)
DRV - [2006/11/02 04:50:13 | 000,040,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvstor.sys โ€“ (nvstor)
DRV - [2006/11/02 04:50:11 | 000,071,272 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\djsvs.sys โ€“ (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arcsas.sys โ€“ (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_scsi.sys โ€“ (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | โ€”- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid2.sys โ€“ (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | โ€”- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\hpcisss.sys โ€“ (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arc.sys โ€“ (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteraid.sys โ€“ (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteatapi.sys โ€“ (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_sas.sys โ€“ (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\symc8xx.sys โ€“ (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_fc.sys โ€“ (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_u3.sys โ€“ (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\mraid35x.sys โ€“ (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_hi.sys โ€“ (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\megasas.sys โ€“ (megasas)
DRV - [2006/11/02 04:49:30 | 000,017,512 | โ€”- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\viaide.sys โ€“ (viaide)
DRV - [2006/11/02 04:49:28 | 000,016,488 | โ€”- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\cmdide.sys โ€“ (cmdide)
DRV - [2006/11/02 04:49:20 | 000,014,952 | โ€”- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\aliide.sys โ€“ (aliide)
DRV - [2006/11/02 03:25:24 | 000,071,808 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserid.sys โ€“ (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | โ€”- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brusbser.sys โ€“ (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltup.sys โ€“ (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltlo.sys โ€“ (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserwdm.sys โ€“ (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brusbmdm.sys โ€“ (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | โ€”- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ntrigdigi.sys โ€“ (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,117,760 | โ€”- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\E1G60I32.sys โ€“ (E1G60) Intelยฎ
DRV - [2006/11/02 02:30:53 | 000,464,384 | โ€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\BCMWL6.SYS โ€“ (BCM43XV)
DRV - [2005/12/18 19:42:12 | 000,008,801 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Program Files\DScaler\DSDrv4.sys โ€“ (DSDrv4)
DRV - [2004/02/04 09:27:56 | 000,049,536 | โ€”- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\tiehdusb.sys โ€“ (TIEHDUSB)
DRV - [2003/10/15 16:52:50 | 000,174,530 | โ€”- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\ov519vid.sys โ€“ (ovt519)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/19 16:06:06 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/19 16:06:07 | 000,000,000 | โ€”D | M]

[2009/12/23 13:37:34 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Extensions
[2011/02/10 17:42:33 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (1-Click YouTube Video Downloader) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\[removed]
[2011/02/10 17:42:33 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 13:33:28 | 000,000,000 | โ€”D | M] (RealPlayer Browser Record Plugin) โ€“ C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/01/06 19:07:00 | 000,023,864 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\Mozilla Firefox\components\Scriptff.dll

O1 HOSTS File: ([2011/02/12 15:23:31 | 000,000,098 | โ€”- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IE2EMBHO Class) - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll (VeryCD.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Grid Service] C:\Program Files\GridService\peer.exe (FS2YOU)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk = C:\Users\Buddy\Desktop\Virus Removal Tool\setup_9.0.0.722_09.02.2011_20-07\startup.exe ()
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe (Smith Micro, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with &ZipScan; - C:\Program Files\ZipScan Evaluation\zs_ie.htm ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: adobe.com ([www] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O24 - Desktop BackupWallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | โ€”- | M] () - C:\autoexec.bat โ€“ [ NTFS ]
O33 - MountPoints2\{47119b37-d2c9-11de-8e41-005056c00008}\Shell\AutoRun\command - "" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe
O33 - MountPoints2\{632b21b5-5ce4-11df-9256-005056c00008}\Shell\AutoRun\command - "" = O:\PMBP_Win.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\amplayer.exe autorun.dat
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKCU\โ€ฆcom [@ = comfile] โ€“ Reg Error: Key error. File not found
O37 - HKCU\โ€ฆexe [@ = exefile] โ€“ Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/02/12 15:30:18 | 000,602,624 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/12 15:19:14 | 000,000,000 | โ€”D | C] โ€“ C:\_OTL
[2011/02/12 14:50:18 | 000,000,000 | Rโ€“D | C] โ€“ C:\32788R22FWJFW
[2011/02/12 14:16:41 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\ERDNT
[2011/02/12 14:16:34 | 000,000,000 | โ€“SD | C] โ€“ C:\Gotcha
[2011/02/12 14:14:50 | 000,000,000 | โ€”D | C] โ€“ C:\Qoobox
[2011/02/10 17:41:22 | 001,366,104 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/09 14:00:11 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Kaspersky Lab
[2011/02/09 13:58:11 | 000,311,312 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\3585869.sys
[2011/02/09 13:58:11 | 000,128,016 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35858691.sys
[2011/02/09 13:58:11 | 000,037,392 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35858692.sys
[2011/02/09 13:58:10 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool
[2011/02/09 13:56:27 | 091,126,696 | โ€”- | C] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 13:46:22 | 001,360,472 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | C] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:53:06 | 000,056,400 | โ€”- | C] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 16:02:39 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\ESET
[2011/02/04 16:18:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\R&R; Playlist

========== Files - Modified Within 30 Days ==========

[2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/12 15:28:02 | 000,084,013 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.dat
[2011/02/12 15:28:02 | 000,084,013 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.001
[2011/02/12 15:27:35 | 000,000,882 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/12 15:26:47 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/12 15:26:46 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/12 15:26:38 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2011/02/12 15:23:31 | 000,000,098 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\etc\Hosts
[2011/02/12 15:10:38 | 000,001,905 | โ€”- | M] () โ€“ C:\Windows\diagwrn.xml
[2011/02/12 15:10:38 | 000,001,905 | โ€”- | M] () โ€“ C:\Windows\diagerr.xml
[2011/02/12 14:43:01 | 000,000,886 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/12 14:09:13 | 000,000,418 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job
[2011/02/11 15:14:21 | 284,916,510 | โ€”- | M] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/11 14:58:02 | 000,000,000 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 18:05:16 | 000,000,680 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2011/02/10 16:49:55 | 014,710,331 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/10 04:08:00 | 001,366,104 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/09 15:18:23 | 000,007,168 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:07:31 | 000,002,478 | โ€”- | M] () โ€“ C:\Windows\hegames.ini
[2011/02/09 14:00:09 | 000,002,153 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:57:53 | 091,126,696 | โ€”- | M] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/09 12:46:26 | 000,056,400 | โ€”- | M] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:50:20 | 000,609,852 | โ€”- | M] () โ€“ C:\Windows\System32\perfh009.dat
[2011/02/08 16:50:20 | 000,106,018 | โ€”- | M] () โ€“ C:\Windows\System32\perfc009.dat
[2011/02/08 16:27:31 | 162,309,026 | โ€”- | M] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:26 | 000,000,020 | โ€”- | M] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | M] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:44:05 | 000,000,758 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 16:46:50 | 001,824,872 | โ€”- | M] () โ€“ C:\Windows\System32\FNTCACHE.DAT
[2011/02/06 16:28:22 | 000,000,930 | โ€”- | M] () โ€“ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/02 19:04:49 | 000,013,043 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/02/02 18:54:32 | 000,723,956 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/02/01 10:36:10 | 001,360,472 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/01/16 13:38:04 | 000,013,259 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\PRICE LIST.docx
[2011/01/16 13:19:07 | 000,020,480 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:35 | 000,092,863 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/16 12:47:24 | 000,001,097 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk

