This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC Running Very Slow

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, don't know if anyone can help but my PC is starting run very slow again. I have used this Forum in the past & it helped a great deal. I have one program that seems to slow down Firefox & other progs , it comes up in the task manager as ' vsmon.exe ', any ideas?
I have attached a hjt log to get started.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:41:18, on 27/10/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\trend micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.skybroadband.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe /icon="hidden"
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: ["c:\Program Files\Common Files\Microsoft Shared\web server extensions\50\bin\CFGWIZ.EXE" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz] "c:\Program Files\Common Files\Microsoft Shared\web server extensions\50\bin\CFGWIZ.EXE" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{94FE915A-DB7C-438A-AA7C-21BCDC77C9FD}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe

–
End of file - 11520 bytes


Regards,

hb
Hello and Welcome to WhatTheTech Forums

My name is BlackPegasus.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for
    further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to
    get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out
    the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to
    ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
Hello henrbowers

IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.
======================
vsmon.exe belongs to ZoneAlarm and yes it can be a system hog.

It would appear that you have more than one anti-virus solution on your machine. I can see AVG, and ZoneAlarm installed.
Having more than one anti-virus program on your machine, even if only one is running, can cause conflicts and slowdowns
in the performance of the machine. Before continuing on, please completely uninstall one of the programs.
If you have any trouble uninstalling one of them please let me know. After you are done, if you are not prompted to do so,
please reboot your machine. Please advise if the issues continue once you only have one anti-virus on the machine.
=====================
Fix HijackThis entries
Important!
Please temporarily disable any anti-spyware programs you are using,
so they will not interfere with the entries we will be fixing in HijackThis.

1. Run HijackThis
* If you are on the Main Menu page… Click "Do a system scan only"
* If you are on the "scan & fix stuff" page… Press the Scan…button.
2. When the scan finishes…Place a check mark next to the following entries (if they are still present):
*Only check those items listed below*

R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

3. After checking these items… CLOSE ALL open windows except HijackThis
4. Click the Fix Checked…button. Choose YES…when prompted to fix the selected items.
5. Once it has fixed them, close HijackThis and reboot your computer normally.

========================

NEXT

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

=======================
NEXT

Please download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
=======================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log and Extras.Txt
3. aswMBR log
4. How's your computer running?
Hi, yes I do still help. I hope haven't missed you as I have been away for a few days & this is the first chance I have had to look at the PC. I will start running the various logs as required tomorrow evening when I have some more time. Regards, henrbowers
Hi BP, please see my reply as follows -

1. Uninstalled Zonealarm - PC is running better but I have no firewall at the moment, any suggestions?

2. OTL Logs -

OTL logfile created on: 02/11/2011 22:05:51 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Steve Bowers\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.80 Mb Total Physical Memory | 474.63 Mb Available Physical Memory | 46.41% Memory free
2.40 Gb Paging File | 1.92 Gb Available in Paging File | 79.96% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 9.89 Gb Free Space | 26.57% Space Free | Partition Type: NTFS
Drive G: | 186.31 Gb Total Space | 73.17 Gb Free Space | 39.27% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 256.76 Gb Free Space | 55.13% Space Free | Partition Type: NTFS

Computer Name: D3538J0J | User Name: Steve Bowers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Steve Bowers\Desktop\OTL.exe (OldTimer Tools)
PRC - G:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SYSTEM32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\1fb5d8788c9a9a7f44e2d0fa19c62729\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\bdaf7904d223589a0f464de58d27e691\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d9228d58804dfd75fd92a4d12ffac8af\Accessibility.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\29d16d2f164fe2263539789ecd0d9d4f\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\a59b17e6040e3f6286a2227dfdb17096\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f354057a5b4fad4c399da28449ba0d92\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\48f8b951a598647dd309ca2031807a5d\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\f6a9a002526806f3a5b745cf5c407cae\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3188.36940__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3188.36964__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3188.36957__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3188.36949__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3188.36961__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3188.37084__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3188.37076__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3188.37018__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3188.37062__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3188.37109__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3188.37045__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3188.37111__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3188.36962__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3188.36948__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Dashboard\2.0.3188.36976__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3188.37055__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3188.36962__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Runtime\2.0.3188.36977__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3188.37054__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3188.37053__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3188.37134__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3188.37133__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3188.37023__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3188.37067__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3188.37021__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3188.36951__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3188.36965__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3188.37039__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3188.37038__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3188.37078__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3188.36966__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3188.36971__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3188.37013__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3188.37019__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3188.37041__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3188.37047__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3188.37020__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3188.37021__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3156.17694__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3156.17689__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3156.17698__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3156.17701__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3156.17722__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3156.17721__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3156.17682__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3156.17699__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3156.17681__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3156.17703__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3156.17703__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3156.17747__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3156.17703__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3156.17682__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3156.17697__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3156.17695__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3156.17689__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3156.17694__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3156.17706__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3156.17695__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3156.17718__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Shared\2.0.3156.17706__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3156.17706__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3156.17704__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3156.17710__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3156.17721__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3156.17708__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3156.17709__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3156.17704__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3156.17710__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3156.17707__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3156.17710__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3156.17701__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3156.17706__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3156.17704__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3156.17708__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3156.17702__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3156.17700__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3156.17695__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3188.37126__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3188.37139__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3156.17686__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll ()
MOD - C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3188.36933__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3188.37099__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3188.37095__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3156.17689__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3156.17702__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3188.36956__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3188.36938__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3156.17686__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3156.17698__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3188.36936__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3156.17698__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3156.17702__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3188.36945__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3156.17692__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3188.36937__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3188.37098__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3156.17711__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3188.36935__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3188.36934__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\WINDOWS\SYSTEM32\pdfcmnnt.dll ()