========== Files Created - No Company Name ==========

[2011/02/11 14:58:02 | 000,000,000 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/09 15:18:18 | 000,007,168 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 14:00:09 | 000,002,153 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_09.02.2011_20-07.lnk
[2011/02/09 13:07:46 | 284,916,510 | โ€”- | C] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/08 16:11:53 | 162,309,026 | โ€”- | C] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:09 | 000,000,020 | โ€”- | C] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | C] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:43:38 | 000,000,758 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 17:04:36 | 018,300,670 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\02 Kind Lady-2008- Extended Mix-.mp3
[2011/02/06 17:04:36 | 014,710,331 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/06 17:04:36 | 011,506,751 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\04 Saturday Night Love -Phunk Disco Mix-.mp3
[2011/02/02 19:04:48 | 000,013,043 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/01/25 16:59:09 | 000,723,956 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/01/16 13:19:10 | 000,020,480 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:33 | 000,092,863 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/09 18:10:21 | 000,000,064 | โ€“S- | C] () โ€“ C:\Windows\ttyxa.sys
[2010/09/19 13:17:41 | 000,087,552 | โ€”- | C] () โ€“ C:\Windows\System32\cpwmon2k.dll
[2010/09/15 14:40:39 | 000,000,005 | โ€”- | C] () โ€“ C:\Windows\treeskp.sys
[2010/08/30 16:46:35 | 000,084,013 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.001
[2010/08/30 16:35:20 | 000,084,013 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.dat
[2010/08/29 17:49:26 | 000,002,640 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\9F5CC62F-036C-4906-A900-0D8AE1702BBC.txt
[2010/07/12 13:22:56 | 000,000,019 | โ€”- | C] () โ€“ C:\Windows\System32\Apache.ini
[2010/05/24 14:33:00 | 004,670,829 | โ€”- | C] () โ€“ C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | โ€”- | C] () โ€“ C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | โ€”- | C] () โ€“ C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,810,113 | โ€”- | C] () โ€“ C:\Windows\System32\xvidcore.dll
[2010/05/24 14:33:00 | 000,336,384 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | โ€”- | C] () โ€“ C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | โ€”- | C] () โ€“ C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | โ€”- | C] () โ€“ C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | โ€”- | C] () โ€“ C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | โ€”- | C] () โ€“ C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | โ€”- | C] () โ€“ C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | โ€”- | C] () โ€“ C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | โ€”- | C] () โ€“ C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | โ€”- | C] () โ€“ C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | โ€”- | C] () โ€“ C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | โ€”- | C] () โ€“ C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | โ€”- | C] () โ€“ C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | โ€”- | C] () โ€“ C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | โ€”- | C] () โ€“ C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | โ€”- | C] () โ€“ C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | โ€”- | C] () โ€“ C:\Windows\System32\mkunicode.dll
[2010/03/21 13:58:38 | 000,002,202 | -HS- | C] () โ€“ C:\ProgramData\VH56DJI7u87yo
[2010/02/21 13:19:42 | 000,000,107 | โ€”- | C] () โ€“ C:\Windows\VobEdit.INI
[2009/07/31 11:51:02 | 000,237,568 | โ€”- | C] () โ€“ C:\Windows\System32\rmc_rtspdl.dll
[2009/07/10 13:34:59 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\libssl32.dll
[2009/07/08 16:25:22 | 000,000,092 | โ€”- | C] () โ€“ C:\Windows\ka.ini
[2009/07/04 16:49:09 | 000,001,374 | โ€”- | C] () โ€“ C:\Windows\disney.ini
[2009/06/17 12:11:55 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DirSize.dll
[2009/06/07 11:24:04 | 000,180,224 | โ€”- | C] () โ€“ C:\Windows\System32\xvidvfw.dll
[2009/04/06 13:35:27 | 000,000,038 | โ€”- | C] () โ€“ C:\Windows\avisplitter.INI
[2009/03/16 14:43:31 | 000,001,222 | โ€”- | C] () โ€“ C:\Windows\AZPR3.INI
[2009/01/30 20:08:03 | 000,002,478 | โ€”- | C] () โ€“ C:\Windows\hegames.ini
[2009/01/29 17:29:25 | 000,004,767 | โ€”- | C] () โ€“ C:\Windows\Irremote.ini
[2009/01/10 17:15:44 | 000,159,744 | โ€”- | C] () โ€“ C:\Windows\System32\mmfinfo.dll
[2008/11/08 11:01:58 | 000,000,000 | โ€”- | C] () โ€“ C:\Windows\Transmogrifier.INI
[2008/11/06 10:37:32 | 003,596,288 | โ€”- | C] () โ€“ C:\Windows\System32\qt-dx331.dll
[2008/10/12 16:52:32 | 000,000,680 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2008/08/17 15:48:14 | 000,000,032 | โ€”- | C] () โ€“ C:\Windows\CD_Start.INI
[2008/08/05 16:18:13 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DGRip.dll
[2008/08/05 16:18:08 | 000,053,248 | โ€”- | C] () โ€“ C:\Windows\System32\imslevel.dll
[2008/07/24 14:07:11 | 000,000,376 | โ€”- | C] () โ€“ C:\Windows\ODBC.INI
[2008/07/23 12:16:53 | 000,000,258 | RHS- | C] () โ€“ C:\ProgramData\ntuser.pol
[2008/06/25 10:05:43 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\nvRegDev.dll
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\ProgramData\T2
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\Program Files\STLL Notifier
[2008/06/17 07:38:16 | 000,164,352 | โ€”- | C] () โ€“ C:\Windows\System32\unrar.dll
[2008/06/14 03:34:18 | 000,309,664 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\lmqseyg.sys
[2008/06/14 03:32:52 | 000,735,664 | โ€”- | C] () โ€“ C:\Windows\System32\msjehlno.dll
[2007/11/06 15:19:28 | 000,053,299 | โ€”- | C] () โ€“ C:\Windows\System32\pthreadVC.dll
[2007/10/13 04:30:20 | 000,000,137 | โ€”- | C] () โ€“ C:\Windows\System32\Registration.ini
[2007/06/16 21:40:13 | 000,110,592 | โ€”- | C] () โ€“ C:\Windows\System32\imsispd.dll
[2006/11/02 07:35:32 | 000,005,632 | โ€”- | C] () โ€“ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | โ€”- | C] () โ€“ C:\Windows\System32\pacerprf.ini
[2004/03/18 17:40:32 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\ssleay32.dll
[2004/03/18 17:40:24 | 000,667,648 | โ€”- | C] () โ€“ C:\Windows\System32\libeay32.dll
[2003/05/09 17:36:30 | 000,151,744 | โ€”- | C] () โ€“ C:\Windows\System32\ir32.dll
[2002/06/06 01:01:58 | 000,029,696 | โ€”- | C] () โ€“ C:\Windows\System32\asutl8.dll

========== LOP Check ==========

[2010/07/05 13:18:58 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\adma
[2009/02/05 14:26:12 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Amazon
[2009/10/08 17:21:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Anvil Studio
[2008/06/16 12:07:30 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Backyard Baseball 2007
[2009/07/22 16:19:52 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\BitTorrent
[2008/08/10 14:29:48 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Bullzip
[2010/07/06 12:37:20 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\calibre
[2009/05/18 18:42:43 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Computer Aces
[2009/06/19 16:45:57 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\dBpoweramp
[2009/07/10 12:29:53 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\DiskAid
[2010/01/13 16:27:35 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\DVDCreator
[2009/12/10 17:39:10 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\FileZilla
[2009/07/22 15:00:17 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\FlashgetSetup
[2010/01/04 16:09:41 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\GrabPro
[2009/04/16 15:52:32 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ICAClient
[2010/06/18 13:23:21 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ImgBurn
[2010/06/02 15:49:05 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\JAM Software
[2009/01/27 12:36:05 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Leadertech
[2008/06/12 17:29:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\LimeWire
[2010/08/15 15:10:42 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\MPEG Streamclip
[2010/08/08 12:20:03 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\MusicBrainz
[2009/08/29 15:32:31 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Netscape
[2010/11/25 13:51:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Neuratron
[2009/08/09 18:49:55 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Opera
[2010/01/04 16:25:33 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Orbit
[2008/07/24 13:26:53 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\PTS Charts
[2010/01/26 17:40:34 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Red Kawa
[2009/04/16 15:52:27 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Runaware
[2010/09/12 16:57:11 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Smith Micro
[2010/03/20 15:02:07 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Thinstall
[2009/09/14 16:02:26 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Trillian
[2011/02/11 16:45:46 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\TuneUpMedia
[2011/02/06 16:41:52 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\uTorrent
[2009/01/07 18:19:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\ViStart
[2009/01/30 17:10:22 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\VitySoft
[2010/08/11 13:53:01 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\WinFF
[2010/08/24 15:18:25 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\WNR
[2010/01/13 16:40:19 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\Xilisoft Corporation
[2009/02/16 17:18:54 | 000,000,000 | โ€”D | M] โ€“ C:\Users\Buddy\AppData\Roaming\XnView
[2011/02/12 15:25:48 | 000,032,526 | โ€”- | M] () โ€“ C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/12 14:09:13 | 000,000,418 | -Hโ€“ | M] () โ€“ C:\Windows\Tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A5682AEF

< End of report >
Excellent as AVP runs I would like you to do a manual analysis for me please

Now an analysis scan

Run AVP
Select the Manual Disinfection tab
Press the Gather System Information button
Once done Open the last report saved folder then attach the zip file to your next post
The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip

[external image: Posted Image]
Found it B)

One or more of the identified infections is a backdoor Trojan and a key logger.

If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.



  • Re-run AVPTool
  • Select the Manual Disinfection tab
  • Where it states Step 3 paste in the following disinfection script and press execute

    begin
    SetAVZPMStatus(True);
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     DeleteService('lmqseyg');
     SetServiceStart('lmqseyg', 4);
     StopService('lmqseyg');
     DeleteService('userinit');
     SetServiceStart('userinit', 4);
     StopService('userinit');
     DeleteService('Q');
     SetServiceStart('Q', 4);
     StopService('Q');
     DeleteService('AZVX');
     SetServiceStart('AZVX', 4);
     StopService('AZVX');
     BC_DeleteFile('C:\Windows\system32\drivers\lmqseyg.sys');
     DeleteFile('C:\Windows\system32\drivers\lmqseyg.sys');
     BC_DeleteFile('C:\Users\Buddy\AppData\Local\Temp\AZVX.exe');
     DeleteFile('C:\Users\Buddy\AppData\Local\Temp\AZVX.exe');
     BC_DeleteFile('C:\Users\Buddy\AppData\Local\Temp\Q.exe');
     DeleteFile('C:\Users\Buddy\AppData\Local\Temp\Q.exe');
    BC_ImportDeletedList;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
  • Your system will reboot on completion, if it does not please do so yourself
  • On completion please run another analysis scan and attach the zip file

[external image: Posted Image]

THEN

Run Combofix (Gotcha)
I executed that script, but I don't think that did it. The invisible iexplore.exe processes are still popping up, as well as google being redirected. I did another analysis with AVP and the zip file is attached. Once again, I just can not get combofix to start. It loads, but this time it crashed to a BSOD that said: DRIVER_IRQL_NOT_LESS_OR_EQUAL Stop: 0x000000D1 (0x00000008, 0x00000002, 0x00000000,0x86547989)
I can't even boot my computer into safe mode. It's giving me a BSOD (ugh!!!). It loads up the drivers, but then crashes. This BSOD is not giving me a specific error message either, so I have no idea what to do to fix that. Here is the OTL log you have requested.

OTL logfile created on: 2/13/2011 1:47:47 PM - Run 3
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Users\Buddy\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 47.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 75.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.93 Gb Total Space | 62.46 Gb Free Space | 13.70% Space Free | Partition Type: NTFS
Drive D: | 9.82 Gb Total Space | 7.63 Gb Free Space | 77.76% Space Free | Partition Type: FAT32

Computer Name: BUDDY-PC | User Name: Buddy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
PRC - [2011/01/19 16:05:57 | 000,910,296 | โ€”- | M] (Mozilla Corporation) โ€“ C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/13 03:47:34 | 003,396,624 | โ€”- | M] (AVAST Software) โ€“ C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/01/13 03:47:33 | 000,040,384 | โ€”- | M] (AVAST Software) โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerAssistant.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/12 03:40:16 | 000,180,224 | โ€”- | M] (PowerISO Computing, Inc.) โ€“ C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2010/03/29 19:26:00 | 000,227,712 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2010/01/18 13:33:03 | 000,198,160 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnat.exe
PRC - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
PRC - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) โ€“ C:\Windows\System32\vmnetdhcp.exe
PRC - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2008/12/30 12:45:08 | 004,993,024 | โ€”- | M] (FS2YOU) โ€“ C:\Program Files\GridService\peer.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\explorer.exe
PRC - [2008/01/19 02:33:35 | 000,217,088 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\WerFault.exe
PRC - [2008/01/19 02:33:35 | 000,056,320 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\wermgr.exe
PRC - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe


========== Modules (SafeList) ==========

MOD - [2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
MOD - [2011/01/13 03:47:35 | 000,189,728 | โ€”- | M] (AVAST Software) โ€“ C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/07/04 16:32:36 | 000,004,608 | โ€”- | M] () โ€“ C:\Program Files\Unlocker\UnlockerHook.dll
MOD - [2008/01/19 02:26:34 | 001,684,480 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] โ€“ โ€“ (userinit)
SRV - File not found [Auto | Stopped] โ€“ โ€“ (Katchall Service)
SRV - [2011/01/13 03:47:33 | 000,040,384 | โ€”- | M] (AVAST Software) [Auto | Running] โ€“ C:\Program Files\Alwil Software\Avast5\AvastSvc.exe โ€“ (avast! Antivirus)
SRV - [2010/06/10 20:03:08 | 000,144,176 | โ€”- | M] (Apple Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe โ€“ (Apple Mobile Device)
SRV - [2010/03/25 09:25:22 | 030,969,208 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Program Files\Microsoft Office\Office14\GROOVE.EXE โ€“ (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/03/18 12:16:28 | 000,753,504 | โ€”- | M] (Microsoft Corporation) [On_Demand | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe โ€“ (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | โ€”- | M] (Microsoft Corporation) [Auto | Stopped] โ€“ C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe โ€“ (clr_optimization_v4.0.30319_32)
SRV - [2009/10/22 05:00:04 | 000,395,824 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnat.exe โ€“ (VMware NAT Service)
SRV - [2009/10/22 04:59:58 | 000,113,200 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-authd.exe โ€“ (VMAuthdService)
SRV - [2009/10/22 04:59:48 | 000,334,384 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Windows\System32\vmnetdhcp.exe โ€“ (VMnetDHCP)
SRV - [2009/10/22 03:47:54 | 000,563,760 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\USB\vmware-usbarbitrator.exe โ€“ (VMUSBArbService)
SRV - [2009/10/12 14:32:24 | 000,191,024 | โ€”- | M] (VMware, Inc.) [On_Demand | Stopped] โ€“ C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe โ€“ (ufad-ws60)
SRV - [2009/07/14 08:22:46 | 000,180,224 | โ€”- | M] () [On_Demand | Stopped] โ€“ C:\Program Files\RipTiger\ElevatorService.exe โ€“ (ElevatorService)
SRV - [2009/01/26 14:31:10 | 001,153,368 | โ€”- | M] (Safer Networking Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe โ€“ (SBSDWSCService)
SRV - [2008/06/25 08:54:10 | 000,654,848 | โ€”- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] โ€“ C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe โ€“ (FLEXnet Licensing Service)
SRV - [2008/01/19 02:38:24 | 000,272,952 | โ€”- | M] (Microsoft Corporation) [Auto | Running] โ€“ C:\Program Files\Windows Defender\MpSvc.dll โ€“ (WinDefend)
SRV - [2007/11/14 20:46:00 | 000,131,072 | โ€”- | M] (Brio) [Disabled | Stopped] โ€“ C:\Program Files\FolderSize\FolderSizeSvc.exe โ€“ (FolderSize)
SRV - [2007/11/06 15:22:26 | 000,092,792 | โ€”- | M] (CACE Technologies) [On_Demand | Stopped] โ€“ C:\Program Files\WinPcap\rpcapd.exe โ€“ (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/03/23 11:02:52 | 000,269,104 | โ€”- | M] (VMware, Inc.) [Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe โ€“ (vmount2)