========== Win32 Services (SafeList) ==========

SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Microsoft Office Groove Audit Service) – G:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (aawservice) – G:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
SRV - (HidServ) – C:\WINDOWS\SYSTEM32\DLLCACHE\hidserv.dll (Microsoft Corporation)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\SYSTEM32\UAService7.exe (Sony DADC Austria AG.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (Dvd43) – C:\WINDOWS\SYSTEM32\DRIVERS\Dvd43.sys (Fengtao Software Inc.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (StarOpen) – C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (nm) – C:\WINDOWS\SYSTEM32\DRIVERS\nmnt.sys (Microsoft Corporation)
DRV - (sscdmdm) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbus.sys (MCCI Corporation)
DRV - (ss_mdm) – C:\WINDOWS\SYSTEM32\DRIVERS\ss_mdm.sys (MCCI Corporation)
DRV - (ss_mdfl) – C:\WINDOWS\SYSTEM32\DRIVERS\ss_mdfl.sys (MCCI Corporation)
DRV - (ss_bus) SAMSUNG Mobile USB Device 1.0 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\ss_bus.sys (MCCI Corporation)
DRV - (s125bus) Sony Ericsson Device 125 driver (WDM) – C:\WINDOWS\SYSTEM32\DRIVERS\s125bus.sys (MCCI Corporation)
DRV - (usbsermpt) – C:\WINDOWS\SYSTEM32\DRIVERS\usbsermpt.sys (Microsoft Corporation)
DRV - (ezplay) – C:\WINDOWS\SYSTEM32\DRIVERS\ezplay.sys (VSO Software)
DRV - (atksgt) – C:\WINDOWS\SYSTEM32\DRIVERS\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\SYSTEM32\DRIVERS\lirsgt.sys ()
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (RivaTuner32) – C:\Program Files\RivaTuner v2.0 RC 16\RivaTuner32.sys ()
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (sfsync04) StarForce Protection Synchronization Driver (version 4.x) – C:\WINDOWS\System32\drivers\sfsync04.sys (Protection Technology (StarForce))
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (RTL8023xp) – C:\WINDOWS\SYSTEM32\DRIVERS\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (sfvfs02) StarForce Protection VFS Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (imagesrv) – C:\WINDOWS\system32\DRIVERS\imagesrv.sys (Ahead Software AG)
DRV - (imagedrv) – C:\WINDOWS\System32\Drivers\imagedrv.sys (Ahead Software AG)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (Maplom) – C:\WINDOWS\System32\drivers\maplom.sys (Jacal Consulting)
DRV - (a347bus) – C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (ElbyDelay) – C:\WINDOWS\SYSTEM32\DRIVERS\ElbyDelay.sys (Elaborate Bytes AG)
DRV - (a347scsi) – C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (CX23880) TV Card(10BIT) – C:\WINDOWS\SYSTEM32\DRIVERS\cx88vid.sys (Geniatech, Inc.)
DRV - (CXTUNE) TV Card(10BIT) – C:\WINDOWS\SYSTEM32\DRIVERS\cx88tune.sys (Geniatech, Inc.)
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\SYSTEM32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\SYSTEM32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (CX88XBAR) TV Card(10BIT) – C:\WINDOWS\SYSTEM32\DRIVERS\cx88xbar.sys (Conexant Systems, Inc.)
DRV - (BCMModem) – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys (Broadcom Corporation)
DRV - (DCamUSBSQTECH) Dual-Mode DSC(2770) – C:\WINDOWS\SYSTEM32\DRIVERS\SQCaptur.sys (Service & Quality Technology.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (bvrp_pci) – C:\WINDOWS\System32\drivers\bvrp_pci.sys ()
DRV - (RegKill) – C:\WINDOWS\SYSTEM32\DRIVERS\RegKill.sys (Elaborate Bytes)
DRV - (pfc) – C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys (Padus, Inc.)
DRV - (kbfilter) – C:\WINDOWS\System32\drivers\kbfilter.sys (WayTech Development, Inc.)
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (EL90XBC) – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.skybroadband.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant_bak = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.msn.co.uk/Default.asp"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: G:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: G:\Program Files\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: G:\Program Files\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: G:\Program Files\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/12/21 15:26:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/03/17 22:41:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/01 07:29:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/17 21:23:24 | 000,000,000 | —D | M]