========== Driver Services (SafeList) ==========

DRV - [2011/02/13 13:20:34 | 000,007,168 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\utqyntkz.sys โ€“ (utqyntkz)
DRV - [2011/02/13 13:15:37 | 000,011,264 | โ€”- | M] () [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\uzqyntkz.sys โ€“ (uzqyntkz)
DRV - [2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\rk_remover.sys โ€“ (rk_remover-boot)
DRV - [2011/01/13 03:41:16 | 000,294,608 | โ€”- | M] (AVAST Software) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\aswSP.sys โ€“ (aswSP)
DRV - [2011/01/13 03:40:16 | 000,047,440 | โ€”- | M] (AVAST Software) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\aswTdi.sys โ€“ (aswTdi)
DRV - [2011/01/13 03:37:30 | 000,023,632 | โ€”- | M] (AVAST Software) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\aswRdr.sys โ€“ (aswRdr)
DRV - [2011/01/13 03:37:19 | 000,051,280 | โ€”- | M] (AVAST Software) [File_System | Auto | Running] โ€“ C:\Windows\System32\drivers\aswMonFlt.sys โ€“ (aswMonFlt)
DRV - [2011/01/13 03:37:09 | 000,017,744 | โ€”- | M] (AVAST Software) [File_System | Auto | Running] โ€“ C:\Windows\System32\drivers\aswFsBlk.sys โ€“ (aswFsBlk)
DRV - [2010/07/10 04:37:00 | 011,008,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\nvlddmkm.sys โ€“ (nvlddmkm)
DRV - [2010/07/09 12:18:56 | 000,020,328 | โ€”- | M] (Windows ยฎ Win 7 DDK provider) [Kernel | On_Demand | Stopped] โ€“ C:\Program Files\CPUID\PC Wizard 2010\pcwiz_x32.sys โ€“ (cpuz134)
DRV - [2010/06/18 12:21:34 | 000,691,696 | โ€”- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\System32\Drivers\sptd.sys โ€“ (sptd)
DRV - [2010/04/12 03:44:34 | 000,059,388 | โ€”- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\scdemu.sys โ€“ (SCDEmu)
DRV - [2010/04/08 20:46:06 | 000,007,168 | โ€”- | M] (MPlayer <http://svn.mplayerhq.hu/mplayer/trunk/vidix/dhahelperwin/>) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\dhahelper.sys โ€“ (DhaHelper)
DRV - [2010/01/21 00:59:58 | 000,020,864 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbdiag.sys โ€“ (UsbDiag)
DRV - [2010/01/21 00:59:56 | 000,024,960 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbmodem.sys โ€“ (USBModem)
DRV - [2010/01/21 00:59:56 | 000,013,056 | โ€”- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\lgusbbus.sys โ€“ (usbbus)
DRV - [2009/10/22 12:54:18 | 000,037,392 | โ€”- | M] (Kaspersky Lab) [Kernel | Boot | Running] โ€“ C:\Windows\system32\DRIVERS\35894002.sys โ€“ (35894002)
DRV - [2009/10/22 05:00:46 | 000,853,936 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmx86.sys โ€“ (vmx86)
DRV - [2009/10/22 05:00:44 | 000,070,704 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmci.sys โ€“ (vmci)
DRV - [2009/10/22 05:00:44 | 000,026,288 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetuserif.sys โ€“ (VMnetuserif)
DRV - [2009/10/22 05:00:44 | 000,023,216 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\VMkbd.sys โ€“ (vmkbd)
DRV - [2009/10/22 04:59:48 | 000,014,896 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmparport.sys โ€“ (VMparport)
DRV - [2009/10/22 03:47:52 | 000,032,304 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\hcmon.sys โ€“ (hcmon)
DRV - [2009/10/22 00:13:36 | 000,031,280 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\vmusb.sys โ€“ (vmusb)
DRV - [2009/10/22 00:13:32 | 000,036,400 | Rโ€” | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\vmnetbridge.sys โ€“ (VMnetBridge)
DRV - [2009/10/22 00:13:32 | 000,016,560 | โ€”- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\vmnetadapter.sys โ€“ (VMnetAdapter)
DRV - [2009/10/12 14:31:52 | 000,022,448 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys โ€“ (vstor2-ws60)
DRV - [2009/10/09 22:31:02 | 000,311,312 | โ€”- | M] (Kaspersky Lab) [File_System | System | Running] โ€“ C:\Windows\System32\drivers\3589400.sys โ€“ (setup_9.0.0.722_13.02.2011_18-16drv)
DRV - [2009/09/25 16:59:42 | 000,128,016 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\35894001.sys โ€“ (35894001)
DRV - [2009/07/07 18:53:02 | 000,028,160 | โ€”- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\libusb0.sys โ€“ (libusb0)
DRV - [2009/02/02 06:56:14 | 000,165,248 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerTun.sys โ€“ (AVMNgTunM780)
DRV - [2009/02/02 06:56:12 | 000,366,976 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerCap.sys โ€“ (AVMNgCapM780)
DRV - [2009/02/02 06:56:10 | 000,057,216 | โ€”- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\AVerBas.sys โ€“ (AVMNgBasM780)
DRV - [2008/07/21 18:34:36 | 000,121,872 | โ€”- | M] (Kaspersky Lab) [Kernel | System | Running] โ€“ C:\Windows\System32\drivers\kl1.sys โ€“ (kl1)
DRV - [2008/01/19 02:42:51 | 000,235,064 | โ€”- | M] (Intel Corporation) [Kernel | Boot | Running] โ€“ C:\Windows\system32\drivers\iastorv.sys โ€“ (iaStorV)
DRV - [2008/01/19 00:53:23 | 000,073,088 | โ€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\USBAUDIO.sys โ€“ (usbaudio) USB Audio Driver (WDM)
DRV - [2007/11/06 15:22:06 | 000,034,064 | โ€”- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\npf.sys โ€“ (NPF)
DRV - [2007/06/29 08:11:02 | 000,008,704 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] โ€“ C:\Windows\System32\drivers\XAudio.sys โ€“ (XAudio)
DRV - [2007/06/20 02:29:56 | 000,984,064 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_DPV.sys โ€“ (HSF_DPV)
DRV - [2007/06/20 02:28:38 | 000,267,264 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSXHWBS2.sys โ€“ (HSXHWBS2)
DRV - [2007/06/20 02:28:22 | 000,660,480 | โ€”- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\HSX_CNXT.sys โ€“ (winachsf)
DRV - [2007/03/23 11:03:00 | 000,018,480 | โ€”- | M] (VMware, Inc.) [Kernel | Auto | Running] โ€“ C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys โ€“ (vstor2)
DRV - [2006/11/02 04:51:45 | 000,900,712 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql2300.sys โ€“ (ql2300)
DRV - [2006/11/02 04:51:38 | 000,420,968 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adp94xx.sys โ€“ (adp94xx)
DRV - [2006/11/02 04:51:34 | 000,316,520 | โ€”- | M] (Emulex) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\elxstor.sys โ€“ (elxstor)
DRV - [2006/11/02 04:51:32 | 000,297,576 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpahci.sys โ€“ (adpahci)
DRV - [2006/11/02 04:51:25 | 000,235,112 | โ€”- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\uliahci.sys โ€“ (uliahci)
DRV - [2006/11/02 04:51:00 | 000,147,048 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu320.sys โ€“ (adpu320)
DRV - [2006/11/02 04:50:45 | 000,115,816 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata2.sys โ€“ (ulsata2)
DRV - [2006/11/02 04:50:41 | 000,112,232 | โ€”- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\vsmraid.sys โ€“ (vsmraid)
DRV - [2006/11/02 04:50:35 | 000,106,088 | โ€”- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ql40xx.sys โ€“ (ql40xx)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ulsata.sys โ€“ (UlSata)
DRV - [2006/11/02 04:50:35 | 000,098,408 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\adpu160m.sys โ€“ (adpu160m)
DRV - [2006/11/02 04:50:24 | 000,088,680 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvraid.sys โ€“ (nvraid)
DRV - [2006/11/02 04:50:19 | 000,045,160 | โ€”- | M] (IBM Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nfrd960.sys โ€“ (nfrd960)
DRV - [2006/11/02 04:50:17 | 000,041,576 | โ€”- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iirsp.sys โ€“ (iirsp)
DRV - [2006/11/02 04:50:16 | 000,071,784 | โ€”- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid4.sys โ€“ (SiSRaid4)
DRV - [2006/11/02 04:50:13 | 000,040,040 | โ€”- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\nvstor.sys โ€“ (nvstor)
DRV - [2006/11/02 04:50:11 | 000,071,272 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\djsvs.sys โ€“ (aic78xx)
DRV - [2006/11/02 04:50:10 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arcsas.sys โ€“ (arcsas)
DRV - [2006/11/02 04:50:10 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_scsi.sys โ€“ (LSI_SCSI)
DRV - [2006/11/02 04:50:10 | 000,038,504 | โ€”- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sisraid2.sys โ€“ (SiSRaid2)
DRV - [2006/11/02 04:50:10 | 000,037,480 | โ€”- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\hpcisss.sys โ€“ (HpCISSs)
DRV - [2006/11/02 04:50:09 | 000,067,688 | โ€”- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\arc.sys โ€“ (arc)
DRV - [2006/11/02 04:50:09 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteraid.sys โ€“ (iteraid)
DRV - [2006/11/02 04:50:07 | 000,035,944 | โ€”- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\iteatapi.sys โ€“ (iteatapi)
DRV - [2006/11/02 04:50:05 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_sas.sys โ€“ (LSI_SAS)
DRV - [2006/11/02 04:50:05 | 000,035,944 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\symc8xx.sys โ€“ (Symc8xx)
DRV - [2006/11/02 04:50:04 | 000,065,640 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\lsi_fc.sys โ€“ (LSI_FC)
DRV - [2006/11/02 04:50:03 | 000,034,920 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_u3.sys โ€“ (Sym_u3)
DRV - [2006/11/02 04:49:59 | 000,033,384 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\mraid35x.sys โ€“ (Mraid35x)
DRV - [2006/11/02 04:49:56 | 000,031,848 | โ€”- | M] (LSI Logic) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\sym_hi.sys โ€“ (Sym_hi)
DRV - [2006/11/02 04:49:53 | 000,028,776 | โ€”- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\megasas.sys โ€“ (megasas)
DRV - [2006/11/02 04:49:30 | 000,017,512 | โ€”- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\viaide.sys โ€“ (viaide)
DRV - [2006/11/02 04:49:28 | 000,016,488 | โ€”- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\cmdide.sys โ€“ (cmdide)
DRV - [2006/11/02 04:49:20 | 000,014,952 | โ€”- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\aliide.sys โ€“ (aliide)
DRV - [2006/11/02 03:25:24 | 000,071,808 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserid.sys โ€“ (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 03:24:47 | 000,011,904 | โ€”- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brusbser.sys โ€“ (BrUsbSer)
DRV - [2006/11/02 03:24:46 | 000,005,248 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltup.sys โ€“ (BrFiltUp)
DRV - [2006/11/02 03:24:45 | 000,013,568 | โ€”- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\system32\drivers\brfiltlo.sys โ€“ (BrFiltLo)
DRV - [2006/11/02 03:24:44 | 000,062,336 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brserwdm.sys โ€“ (BrSerWdm)
DRV - [2006/11/02 03:24:44 | 000,012,160 | โ€”- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\brusbmdm.sys โ€“ (BrUsbMdm)
DRV - [2006/11/02 02:36:50 | 000,020,608 | โ€”- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] โ€“ C:\Windows\system32\drivers\ntrigdigi.sys โ€“ (ntrigdigi)
DRV - [2006/11/02 02:30:54 | 000,117,760 | โ€”- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\E1G60I32.sys โ€“ (E1G60) Intelยฎ
DRV - [2006/11/02 02:30:53 | 000,464,384 | โ€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] โ€“ C:\Windows\System32\drivers\BCMWL6.SYS โ€“ (BCM43XV)
DRV - [2005/12/18 19:42:12 | 000,008,801 | โ€”- | M] () [Kernel | On_Demand | Stopped] โ€“ C:\Program Files\DScaler\DSDrv4.sys โ€“ (DSDrv4)
DRV - [2004/02/04 09:27:56 | 000,049,536 | โ€”- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\tiehdusb.sys โ€“ (TIEHDUSB)
DRV - [2003/10/15 16:52:50 | 000,174,530 | โ€”- | M] (OmniVision Technologies, Inc.) [Kernel | On_Demand | Stopped] โ€“ C:\Windows\System32\drivers\ov519vid.sys โ€“ (ovt519)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.5
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/19 16:06:06 | 000,000,000 | โ€”D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/19 16:06:07 | 000,000,000 | โ€”D | M]