[2009/06/21 22:26:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Extensions
[2004/12/14 22:04:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\0s19znww.default\extensions
[2004/12/14 22:04:09 | 000,000,000 | —D | M] (Firefox (default)) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\0s19znww.default\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/10/11 20:08:05 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\extensions
[2010/04/28 19:48:42 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/18 21:35:37 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2011/10/11 20:08:05 | 000,000,000 | —D | M] (TenchisTV Community Toolbar) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\extensions\{ece24dcf-8548-4655-b392-47a388721482}
[2011/06/19 14:20:36 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\extensions\[removed]
[2011/09/29 15:07:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/01 07:29:03 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/03/24 12:00:00 | 000,555,008 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npagent.dll
[2008/09/04 00:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2011/06/17 21:23:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2008/10/09 19:30:44 | 000,000,686 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - G:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] G:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoViewOnDrive = 0
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - G:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{94FE915A-DB7C-438A-AA7C-21BCDC77C9FD}: NameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - G:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\SYSTEM32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - (avgrsstx.dll) - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {93994DE8-8239-4655-B1D1-5F4E91300429} - C:\Program Files\DVD Region+CSS Free\DVDShell.dll (Fengtao Software Inc.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - G:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell - "" = AutoRun
O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – Reg Error: Value error. File not found
O37 - HKCU\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/02 19:12:07 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Steve Bowers\Desktop\OTL.exe
[2011/10/27 20:38:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Steve Bowers\Start Menu\Programs\HiJackThis
[2011/10/17 07:29:52 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Steve Bowers\PrivacIE
[2011/10/09 12:33:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Steve Bowers\Desktop\Lauren Bowers
[2011/10/09 12:12:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Steve Bowers\Desktop\Callum Bowers
[2007/08/31 20:56:24 | 000,094,080 | —- | C] (VSO Software) – C:\Documents and Settings\Steve Bowers\Application Data\ezplay.sys
[2006/11/15 09:52:07 | 000,047,360 | —- | C] (VSO Software) – C:\Documents and Settings\Steve Bowers\Application Data\pcouffin.sys
[2005/07/29 18:50:51 | 000,158,720 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347bus.sys
[2005/07/29 18:50:51 | 000,005,248 | —- | C] ( ) – C:\WINDOWS\System32\drivers\a347scsi.sys
[47 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[45 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/02 21:17:01 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2011/11/02 19:15:38 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2011/11/02 19:15:36 | 000,055,160 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2011/11/02 19:15:31 | 1072,549,888 | -HS- | M] () – C:\hiberfil.sys
[2011/11/02 19:12:10 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Steve Bowers\Desktop\OTL.exe
[2011/11/02 19:07:05 | 000,002,461 | —- | M] () – C:\Documents and Settings\Steve Bowers\Desktop\HiJackThis.lnk
[2011/11/02 16:05:12 | 085,662,370 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/10/31 08:52:54 | 000,444,832 | —- | M] () – C:\WINDOWS\System32\PERFH009.DAT
[2011/10/31 08:52:54 | 000,072,582 | —- | M] () – C:\WINDOWS\System32\PERFC009.DAT
[2011/10/30 23:07:36 | 000,152,576 | —- | M] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/25 15:13:46 | 000,000,668 | —- | M] () – C:\Documents and Settings\Steve Bowers\Application Data\vso_ts_preview.xml
[2011/10/18 20:49:13 | 000,000,067 | —- | M] () – C:\WINDOWS\Easy DVD Creator.INI
[2011/10/10 20:32:07 | 000,000,211 | -HS- | M] () – C:\BOOT.INI
[47 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[45 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/05 22:02:31 | 000,013,726 | -HS- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\2a88372pk28
[2011/07/05 22:02:31 | 000,013,726 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\2a88372pk28
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ytl.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\ukp.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\taf.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\rsp.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\inj.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\hch.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\gbk.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\dwd.exe
[2011/07/05 22:02:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\btm.exe
[2011/03/08 01:10:01 | 000,234,600 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/08/29 12:29:45 | 000,077,824 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\000017F0_VTS_1.IFO
[2010/06/18 10:34:15 | 000,000,248 | —- | C] () – C:\WINDOWS\RomeTW.ini
[2010/05/19 11:01:58 | 003,508,170 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\Alexandra Burke - All Night Long (Ft Pitbull).zip
[2010/02/01 22:10:39 | 000,116,224 | —- | C] () – C:\WINDOWS\System32\pdfcmnnt.dll
[2009/06/23 20:57:00 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2009/06/23 20:52:35 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2008/11/18 20:31:11 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2008/11/18 20:24:55 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2008/11/14 21:33:35 | 000,000,668 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\vso_ts_preview.xml
[2008/11/14 21:31:49 | 000,087,608 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\inst.exe
[2008/10/29 01:40:41 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativvaxx.dat
[2008/10/29 01:40:41 | 003,107,788 | —- | C] () – C:\WINDOWS\System32\ativva5x.dat
[2008/10/29 01:40:41 | 000,887,724 | —- | C] () – C:\WINDOWS\System32\ativva6x.dat
[2008/10/21 17:51:43 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\atibrtmon.exe
[2008/08/14 17:42:21 | 000,176,918 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2008/05/16 10:58:04 | 000,012,632 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2008/03/17 22:02:08 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/02/26 19:22:34 | 000,691,545 | —- | C] () – C:\WINDOWS\unins000.exe
[2008/02/26 19:22:34 | 000,002,550 | —- | C] () – C:\WINDOWS\unins000.dat
[2007/10/19 20:48:54 | 000,000,067 | —- | C] () – C:\WINDOWS\Easy DVD Creator.INI
[2007/08/31 20:56:22 | 000,081,920 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\ezpinst.exe
[2007/08/21 21:51:16 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2007/08/21 19:36:12 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2007/07/28 21:47:53 | 000,000,026 | —- | C] () – C:\WINDOWS\dvdSanta.INI
[2006/11/15 09:52:42 | 000,007,172 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\ezplay.cat
[2006/11/15 09:52:41 | 000,001,104 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.inf
[2006/11/15 09:52:41 | 000,000,125 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.ini
[2006/11/15 09:52:07 | 000,007,887 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\pcouffin.cat
[2006/11/15 09:52:07 | 000,001,144 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\pcouffin.inf
[2006/07/27 02:05:58 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006/07/12 18:28:13 | 000,165,376 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2006/07/12 18:28:04 | 000,018,048 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2006/06/27 18:41:03 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/06/21 10:43:08 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2006/06/21 10:33:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/06/14 14:40:09 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/04/17 22:04:19 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2006/01/21 20:08:58 | 000,038,912 | —- | C] () – C:\WINDOWS\System32\DISP_OPT1.dll
[2005/11/24 14:09:30 | 000,014,320 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2005/11/09 22:25:11 | 000,000,135 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\fusioncache.dat
[2005/10/09 22:08:15 | 000,000,229 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2005/04/17 20:15:08 | 000,012,288 | —- | C] () – C:\WINDOWS\impborl.dll
[2005/02/24 06:32:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/02/24 06:32:00 | 001,626,112 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2005/02/24 06:32:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/02/24 06:32:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/02/24 06:32:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/02/24 06:32:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2005/02/24 06:32:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2005/02/24 06:32:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/01/01 20:16:11 | 000,000,182 | —- | C] () – C:\WINDOWS\System32\EBPPORT4.DAT
[2005/01/01 20:07:16 | 000,000,025 | —- | C] () – C:\WINDOWS\CDER300Euro.ini
[2004/12/31 09:28:35 | 000,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/12/29 16:21:33 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/12/27 13:38:39 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/12/21 20:03:11 | 000,000,102 | —- | C] () – C:\WINDOWS\DVDRegionFree.INI
[2004/12/14 22:04:34 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2004/12/14 22:03:20 | 000,099,965 | —- | C] () – C:\WINDOWS\UninstallFirefox.exe
[2004/12/14 22:02:09 | 000,007,002 | —- | C] () – C:\WINDOWS\mozver.dat
[2004/11/21 20:46:19 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2004/11/15 09:03:52 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2004/08/08 19:21:51 | 000,000,112 | —- | C] () – C:\WINDOWS\ActiveSkin.INI
[2004/07/25 07:32:30 | 000,000,108 | —- | C] () – C:\WINDOWS\System32\BurnData.bin
[2004/07/15 10:42:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2004/07/15 10:42:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2004/06/21 18:24:06 | 000,011,264 | —- | C] () – C:\WINDOWS\CATSTUB.EXE
[2004/06/21 18:24:06 | 000,000,344 | —- | C] () – C:\WINDOWS\encarta.ini
[2004/06/21 18:24:04 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2004/04/30 20:04:05 | 000,000,063 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/04/10 09:34:57 | 000,008,192 | -HS- | C] () – C:\WINDOWS\o2cLicStore.bin
[2004/04/10 08:42:55 | 000,000,061 | —- | C] () – C:\WINDOWS\Tiny_Run.ini
[2003/12/28 20:37:00 | 000,025,601 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2003/12/28 19:57:33 | 000,000,525 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2003/11/25 22:29:19 | 000,000,000 | —- | C] () – C:\WINDOWS\RussSqr.INI
[2003/09/30 19:56:06 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/09/21 19:58:52 | 000,000,004 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/21 18:09:16 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2003/08/06 22:33:55 | 000,000,089 | -H– | C] () – C:\WINDOWS\pcconfig.dat
[2003/07/25 13:21:14 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\myfastaccess.dll
[2003/06/29 19:10:45 | 000,000,688 | —- | C] () – C:\WINDOWS\Vtw.INI
[2003/06/21 14:29:09 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/05/27 17:34:31 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\GkSui18.EXE
[2003/04/19 17:02:28 | 000,001,503 | —- | C] () – C:\WINDOWS\photoimpression.ini
[2002/11/02 15:46:12 | 000,001,490 | —- | C] () – C:\WINDOWS\eReg.dat
[2002/10/29 21:58:08 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2002/10/27 16:13:17 | 000,000,491 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2002/10/26 17:13:05 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2002/10/26 17:13:05 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2002/10/26 17:13:05 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2002/10/22 17:52:28 | 000,000,016 | —- | C] () – C:\WINDOWS\ka.ini
[2002/10/21 20:05:54 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2002/10/20 20:49:23 | 000,056,320 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[2002/10/17 20:58:22 | 000,152,576 | —- | C] () – C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2002/10/17 20:40:48 | 000,001,447 | —- | C] () – C:\WINDOWS\disney.ini
[2002/10/07 14:04:59 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/10/07 13:59:24 | 001,576,960 | —- | C] () – C:\WINDOWS\System32\mplvw7.dll
[2002/10/07 13:59:24 | 001,118,208 | —- | C] () – C:\WINDOWS\System32\mplvpx.dll
[2002/10/07 13:59:23 | 001,642,496 | —- | C] () – C:\WINDOWS\System32\mplva6.dll
[2002/10/07 13:59:23 | 001,548,288 | —- | C] () – C:\WINDOWS\System32\mplvm6.dll
[2002/10/07 13:59:23 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaw7.dll
[2002/10/07 13:59:23 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\mplaa6.dll
[2002/10/07 13:59:23 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\mplapx.dll
[2002/10/07 13:59:23 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\mplam6.dll
[2002/10/07 13:59:23 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2002/10/07 13:56:23 | 000,000,883 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/10/07 13:50:06 | 000,002,048 | –S- | C] () – C:\WINDOWS\BOOTSTAT.DAT
[2002/10/07 13:49:30 | 000,444,832 | —- | C] () – C:\WINDOWS\System32\PERFH009.DAT
[2002/10/07 13:49:30 | 000,072,582 | —- | C] () – C:\WINDOWS\System32\PERFC009.DAT
[2002/10/07 13:26:40 | 000,000,549 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2002/01/25 07:04:50 | 000,005,440 | —- | C] () – C:\WINDOWS\System32\mciwa16.dll
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\pspsbext.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\pspfidrv.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\pspfbase.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\pspaudrv.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\pspapdrv.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\mciwaw95.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\mcipspwa.ini
[2002/01/25 07:04:50 | 000,000,221 | —- | C] () – C:\WINDOWS\System32\mcipspct.ini
[2002/01/25 07:04:50 | 000,000,220 | —- | C] () – C:\WINDOWS\System32\pspwave.ini
[2002/01/25 07:04:50 | 000,000,219 | —- | C] () – C:\WINDOWS\System32\pspdss.ini
[2002/01/25 07:04:50 | 000,000,219 | —- | C] () – C:\WINDOWS\System32\pspddi.ini
[2001/08/31 09:55:56 | 000,404,712 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2001/08/31 09:50:36 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2001/08/31 09:47:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2001/08/23 14:07:14 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2001/08/23 14:07:02 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2001/08/18 06:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\MLANG.DAT
[2001/08/18 06:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\PERFI009.DAT
[2001/08/18 06:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\DSSEC.DAT
[2001/08/18 06:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\MIB.BIN
[2001/08/18 06:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\PERFD009.DAT
[2001/08/18 06:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2001/08/18 06:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\NOISE.DAT