[2009/12/23 13:37:34 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Extensions
[2011/02/12 15:52:56 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (Microsoft .NET Framework Assistant) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/06 14:37:05 | 000,000,000 | โ€”D | M] (1-Click YouTube Video Downloader) โ€“ C:\Users\Buddy\AppData\Roaming\Mozilla\Firefox\Profiles\nplq0xdk.default\extensions\[removed]
[2011/02/12 15:52:56 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
[2010/01/18 13:33:28 | 000,000,000 | โ€”D | M] (RealPlayer Browser Record Plugin) โ€“ C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD\FIREFOX\EXT
[2010/01/06 19:07:00 | 000,023,864 | โ€”- | M] (McAfee, Inc.) โ€“ C:\Program Files\Mozilla Firefox\components\Scriptff.dll

O1 HOSTS File: ([2011/02/12 15:23:31 | 000,000,098 | โ€”- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IE2EMBHO Class) - {0A0DDBD3-6641-40B9-873F-BBDD26D6C14E} - C:\Program Files\easyMule\modules\IE2EM.dll (VeryCD.com)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Grid Service] C:\Program Files\GridService\peer.exe (FS2YOU)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_13.02.2011_18-16.lnk = C:\Users\Buddy\Desktop\Virus Removal Tool1\setup_9.0.0.722_13.02.2011_18-16\startup.exe ()
O4 - Startup: C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\V CAST Media Monitor.lnk = C:\Program Files\V CAST Media Manager\MEMonitor.exe (Smith Micro, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with &ZipScan; - C:\Program Files\ZipScan Evaluation\zs_ie.htm ()
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\..Trusted Domains: adobe.com ([www] http in Trusted sites)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O24 - Desktop BackupWallPaper: C:\Users\Buddy\Pictures\thanksgiving.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | โ€”- | M] () - C:\autoexec.bat โ€“ [ NTFS ]
O33 - MountPoints2\{47119b37-d2c9-11de-8e41-005056c00008}\Shell\AutoRun\command - "" = C:\Program Files\iMesh Applications\iMesh\iMesh.exe
O33 - MountPoints2\{632b21b5-5ce4-11df-9256-005056c00008}\Shell\AutoRun\command - "" = O:\PMBP_Win.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\amplayer.exe autorun.dat
O33 - MountPoints2\M\Shell - "" = AutoRun
O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*
O37 - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\โ€ฆcom [@ = comfile] โ€“ Reg Error: Key error. File not found
O37 - HKU\S-1-5-21-884816068-2633634329-2448390406-1000\โ€ฆexe [@ = exefile] โ€“ Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/02/13 13:24:25 | 000,000,000 | Rโ€“D | C] โ€“ C:\32788R22FWJFW
[2011/02/13 13:15:47 | 000,010,240 | โ€”- | C] (Zaitsev Oleg, 2006) โ€“ C:\Windows\System32\drivers\ujqyntkz.sys
[2011/02/13 13:10:35 | 000,294,608 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswSP.sys
[2011/02/13 13:10:35 | 000,017,744 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswFsBlk.sys
[2011/02/13 13:10:35 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/02/13 13:10:34 | 000,047,440 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswTdi.sys
[2011/02/13 13:10:34 | 000,023,632 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswRdr.sys
[2011/02/13 13:10:33 | 000,051,280 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\drivers\aswMonFlt.sys
[2011/02/13 13:10:20 | 000,038,848 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\avastSS.scr
[2011/02/13 13:10:19 | 000,188,216 | โ€”- | C] (AVAST Software) โ€“ C:\Windows\System32\aswBoot.exe
[2011/02/13 13:04:31 | 000,000,000 | -HSD | C] โ€“ C:\Config.Msi
[2011/02/13 12:31:05 | 000,311,312 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\3589400.sys
[2011/02/13 12:31:05 | 000,128,016 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35894001.sys
[2011/02/13 12:31:05 | 000,037,392 | โ€”- | C] (Kaspersky Lab) โ€“ C:\Windows\System32\drivers\35894002.sys
[2011/02/13 12:31:04 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool1
[2011/02/13 12:28:56 | 091,623,816 | โ€”- | C] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_13.02.2011_18-16.exe
[2011/02/13 00:01:53 | 000,424,448 | โ€”- | C] (imgs) โ€“ C:\ProgramData\AFIGYSUOYrKmtum.dll
[2011/02/12 16:45:29 | 000,114,176 | โ€”- | C] (CPUID) โ€“ C:\Windows\System32\PCWizard.cpl
[2011/02/12 16:45:29 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\Java
[2011/02/12 16:45:29 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2011/02/12 16:45:28 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\CPUID
[2011/02/12 15:30:18 | 000,602,624 | โ€”- | C] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/12 15:19:14 | 000,000,000 | โ€”D | C] โ€“ C:\_OTL
[2011/02/12 14:16:41 | 000,000,000 | โ€”D | C] โ€“ C:\Windows\ERDNT
[2011/02/12 14:16:34 | 000,000,000 | โ€“SD | C] โ€“ C:\Gotcha
[2011/02/12 14:14:50 | 000,000,000 | โ€”D | C] โ€“ C:\Qoobox
[2011/02/10 17:41:22 | 001,366,104 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/09 14:00:11 | 000,000,000 | โ€”D | C] โ€“ C:\ProgramData\Kaspersky Lab
[2011/02/09 13:58:10 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\Virus Removal Tool
[2011/02/09 13:56:27 | 091,126,696 | โ€”- | C] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 13:46:22 | 001,360,472 | โ€”- | C] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | C] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | C] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:53:06 | 000,056,400 | โ€”- | C] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 16:02:39 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\ESET
[2011/02/04 16:18:44 | 000,000,000 | โ€”D | C] โ€“ C:\Users\Buddy\Desktop\R&R; Playlist