========== LOP Check ==========

[2011/05/15 19:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2007/09/26 19:24:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bags loud rect corn
[2007/06/21 15:59:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2011/10/02 10:01:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2009/11/03 23:14:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2007/06/17 20:06:08 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\NeoTemp
[2011/05/12 21:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2003/12/28 20:04:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2004/11/16 14:31:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2003/12/30 19:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanAppDataDir
[2003/12/30 19:26:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SSScanWizard
[2007/09/29 19:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/11/23 22:12:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2005/01/01 20:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UDL
[2004/10/10 19:40:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/11/18 16:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/01/01 16:03:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Amazon
[2011/05/15 19:19:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Autodesk
[2011/10/30 10:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\BitTorrent
[2011/09/25 17:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Canon
[2011/10/02 10:02:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\CheckPoint
[2009/02/08 21:55:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\CopyToDvd
[2009/11/04 19:35:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\DAEMON Tools Lite
[2009/11/20 23:14:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\DNA
[2007/08/15 20:27:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\FlashGet
[2010/12/17 20:59:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\FreeArc
[2003/12/28 19:54:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\InterTrust
[2010/04/22 21:38:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Mount&Blade; Warband
[2006/05/02 19:46:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\My Games
[2007/09/26 19:24:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Once 4 junk
[2010/02/02 20:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\pdfforge
[2007/08/15 20:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\PPLive
[2010/05/30 18:17:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\RipIt4Me
[2009/06/23 20:58:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Samsung
[2003/12/28 19:57:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\ScanSoft
[2011/08/07 11:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Search Settings
[2008/12/20 16:04:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Teleca
[2003/02/02 16:39:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Template
[2009/03/05 19:34:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\The Creative Assembly
[2003/05/11 14:17:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\The Labyrinth Plus! Edition
[2004/10/10 19:44:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Ulead Systems
[2011/10/25 15:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Steve Bowers\Application Data\Vso

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Steve Bowers\My Documents\u32Cfg.dll:SummaryInformation

< End of report >


OTL Extras logfile created on: 02/11/2011 22:05:51 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Steve Bowers\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1022.80 Mb Total Physical Memory | 474.63 Mb Available Physical Memory | 46.41% Memory free
2.40 Gb Paging File | 1.92 Gb Available in Paging File | 79.96% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 9.89 Gb Free Space | 26.57% Space Free | Partition Type: NTFS
Drive G: | 186.31 Gb Total Space | 73.17 Gb Free Space | 39.27% Space Free | Partition Type: NTFS
Drive I: | 465.76 Gb Total Space | 256.76 Gb Free Space | 55.13% Space Free | Partition Type: NTFS

Computer Name: D3538J0J | User Name: Steve Bowers | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] – Reg Error: Value error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – Reg Error: Value error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – G:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\iau.exe" = C:\WINDOWS\iau.exe:*:Disabled:iau
"C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat" = C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat:*:Enabled:?????????????????????????
"C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe" = C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG Free\avgcc.exe" = C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\BitTorrent_DNA\dna.exe" = C:\Program Files\BitTorrent_DNA\dna.exe:*:Enabled:DNA
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"G:\Program Files\PPMate\ppmate.exe" = G:\Program Files\PPMate\ppmate.exe:*:Enabled:PPMate
"G:\Program Files\PPMate\ppmnet.exe" = G:\Program Files\PPMate\ppmnet.exe:*:Enabled:PPMate
"G:\Program Files\PPLive\PPLive.exe" = G:\Program Files\PPLive\PPLive.exe:*:Enabled:PPLive – ()
"G:\Program Files\FlashGet\flashget.exe" = G:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget
"G:\Program Files\TVAnts\Tvants.exe" = G:\Program Files\TVAnts\Tvants.exe:*:Enabled:TVAnts – (Zhejiang University)
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA – (BitTorrent, Inc.)
"G:\Program Files\BitTorrent\bittorrent.exe" = G:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\AVG\AVG8\avgam.exe" = C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost
"G:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = G:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"G:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = G:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove – (Microsoft Corporation)
"G:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = G:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote – (Microsoft Corporation)
"C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe" = C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe:*:Enabled:vsmon