========== Files - Modified Within 30 Days ==========

[2011/02/13 13:43:02 | 000,000,886 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/13 13:30:24 | 000,036,917 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.dat
[2011/02/13 13:30:23 | 000,036,917 | โ€”- | M] () โ€“ C:\ProgramData\nvModes.001
[2011/02/13 13:30:02 | 000,000,882 | โ€”- | M] () โ€“ C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/13 13:29:49 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/13 13:29:48 | 000,002,480 | -Hโ€“ | M] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/13 13:29:38 | 000,067,584 | โ€“S- | M] () โ€“ C:\Windows\bootstat.dat
[2011/02/13 13:29:32 | 262,056,734 | โ€”- | M] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/13 13:20:34 | 000,007,168 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/13 13:15:47 | 000,010,240 | โ€”- | M] (Zaitsev Oleg, 2006) โ€“ C:\Windows\System32\drivers\ujqyntkz.sys
[2011/02/13 13:15:37 | 000,011,264 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\uzqyntkz.sys
[2011/02/13 13:10:35 | 000,001,840 | โ€”- | M] () โ€“ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/02/13 13:10:33 | 000,002,577 | โ€”- | M] () โ€“ C:\Windows\System32\config.nt
[2011/02/13 13:09:03 | 058,833,152 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\setup_av_free.exe
[2011/02/13 13:02:24 | 000,025,600 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\Mary Collin1.doc
[2011/02/13 12:54:16 | 000,000,418 | -Hโ€“ | M] () โ€“ C:\Windows\tasks\User_Feed_Synchronization-{E2DCF500-2AE9-4C71-A2E6-0B1861D91A9F}.job
[2011/02/13 12:36:34 | 000,092,193 | โ€”- | M] () โ€“ C:\avz_sysinfo.htm
[2011/02/13 12:32:13 | 000,002,162 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_13.02.2011_18-16.lnk
[2011/02/13 12:30:41 | 091,623,816 | โ€”- | M] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_13.02.2011_18-16.exe
[2011/02/13 12:01:58 | 000,424,448 | โ€”- | M] (imgs) โ€“ C:\ProgramData\AFIGYSUOYrKmtum.dll
[2011/02/13 00:01:43 | 000,000,680 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2011/02/12 16:45:29 | 000,000,901 | โ€”- | M] () โ€“ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Wizard 2010.lnk
[2011/02/12 15:38:24 | 004,263,406 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Gotcha.exe
[2011/02/12 15:30:21 | 000,602,624 | โ€”- | M] (OldTimer Tools) โ€“ C:\Users\Buddy\Desktop\OTL.exe
[2011/02/12 15:23:31 | 000,000,098 | โ€”- | M] () โ€“ C:\Windows\System32\drivers\etc\Hosts
[2011/02/12 15:10:38 | 000,001,905 | โ€”- | M] () โ€“ C:\Windows\diagwrn.xml
[2011/02/12 15:10:38 | 000,001,905 | โ€”- | M] () โ€“ C:\Windows\diagerr.xml
[2011/02/11 14:58:02 | 000,000,000 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/10 16:49:55 | 014,710,331 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/10 04:08:00 | 001,366,104 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\abc12223.com
[2011/02/09 14:07:31 | 000,002,478 | โ€”- | M] () โ€“ C:\Windows\hegames.ini
[2011/02/09 13:57:53 | 091,126,696 | โ€”- | M] ( ) โ€“ C:\Users\Buddy\Desktop\setup_9.0.0.722_09.02.2011_20-07.exe
[2011/02/09 12:46:26 | 000,190,032 | โ€”- | M] (Trend Micro Inc.) โ€“ C:\Windows\System32\drivers\tmcomm.sys
[2011/02/09 12:46:26 | 000,056,400 | โ€”- | M] (trend_company_name) โ€“ C:\Windows\System32\drivers\tmrkb.sys
[2011/02/08 17:14:55 | 000,053,248 | โ€”- | M] (eSage Lab) โ€“ C:\Windows\System32\drivers\rk_remover.sys
[2011/02/08 16:50:20 | 000,609,852 | โ€”- | M] () โ€“ C:\Windows\System32\perfh009.dat
[2011/02/08 16:50:20 | 000,106,018 | โ€”- | M] () โ€“ C:\Windows\System32\perfc009.dat
[2011/02/08 16:27:31 | 162,309,026 | โ€”- | M] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:26 | 000,000,020 | โ€”- | M] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | M] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:44:05 | 000,000,758 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 16:46:50 | 001,824,872 | โ€”- | M] () โ€“ C:\Windows\System32\FNTCACHE.DAT
[2011/02/06 16:28:22 | 000,000,930 | โ€”- | M] () โ€“ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/02/02 19:04:49 | 000,013,043 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/02/02 18:54:32 | 000,723,956 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/02/02 17:11:20 | 000,222,080 | โ€”- | M] (Microsoft Corporation) โ€“ C:\Windows\System32\MpSigStub.exe
[2011/02/01 10:36:10 | 001,360,472 | โ€”- | M] (Kaspersky Lab ZAO) โ€“ C:\Users\Buddy\Desktop\abc123.com
[2011/01/16 13:38:04 | 000,013,259 | โ€”- | M] () โ€“ C:\Users\Buddy\Documents\PRICE LIST.docx
[2011/01/16 13:19:07 | 000,020,480 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:35 | 000,092,863 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | M] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/16 12:47:24 | 000,001,097 | โ€”- | M] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk