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}" = Medieval II Total War : Kingdoms : Crusades
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{03F1CC67-5BD8-4C36-8394-76311B2AE69A}" = ArcSoft PhotoStudio 5
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{06A940CD-4924-485E-8500-476C9E08A820}" = Samsung PC Studio 3
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{109D28C7-FB38-483A-9C91-001CB59E2699}" = EPSON CardMonitor
"{11202615-E557-4ECF-9B86-F59C81E52909}" = FIFA 10
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{14C35072-D7D0-4B29-B5BF-C94E426D77E9}" = Sky Broadband
"{1798227A-AA89-4C78-AF55-56A38E654788}" = Belkin F5D5000 Desktop PCI Card Driver
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F8640AF-F0BB-C185-C0C7-A618C9D8CC5F}" = Catalyst Control Center Graphics Light
"{2315B23D-3E21-4920-837D-AE6460934ECB}" = FIFA 09
"{23B59B9F-C360-11D7-875B-0090CC005647}" = PIF DESIGNER2.1
"{23B59ED4-C360-11D7-875B-0090CC005647}" = EPSON PRINT Image Framer Tool2.1
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 13
"{29931C9B-6DCE-B152-575B-837D698E08E3}" = ccc-core-static
"{2C0A655C-61E7-428A-8ED2-23A3D20E7DD2}" = Data Lifeguard
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33AE85D9-0386-41AD-BD99-FDF3ABC19DBB}" =
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C586119-257A-B324-F6D7-8C14A8E63A8F}" = Catalyst Control Center Graphics Full Existing
"{3D374523-CFDE-461A-827E-2A102E2AB365}" = Star Wars Battlefront II
"{3E363410-6618-DE74-FA07-6DACC0248608}" = Skins
"{3E908702-AF35-4611-9518-955DA24B7E07}" = Microsoft XML Parser and SDK
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = Dell Modem-On-Hold
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4F087AEB-84C2-40C3-5CD7-91AD81E6EC99}" = Catalyst Control Center Graphics Full New
"{4F1DA6BF-3614-48A1-9970-9E90F646789E}" = Ulead VideoStudio 8.0 Trial
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{513AEC24-3465-8C4F-87BA-652D6F491033}" = Nero 7 Demo
"{5783F2D7-8001-0409-0002-0060B0CE6BBA}" = AutoCAD 2010 - English
"{5783F2D7-8001-0409-1002-0060B0CE6BBA}" = AutoCAD 2010 Language Pack - English
"{5B4F13B0-62C4-4F70-B9A6-3788196EC972}" = GBalph NDSMovie Converter V1.00
"{6249C22D-E6A8-407B-BA8B-40298848ED94}" = OmniPage SE
"{65F5B7AF-3363-11D7-BB6B-00018021113F}" = EPSON PhotoQuicker3.5
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DE13770-01B7-4366-8DA6-48237793F445}" = VoiceOver Kit
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{75983B66-804C-40D1-BA13-64DAF652A6F1}" = Medieval II Total War : Kingdoms : Americas
"{76C24F39-B161-498F-BD8B-C64789812D13}_is1" = ConvertXtoDVD [removed]
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7A22B382-FA54-FA71-FE3D-5ADD12D02234}" = Catalyst Control Center Graphics Previews Common
"{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}" = Medieval II Total War : Kingdoms : Teutonic
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A5D65411-8E73-4C85-AD80-9FE8B7391CF9}" = Rome Total War - patch 1.3
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War™
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B360A8E5-C171-4AAE-9777-65B3CDB0072C}" = CanoScan LiDE20,30 Manual
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B607C354-CD79-4D22-86D1-92DC94153F42}" = Apple Application Support
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{BF422939-232D-A68C-B57A-367C2804AA00}" = Catalyst Control Center Core Implementation
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C48817E7-AA05-4151-A99D-1E1E550CE801}" = EPSON PhotoStarter3.1
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{CE177DFA-B1C8-BB04-8284-E1CB240CC9DD}" = ccc-core-preinstall
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}" = Medieval II Total War : Kingdoms : Britannia
"{CF7C4842-3370-B6C0-287D-674FD99AEBB2}" = CCC Help English
"{D1A74FBB-CA8D-4CCA-9B89-BAAA436DB178}" = iTunes
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3436EE2-D5CB-4249-840B-3A0140CC34C3}" = Classic PhoneTools
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}" = ScanToWeb
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}" = Microsoft Plus! for Windows XP
"{F62DFC11-8A61-D19B-1A68-BAE51C35BC43}" = ccc-utility
"{F8D0829C-9C6F-11D3-8080-00C04FA329AA}" = Microsoft Works 6.0
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FD3D9B16-44E4-4231-E1E2-85C40A115F87}" = ATI Catalyst Install Manager
"{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}" = Barbarian Invasion
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"7-Zip" = 7-Zip 4.51 beta
"Adobe Acrobat 5.0" = Adobe Acrobat 4.0, 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Amazon Kindle For PC" = Amazon Kindle For PC
"ATI Display Driver" = ATI Display Driver
"AutoCAD 2010 - English" = AutoCAD 2010 - English
"AVG8Uninstall" = AVG 8.5
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"BitTorrent" = BitTorrent
"CloneCD Games Database" = CloneCD Games Database
"CloneDVD Trial_is1" = CloneDVD Trial [removed]
"CloneDVD2" = CloneDVD2
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2007-07-22
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"Digital Camera" = Digital Camera
"DriverAgent" = DriverAgent Plugin for Netscape by TouchStone Software
"DVD Decrypter" = DVD Decrypter (Remove Only)
"DVD Region Killer" = DVD Region Killer
"DVD Region+CSS Free_is1" = DVD Region+CSS Free 5.59
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD43_is1" = DVD43 v3.5.2
"Easy DVD Creator_is1" = Easy DVD Creator 1.5.3
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"ffdshow_is1" = ffdshow [rev 1900] [2008-03-15]
"Free WMA to MP3 Converter_is1" = Free WMA to MP3 Converter 1.16
"FreeArc" = FreeArc 0.60
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War™
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"Magic FLAC to MP3 Converter_is1" = Magic FLAC to MP3 Converter 3.72
"Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mount&Blade; Warband" = Mount&Blade; Warband
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PC Linker for TouchPod" = PC Linker for TouchPod Ð¶ÔØ³ÌÐò
"PowerISO" = PowerISO
"PPLive" = PPLive 1.7
"PRJPRO" = Microsoft Office Project Professional 2007
"RealPlayer 6.0" = RealPlayer
"RivaTuner" = RivaTuner v2.0 RC 16
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Shockwave" = Shockwave
"SopCast" = SopCast 1.1.2
"SopFilter" = SopFilter 3.0.5
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.5.2.20
"TVAnts 1.0" = TVAnts 1.0
"TVUPlayer" = TVUPlayer 2.3.0.0
"Tweak UI 2.10" = Tweak UI
"USB-706 Vibration Joystick" = USB-706 Vibration Joystick
"ViewpointMediaPlayer" = Viewpoint Media Player (Remove Only)
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WIC" = Windows Imaging Component
"Win AVI HelixSDK_is1" = Win AVI HelixSDK
"WinAVI Video Converter_is1" = WinAVI Video Converter
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XVid;-)" = XVid;-)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 07/08/2011 08:34:02 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application DRWTSN32.EXE, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 09/08/2011 15:00:54 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module explorer.exe, version 6.0.2900.5512, fault address 0x000027b1.

Error - 09/08/2011 15:01:32 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application DRWTSN32.EXE, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 17/08/2011 11:28:15 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x000101b3.

Error - 27/08/2011 08:41:45 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application epsoncd.exe, version 1.2.0.0, faulting module
epsoncd.exe, version 1.2.0.0, fault address 0x0008c697.

Error - 28/08/2011 14:40:32 | Computer Name = D3538J0J | Source = MsiInstaller | ID = 11920
Description = Product: pdfforge Toolbar v4.6 – Error 1920.Service Application Updater
(Application Updater) failed to start. Verify that you have sufficient privileges
to start system services.

Error - 25/09/2011 05:30:58 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x519857d0.

Error - 19/10/2011 11:38:05 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x000101b3.

Error - 19/10/2011 11:43:42 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module ntdll.dll, version 5.1.2600.6055, fault address 0x000101b3.

Error - 30/10/2011 19:12:20 | Computer Name = D3538J0J | Source = Application Error | ID = 1000
Description = Faulting application vlc.exe, version 0.8.6.0, faulting module libffmpeg_plugin.dll,
version 0.0.0.0, fault address 0x0021f85d.

[ System Events ]
Error - 23/10/2011 09:20:16 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:20:17 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:21:09 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:21:10 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:21:16 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:21:17 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:26:49 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:26:50 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:26:54 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 23/10/2011 09:26:55 | Computer Name = D3538J0J | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.


< End of report >


3. aswMSR Log


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-02 22:26:47
—————————–
22:26:47.562 OS Version: Windows 5.1.2600 Service Pack 3
22:26:47.562 Number of processors: 1 586 0x204
22:26:47.562 ComputerName: D3538J0J UserName:
22:26:49.828 Initialize success
22:27:09.484 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
22:27:09.484 Disk 0 Vendor: WDC_WD400EB-75CPF0 06.04G06 Size: 38166MB BusType: 3
22:27:09.484 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
22:27:09.484 Disk 1 Vendor: WDC_WD2000BB-55GUA0 08.02D08 Size: 190782MB BusType: 3
22:27:09.484 Device \Driver\atapi -> DriverStartIo f75ef864
22:27:09.484 Device \Driver\atapi -> MajorFunction 87482008
22:27:11.515 Disk 0 MBR read successfully
22:27:11.515 Disk 0 MBR scan
22:27:11.515 Disk 0 Windows XP default MBR code
22:27:11.515 Disk 0 scanning sectors +78156225
22:27:11.609 Disk 0 scanning C:\WINDOWS\system32\drivers
22:27:34.078 Service scanning
22:27:35.328 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
22:27:35.984 Modules scanning
22:27:59.625 Disk 0 trace - called modules:
22:27:59.656 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x87482008]<<
22:27:59.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x877e9298]
22:27:59.656 3 CLASSPNP.SYS[f7833fd7] -> nt!IofCallDriver -> \Device\00000078[0x877dd468]
22:27:59.671 5 ACPI.sys[f7648620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x877dd818]
22:27:59.671 \Driver\atapi[0x877129c8] -> IRP_MJ_CREATE -> 0x87482008
22:27:59.671 Scan finished successfully
22:30:56.406 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Steve Bowers\Desktop\MBR.dat"
22:30:56.421 The log file has been saved successfully to "C:\Documents and Settings\Steve Bowers\Desktop\aswMBR.txt"

4. PC is running better, the vsmon.exe was the main problem, I think since I did the latest update?

Thanks

henrbowers

Hello henrbowers,

IMPORTANT NOTE : Please do not delete anything unless instructed to. DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

P2P Warning!

IMPORTANT: There are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer. BitTorrent and BitTorrent DNA
Please note whenever you use any form of P2P networking to download files you can anticipate infestations of malware to occur.
P2P file sharing used to be fairly safe. This is no longer true…continue to use P2P sharing …at your own risk!
Keep in mind that this practice may be the source of your current malware infestation.

I strongly recommend that you uninstall: BitTorrent and BitTorrent DNA
You can do so using the Control Panel >> Add or Remove Programs function…however, that choice is up to you.

If you choose not to remove them, please do not use them until this computer is clean.

References… siting the risk factors, of using P2P programs:
Malware: Help prevent the Infection
IM And P2P Malware Threats Nearly Triple
How to Prevent the Online Invasion of Spyware and Adware

=======================
Please go to one of the below sites to scan the following files:

Virus Total
jotti.org
Kaspersky Virus File Scanner


click on Browse, and upload the following file for analysis:

C:\Documents and Settings\All Users\Application Data\2a88372pk28
C:\Documents and Settings\All Users\Application Data\ytl.exe
C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\ukp.exe
C:\Documents and Settings\All Users\Application Data\taf.exe
C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\rsp.exe
C:\Documents and Settings\All Users\Application Data\inj.exe
C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\hch.exe
C:\Documents and Settings\All Users\Application Data\gbk.exe
C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\dwd.exe
C:\Documents and Settings\All Users\Application Data\btm.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

==================
We need to uninstall Spybot - Search & Destroy, sometimes it prevents us from making the changes to your computer.
When were done we can reinstall Spybot if you would like.

Please go to Start>Control Panel>Add Remove Programs. On the list you should find an entry for Spybot - Search & Destroy. Click Remove and allow Windows to completely remove the program.Then reboot your computer to complete this part of the process.