========== Files Created - No Company Name ==========

[2011/02/13 13:29:45 | 000,036,917 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.001
[2011/02/13 13:19:10 | 000,036,917 | โ€”- | C] () โ€“ C:\ProgramData\nvModes.dat
[2011/02/13 13:15:37 | 000,011,264 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\uzqyntkz.sys
[2011/02/13 13:10:35 | 000,001,840 | โ€”- | C] () โ€“ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2011/02/13 13:09:00 | 058,833,152 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\setup_av_free.exe
[2011/02/13 13:02:23 | 000,025,600 | โ€”- | C] () โ€“ C:\Users\Buddy\Documents\Mary Collin1.doc
[2011/02/13 12:40:44 | 000,092,193 | โ€”- | C] () โ€“ C:\avz_sysinfo.htm
[2011/02/13 12:32:13 | 000,002,162 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\setup_9.0.0.722_13.02.2011_18-16.lnk
[2011/02/12 16:45:29 | 000,000,901 | โ€”- | C] () โ€“ C:\Users\Buddy\Application Data\Microsoft\Internet Explorer\Quick Launch\PC Wizard 2010.lnk
[2011/02/12 15:38:23 | 004,263,406 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Gotcha.exe
[2011/02/11 14:58:02 | 000,000,000 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\settings.dat
[2011/02/09 15:18:18 | 000,007,168 | โ€”- | C] () โ€“ C:\Windows\System32\drivers\utqyntkz.sys
[2011/02/09 13:07:46 | 262,056,734 | โ€”- | C] () โ€“ C:\Windows\MEMORY.DMP
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/09 11:31:11 | 000,002,480 | -Hโ€“ | C] () โ€“ C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/08 16:11:53 | 162,309,026 | โ€”- | C] () โ€“ C:\Windows\System32\UPPJZ
[2011/02/08 15:58:09 | 000,000,020 | โ€”- | C] () โ€“ C:\Users\Buddy\defogger_reenable
[2011/02/08 00:38:26 | 001,228,854 | โ€”- | C] () โ€“ C:\fsqwr.bmp
[2011/02/07 16:43:38 | 000,000,758 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Kill Java.lnk
[2011/02/06 17:04:36 | 018,300,670 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\02 Kind Lady-2008- Extended Mix-.mp3
[2011/02/06 17:04:36 | 014,710,331 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\06 Look To The Sky -Cyber True Color Extended-.mp3
[2011/02/06 17:04:36 | 011,506,751 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\04 Saturday Night Love -Phunk Disco Mix-.mp3
[2011/02/02 19:04:48 | 000,013,043 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Table of Contents.docx
[2011/01/25 16:59:09 | 000,723,956 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Poetry Collection.docx
[2011/01/16 13:19:10 | 000,020,480 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\JV Softball Schedule.doc
[2011/01/16 13:18:42 | 000,022,528 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\2011%20AHS%20Varsity%20Softball[1].doc
[2011/01/16 13:15:33 | 000,092,863 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\Dear Supporters of AHS Softball.docx
[2011/01/16 12:49:01 | 000,078,296 | โ€”- | C] () โ€“ C:\Users\Buddy\Desktop\logo.jpg
[2011/01/09 18:10:21 | 000,000,064 | โ€“S- | C] () โ€“ C:\Windows\ttyxa.sys
[2010/09/19 13:17:41 | 000,087,552 | โ€”- | C] () โ€“ C:\Windows\System32\cpwmon2k.dll
[2010/09/15 14:40:39 | 000,000,005 | โ€”- | C] () โ€“ C:\Windows\treeskp.sys
[2010/08/29 17:49:26 | 000,002,640 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\9F5CC62F-036C-4906-A900-0D8AE1702BBC.txt
[2010/07/12 13:22:56 | 000,000,019 | โ€”- | C] () โ€“ C:\Windows\System32\Apache.ini
[2010/05/24 14:33:00 | 004,670,829 | โ€”- | C] () โ€“ C:\Windows\System32\libavcodec.dll
[2010/05/24 14:33:00 | 001,529,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_samplerate.dll
[2010/05/24 14:33:00 | 001,447,921 | โ€”- | C] () โ€“ C:\Windows\System32\ffmpegmt.dll
[2010/05/24 14:33:00 | 000,877,385 | โ€”- | C] () โ€“ C:\Windows\System32\ff_x264.dll
[2010/05/24 14:33:00 | 000,810,113 | โ€”- | C] () โ€“ C:\Windows\System32\xvidcore.dll
[2010/05/24 14:33:00 | 000,336,384 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libfaad2.dll
[2010/05/24 14:33:00 | 000,324,096 | โ€”- | C] () โ€“ C:\Windows\System32\TomsMoComp_ff.dll
[2010/05/24 14:33:00 | 000,248,320 | โ€”- | C] () โ€“ C:\Windows\System32\ff_kernelDeint.dll
[2010/05/24 14:33:00 | 000,216,576 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libdts.dll
[2010/05/24 14:33:00 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\ff_libmad.dll
[2010/05/24 14:33:00 | 000,145,408 | โ€”- | C] () โ€“ C:\Windows\System32\libmpeg2_ff.dll
[2010/05/24 14:33:00 | 000,139,944 | โ€”- | C] () โ€“ C:\Windows\System32\libmplayer.dll
[2010/05/24 14:33:00 | 000,121,856 | โ€”- | C] () โ€“ C:\Windows\System32\ff_liba52.dll
[2010/05/24 14:33:00 | 000,116,736 | โ€”- | C] () โ€“ C:\Windows\System32\ff_tremor.dll
[2010/05/24 14:33:00 | 000,108,032 | โ€”- | C] () โ€“ C:\Windows\System32\ff_vfw.dll
[2010/05/24 14:33:00 | 000,100,864 | โ€”- | C] () โ€“ C:\Windows\System32\ff_wmv9.dll
[2010/05/24 14:33:00 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\ff_unrar.dll
[2010/05/19 15:59:20 | 000,150,528 | โ€”- | C] () โ€“ C:\Windows\System32\mkx.dll
[2010/05/19 15:59:10 | 000,109,568 | โ€”- | C] () โ€“ C:\Windows\System32\avi.dll
[2010/05/19 15:59:02 | 000,141,824 | โ€”- | C] () โ€“ C:\Windows\System32\mp4.dll
[2010/05/19 15:58:52 | 000,123,392 | โ€”- | C] () โ€“ C:\Windows\System32\ogm.dll
[2010/05/19 15:58:18 | 000,154,112 | โ€”- | C] () โ€“ C:\Windows\System32\ts.dll
[2010/05/19 15:58:08 | 000,249,856 | โ€”- | C] () โ€“ C:\Windows\System32\dxr.dll
[2010/05/19 15:57:42 | 000,097,792 | โ€”- | C] () โ€“ C:\Windows\System32\avs.dll
[2010/05/19 15:57:26 | 000,093,184 | โ€”- | C] () โ€“ C:\Windows\System32\avss.dll
[2010/05/19 15:55:40 | 000,080,384 | โ€”- | C] () โ€“ C:\Windows\System32\mkzlib.dll
[2010/05/19 15:55:36 | 000,024,576 | โ€”- | C] () โ€“ C:\Windows\System32\mkunicode.dll
[2010/03/21 13:58:38 | 000,002,202 | -HS- | C] () โ€“ C:\ProgramData\VH56DJI7u87yo
[2010/02/21 13:19:42 | 000,000,107 | โ€”- | C] () โ€“ C:\Windows\VobEdit.INI
[2009/07/31 11:51:02 | 000,237,568 | โ€”- | C] () โ€“ C:\Windows\System32\rmc_rtspdl.dll
[2009/07/10 13:34:59 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\libssl32.dll
[2009/07/08 16:25:22 | 000,000,092 | โ€”- | C] () โ€“ C:\Windows\ka.ini
[2009/07/04 16:49:09 | 000,001,374 | โ€”- | C] () โ€“ C:\Windows\disney.ini
[2009/06/17 12:11:55 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DirSize.dll
[2009/06/07 11:24:04 | 000,180,224 | โ€”- | C] () โ€“ C:\Windows\System32\xvidvfw.dll
[2009/04/06 13:35:27 | 000,000,038 | โ€”- | C] () โ€“ C:\Windows\avisplitter.INI
[2009/03/16 14:43:31 | 000,001,222 | โ€”- | C] () โ€“ C:\Windows\AZPR3.INI
[2009/01/30 20:08:03 | 000,002,478 | โ€”- | C] () โ€“ C:\Windows\hegames.ini
[2009/01/29 17:29:25 | 000,004,767 | โ€”- | C] () โ€“ C:\Windows\Irremote.ini
[2009/01/10 17:15:44 | 000,159,744 | โ€”- | C] () โ€“ C:\Windows\System32\mmfinfo.dll
[2008/11/08 11:01:58 | 000,000,000 | โ€”- | C] () โ€“ C:\Windows\Transmogrifier.INI
[2008/11/06 10:37:32 | 003,596,288 | โ€”- | C] () โ€“ C:\Windows\System32\qt-dx331.dll
[2008/10/12 16:52:32 | 000,000,680 | โ€”- | C] () โ€“ C:\Users\Buddy\AppData\Local\d3d9caps.dat
[2008/08/17 15:48:14 | 000,000,032 | โ€”- | C] () โ€“ C:\Windows\CD_Start.INI
[2008/08/05 16:18:13 | 000,036,864 | โ€”- | C] () โ€“ C:\Windows\System32\DGRip.dll
[2008/08/05 16:18:08 | 000,053,248 | โ€”- | C] () โ€“ C:\Windows\System32\imslevel.dll
[2008/07/24 14:07:11 | 000,000,376 | โ€”- | C] () โ€“ C:\Windows\ODBC.INI
[2008/07/23 12:16:53 | 000,000,258 | RHS- | C] () โ€“ C:\ProgramData\ntuser.pol
[2008/06/25 10:05:43 | 000,151,552 | โ€”- | C] () โ€“ C:\Windows\System32\nvRegDev.dll
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\ProgramData\T2
[2008/06/17 09:13:06 | 000,000,604 | -Hโ€“ | C] () โ€“ C:\Program Files\STLL Notifier
[2008/06/17 07:38:16 | 000,164,352 | โ€”- | C] () โ€“ C:\Windows\System32\unrar.dll
[2008/06/14 03:32:52 | 000,735,664 | โ€”- | C] () โ€“ C:\Windows\System32\msjehlno.dll
[2007/11/06 15:19:28 | 000,053,299 | โ€”- | C] () โ€“ C:\Windows\System32\pthreadVC.dll
[2007/10/13 04:30:20 | 000,000,137 | โ€”- | C] () โ€“ C:\Windows\System32\Registration.ini
[2007/06/16 21:40:13 | 000,110,592 | โ€”- | C] () โ€“ C:\Windows\System32\imsispd.dll
[2006/11/02 07:35:32 | 000,005,632 | โ€”- | C] () โ€“ C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:40:29 | 000,013,750 | โ€”- | C] () โ€“ C:\Windows\System32\pacerprf.ini
[2004/03/18 17:40:32 | 000,155,648 | โ€”- | C] () โ€“ C:\Windows\System32\ssleay32.dll
[2004/03/18 17:40:24 | 000,667,648 | โ€”- | C] () โ€“ C:\Windows\System32\libeay32.dll
[2003/05/09 17:36:30 | 000,151,744 | โ€”- | C] () โ€“ C:\Windows\System32\ir32.dll
[2002/06/06 01:01:58 | 000,029,696 | โ€”- | C] () โ€“ C:\Windows\System32\asutl8.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7E95B6FD
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A5682AEF