==================
NEXT

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

==================
NEXT

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - SITEguard - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
    O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell - "" = AutoRun
    O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
    O33 - MountPoints2\K\Shell - "" = AutoRun
    O33 - MountPoints2\K\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\Autorun.exe
    [47 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    [45 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
    [2006/11/15 09:52:41 | 000,001,104 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.inf
    [2006/11/15 09:52:41 | 000,000,125 | —- | C] () – C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.ini
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

=====================
Please include in your next reply:
1. Any problem executing the instructions?
2. Virus Total log
3. OTL log
4. How is the computer behaving?
Hi BP, please see results below - Uninstalled Spybot jotti - found no problems (virus tool didn't what to work?) OTL Log All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found. File not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@checkpoint.com/FFApi\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\SITEguard deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully. Starting removal of ActiveX control Microsoft XML Parser for Java Reg Error: Value error. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java Reg Error: Value error.\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java Reg Error: Value error.\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found. File I:\LaunchU3.exe -a not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found. File K:\Autorun.exe not found. C:\WINDOWS\System32\CONFIG.TMP deleted successfully. C:\WINDOWS\System32\SET721.tmp deleted successfully. C:\WINDOWS\System32\SET722.tmp deleted successfully. C:\WINDOWS\System32\SET723.tmp deleted successfully. C:\WINDOWS\System32\SET724.tmp deleted successfully. C:\WINDOWS\System32\SET725.tmp deleted successfully. C:\WINDOWS\System32\SET726.tmp deleted successfully. C:\WINDOWS\System32\SET727.tmp deleted successfully. C:\WINDOWS\System32\SET728.tmp deleted successfully. C:\WINDOWS\System32\SET72B.tmp deleted successfully. C:\WINDOWS\System32\SET72D.tmp deleted successfully. C:\WINDOWS\System32\SET72E.tmp deleted successfully. C:\WINDOWS\System32\SET72F.tmp deleted successfully. C:\WINDOWS\System32\SET732.tmp deleted successfully. C:\WINDOWS\System32\SET733.tmp deleted successfully. C:\WINDOWS\System32\SET735.tmp deleted successfully. C:\WINDOWS\System32\SET736.tmp deleted successfully. C:\WINDOWS\System32\SET738.tmp deleted successfully. C:\WINDOWS\System32\SET73A.tmp deleted successfully. C:\WINDOWS\System32\SET73B.tmp deleted successfully. C:\WINDOWS\System32\SET73C.tmp deleted successfully. C:\WINDOWS\System32\SET73D.tmp deleted successfully. C:\WINDOWS\System32\SET73E.tmp deleted successfully. C:\WINDOWS\System32\SET73F.tmp deleted successfully. C:\WINDOWS\System32\SET740.tmp deleted successfully. C:\WINDOWS\System32\SET744.tmp deleted successfully. C:\WINDOWS\System32\SET745.tmp deleted successfully. C:\WINDOWS\System32\SET746.tmp deleted successfully. C:\WINDOWS\System32\SET747.tmp deleted successfully. C:\WINDOWS\System32\SET748.tmp deleted successfully. C:\WINDOWS\System32\SET749.tmp deleted successfully. C:\WINDOWS\System32\SET74A.tmp deleted successfully. C:\WINDOWS\System32\SET74B.tmp deleted successfully. C:\WINDOWS\System32\SET752.tmp deleted successfully. C:\WINDOWS\System32\SET753.tmp deleted successfully. C:\WINDOWS\System32\SET754.tmp deleted successfully. C:\WINDOWS\System32\SET755.tmp deleted successfully. C:\WINDOWS\System32\SET756.tmp deleted successfully. C:\WINDOWS\System32\SET757.tmp deleted successfully. C:\WINDOWS\System32\SET758.tmp deleted successfully. C:\WINDOWS\System32\SET759.tmp deleted successfully. C:\WINDOWS\System32\SET75A.tmp deleted successfully. C:\WINDOWS\System32\SET76.tmp deleted successfully. C:\WINDOWS\System32\SET7A.tmp deleted successfully. C:\WINDOWS\System32\SET7B.tmp deleted successfully. C:\WINDOWS\System32\SET82.tmp deleted successfully. C:\WINDOWS\System32\SETCC.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6DF.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E0.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E1.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E2.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E3.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E4.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E5.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E6.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E7.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E8.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6E9.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6EA.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6EB.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6EC.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6ED.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6EE.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6EF.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F0.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F1.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F2.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F3.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F4.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F5.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F6.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F7.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F8.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6F9.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FA.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FB.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FC.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FD.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FE.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET6FF.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET700.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET701.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET702.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET703.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET704.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET705.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET706.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET707.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET708.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET709.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET70A.tmp deleted successfully. C:\WINDOWS\System32\dllcache\SET70B.tmp deleted successfully. C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.inf moved successfully. C:\Documents and Settings\Steve Bowers\Application Data\DSHLJWLV.ini moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point (0) [EMPTYTEMP] User: Administrator User: Administrator.D3538J0J ->Temp folder emptied: 289828 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->FireFox cache emptied: 6570093 bytes User: All Users User: Default User ->Temp folder emptied: 289828 bytes ->Temporary Internet Files folder emptied: 279779 bytes User: Jamie Bowers ->Temp folder emptied: 39173513 bytes ->Temporary Internet Files folder emptied: 273768298 bytes ->Java cache emptied: 80138434 bytes ->FireFox cache emptied: 191537516 bytes ->Flash cache emptied: 103947 bytes User: Jamie Bowers.D3538J0J ->Temp folder emptied: 1381006 bytes ->Temporary Internet Files folder emptied: 41776657 bytes ->FireFox cache emptied: 700991934 bytes ->Flash cache emptied: 1374 bytes User: LocalService ->Temp folder emptied: 2052104 bytes ->Temporary Internet Files folder emptied: 40822 bytes User: NetworkService ->Temp folder emptied: 1983400 bytes ->Temporary Internet Files folder emptied: 34702 bytes User: Owner User: Steve Bowers ->Temp folder emptied: 10369815 bytes ->Temporary Internet Files folder emptied: 73773712 bytes ->Java cache emptied: 95222599 bytes ->FireFox cache emptied: 156011789 bytes ->Apple Safari cache emptied: 1072128 bytes ->Flash cache emptied: 1019 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 39097 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 539732 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 138616736 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 148079612 bytes RecycleBin emptied: 3993117324 bytes Total Files Cleaned = 5,681.00 mb OTL by OldTimer - Version 3.2.31.0 log created on 11062011_213608 Files\Folders moved on Reboot… Registry entries deleted on Reboot… Computer not running too bad, seems ok? Regards hb
Hi henrbowers

  • Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  • Please disable any Antivirus or Firewall you have active, as shown in this topic. Please close all open application windows.
  • Double click on ComboFix.exe & follow the prompts
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console
[external image: Posted Image]
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper

================
Please include in your next reply:
1. Any problem executing the instructions?
2. Combofix log
3. How is the computer behaving?
Hi BP Combofix installed & run No log, prog didn't seem to want finish? I had the following screen on for over an hour- 'PREPARING LOG REPORT DO NOT RUN ANY PROGRAMS UNTIL COMBOFIX HAS FINISHED' reGARDS, hb
Hi henrbowers

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    C:\Documents and Settings\All Users\Application Data\2a88372pk28
    C:\Documents and Settings\All Users\Application Data\ytl.exe
    C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\ukp.exe
    C:\Documents and Settings\All Users\Application Data\taf.exe
    C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\rsp.exe
    C:\Documents and Settings\All Users\Application Data\inj.exe
    C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\hch.exe
    C:\Documents and Settings\All Users\Application Data\gbk.exe
    C:\Documents and Settings\Steve Bowers\Local Settings\Application Data\dwd.exe
    C:\Documents and Settings\All Users\Application Data\btm.exe:Commands
    
    [createrestorepoint]
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )

=====================
NEXT

Please try and Rerun Combofix again.


Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. Combofix log
4. How is the computer behaving?
OTL Log

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@checkpoint.com/FFApi\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\SITEguard deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully.
Starting removal of ActiveX control Microsoft XML Parser for Java Reg Error: Value error.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java Reg Error: Value error.\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java Reg Error: Value error.\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ab979687-d2d0-11de-a38e-00173f99e22e}\ not found.
File I:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found.
File K:\Autorun.exe not found.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET721.tmp deleted successfully.
C:\WINDOWS\System32\SET722.tmp deleted successfully.
C:\WINDOWS\System32\SET723.tmp deleted successfully.
C:\WINDOWS\System32\SET724.tmp deleted successfully.
C:\WINDOWS\System32\SET725.tmp deleted successfully.
C:\WINDOWS\System32\SET726.tmp deleted successfully.
C:\WINDOWS\System32\SET727.tmp deleted successfully.

Combofix Log -

ComboFix 11-11-10.03 - Steve Bowers 10/11/2011 22:46:12.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.460 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\TSOC.LOG
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\DirectCDUserNameD.txt
c:\documents and settings\All Users\Application Data\gbk.exe
c:\documents and settings\Steve Bowers\Application Data\Adobe\usanaz.exe
c:\documents and settings\Steve Bowers\Local Settings\Application Data\dwd.exe
c:\documents and settings\Steve Bowers\Local Settings\Application Data\hch.exe
c:\documents and settings\Steve Bowers\Local Settings\Application Data\rsp.exe
c:\documents and settings\Steve Bowers\Local Settings\Application Data\ukp.exe
c:\program files\Internet Explorer\SET714.tmp
c:\program files\Internet Explorer\SET715.tmp
c:\program files\Internet Explorer\SET717.tmp
c:\windows\system32\Wnccdctl.log
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_ISEXENG
——-\Legacy_USNJSVC
——-\Service_Driver
——-\Service_usnjsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
.
.
2011-11-09 19:03 . 2011-11-09 19:10 ——– d—–w- c:\windows\ie8updates
2011-11-09 18:06 . 2011-06-24 14:10 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-11-09 18:06 . 2011-08-22 23:48 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2011-11-09 18:06 . 2011-08-22 23:48 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-09 18:06 . 2011-08-22 23:48 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-09 18:01 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2011-11-06 21:36 . 2011-11-06 21:36 ——– d—–w- C:\_OTL
2011-10-27 20:38 . 2011-10-27 20:38 388096 —-a-r- c:\documents and settings\Steve Bowers\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-18 16:30 . 2011-10-18 16:30 ——– d—–w- c:\documents and settings\Jamie Bowers.D3538J0J\Application Data\Apple Computer
2011-10-18 16:30 . 2011-10-18 16:30 ——– d—–w- c:\documents and settings\Jamie Bowers.D3538J0J\Local Settings\Application Data\Apple Computer
2011-10-17 07:29 . 2011-10-17 07:29 ——– d-sh–w- c:\documents and settings\Steve Bowers\PrivacIE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2001-08-18 06:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-26 11:41 . 2008-07-29 18:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 11:41 . 2001-08-18 06:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 11:41 . 2001-08-18 06:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12 . 2002-09-23 15:10 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2002-02-20 17:46 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2002-03-05 07:56 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2001-08-18 06:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2001-08-18 06:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-08-18 17:50 . 2011-08-18 17:50 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-17 13:49 . 2001-08-18 06:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-11-10 22:05 . 2011-06-17 21:23 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-24 94208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2011-10-17 2042208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Adobe Acrobat Speed Launcher"="g:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-01-30 36760]
"Acrobat Assistant 8.0"="g:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-01-30 821144]
"GrooveMonitor"="g:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Steve Bowers\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - g:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDREG~1\DVDShell.dll" [2004-10-09 49152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-05 17:25 11952 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-11-13 21:48 323392 —-a-w- c:\program files\DNA\btdna.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 —-a-w- g:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVD43]
2005-02-17 22:44 784896 —-a-w- c:\program files\dvd43\DVD43_Tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 11:44 31072 —-a-w- g:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 20:21 141600 —-a-w- g:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
2000-07-13 19:00 311350 -c—-w- c:\program files\Microsoft Works\wkssb.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2000-07-13 19:00 28739 -c—-w- c:\program files\Microsoft Works\WkDetect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 10:50 155648 -c–a-w- c:\windows\SYSTEM32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-12-05 01:41 1626112 —-a-w- c:\windows\SYSTEM32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-06-03 11:38 49152 —-a-w- c:\program files\ScanSoft\OmniPageSE\opware32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2006-06-05 14:06 188416 —-a-w- g:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 01:54 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-09-11 17:26 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
2000-07-13 19:00 24576 ——w- c:\program files\Microsoft Works\wkfud.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"g:\\Program Files\\PPLive\\PPLive.exe"=
"g:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"g:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"g:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"g:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"g:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R0 ElbyVCD;ElbyVCD;c:\windows\System32\DRIVERS\ElbyVCD.sys [x]
R2 CX88XBAR;TV Card(10BIT) 23881 Crossbar;c:\windows\system32\drivers\CX88XBAR.sys [2003-11-06 19456]
R3 TVProDrv;TVProDrv;c:\progra~1\TVApp\TVPro\TVProDrv.sys [x]
R4 a347bus;a347bus;c:\windows\system32\DRIVERS\a347bus.sys [2004-08-23 158720]
R4 a347scsi;a347scsi;c:\windows\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-03 691696]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-04-29 12552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-05 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-29 108552]
S1 kbfilter;Keyboard Filter Driver; [x]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-08-05 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-08-05 297752]
S3 Dvd43;Dvd43;c:\windows\system32\DRIVERS\Dvd43.sys [2010-08-09 35296]
S3 Pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\Pcouffin.sys [2008-11-14 47360]
S3 RegKill;RegKill;c:\windows\system32\Drivers\RegKill.sys [2002-03-10 6144]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.msn.co.uk/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - g:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{94FE915A-DB7C-438A-AA7C-21BCDC77C9FD}: NameServer = 192.168.0.1
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Steve Bowers\Application Data\Mozilla\Firefox\Profiles\7am3izck.Steve B\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2411669&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - TenchisTV Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://sn131w.snt131.mail.live.com/default.aspx?wa=wsignin1.0
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2411669&q=
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-10 23:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2856520603-4282951562-813958858-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-11-10 23:14:56
ComboFix-quarantined-files.txt 2011-11-10 23:14
.
Pre-Run: 10,453,422,080 bytes free
Post-Run: 10,606,071,808 bytes free
.
- - End Of File - - C80A10676E699A61456356AB0C259B5D


PC running ok