< End of report >
That revealed some more, looks like we may have to nibble away at this

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Disabled | Stopped] โ€“ โ€“ (userinit)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    [2011/02/13 12:01:58 | 000,424,448 | โ€”- | M] (imgs) โ€“ C:\ProgramData\AFIGYSUOYrKmtum.dll
    [2011/01/09 18:10:21 | 000,000,064 | โ€“S- | C] () โ€“ C:\Windows\ttyxa.sys
    [2010/09/15 14:40:39 | 000,000,005 | โ€”- | C] () โ€“ C:\Windows\treeskp.sys
    [2010/03/21 13:58:38 | 000,002,202 | -HS- | C] () โ€“ C:\ProgramData\VH56DJI7u87yo

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it
[external image: Posted Image]

Click the "Scan" button to start scan
[external image: Posted Image]

Click the "Fix" in case of infection
[external image: Posted Image]

Save the aswMBR.log to the desktop and post in your next reply
[external image: Posted Image]
here are the two logs. Thankfully, both programs ran without problems.
OTL

All processes killed
========== OTL ==========
Service userinit stopped successfully!
Service userinit deleted successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
C:\ProgramData\AFIGYSUOYrKmtum.dll moved successfully.
C:\Windows\ttyxa.sys moved successfully.
C:\Windows\treeskp.sys moved successfully.
C:\ProgramData\VH56DJI7u87yo moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Buddy\Desktop\cmd.bat deleted successfully.
C:\Users\Buddy\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Buddy
->Temp folder emptied: 16284365 bytes
->Temporary Internet Files folder emptied: 17502612 bytes
->Java cache emptied: 5041 bytes
->FireFox cache emptied: 77830746 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 3262 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 19558 bytes
RecycleBin emptied: 101482 bytes

Total Files Cleaned = 107.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Buddy
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb



OTL by OldTimer - Version 3.2.20.6 log created on 02132011_140922

Files\Folders moved on Rebootโ€ฆ
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFBCE.tmp not found!
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFBD8.tmp not found!
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFC55.tmp not found!
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFC60.tmp not found!
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFCBE.tmp not found!
File\Folder C:\Users\Buddy\AppData\Local\Temp\~DFFCC8.tmp not found!
C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.
C:\Users\Buddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JYIH4T4A\ac[7].htm moved successfully.
File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
C:\Windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2460.log moved successfully.
C:\Windows\temp\ehmsdri.log moved successfully.
File move failed. C:\Windows\temp\ehRecvr.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\vmware-vmount.log scheduled to be moved on reboot.

Registry entries deleted on Rebootโ€ฆ


and the one from MBR

aswMBR version 0.9.2 Copyrightยฉ 2011 avast! Software
Run date: 2011-02-13 19:21:17
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“
14:21:17.179 OS Version: Windows 6.0.6001 Service Pack 1
14:21:17.179 Number of processors: 2 586 0xF06
14:21:17.179 ComputerName: BUDDY-PC UserName: Buddy
14:21:25.556 Initialize success
14:21:46.975 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
14:21:46.975 Disk 0 Vendor: WDC_WD50 12.0 Size: 476940MB BusType: 3
14:21:46.975 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000080
14:21:46.975 Disk 1 Vendor: HP______ 1.00 Size: 476940MB BusType: 7
14:21:46.991 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000082
14:21:46.991 Disk 2 Vendor: Generic_ 1.00 Size: 476940MB BusType: 7
14:21:46.991 Disk 3 \Device\Harddisk3\DR3 -> \Device\00000083
14:21:46.991 Disk 3 Vendor: Generic_ 1.01 Size: 476940MB BusType: 7
14:21:46.991 Disk 4 \Device\Harddisk4\DR4 -> \Device\00000084
14:21:47.006 Disk 4 Vendor: Generic_ 1.02 Size: 476940MB BusType: 7
14:21:47.006 Disk 5 \Device\Harddisk5\DR5 -> \Device\00000085
14:21:47.006 Disk 5 Vendor: Generic_ 1.03 Size: 476940MB BusType: 7
14:21:47.006 Disk 0 MBR read successfully
14:21:47.053 Disk 0 MBR scan
14:21:47.115 Disk 0 scanning sectors +976770099
14:21:47.193 Disk 0 trace - called modules:
14:21:47.193 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8656e1ed]<<
14:21:47.193 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85ed0aa0]
14:21:47.193 3 CLASSPNP.SYS[8899c745] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8520f040]
14:21:47.193 \Driver\iaStorV[0x851e8940] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8656e1ed
14:21:47.193 Scan finished successfully
OK one of my colleagues has been looking at this - so lets try this


Click your start button, right click on My Computer
Click properties
click the Hardware tab
click Device manager button
click the + sign beside System Devices
look for something with cmz vmkd or vbma in name it should say virtual bus
right click the entry & select uninstall

Then retry Combofix

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI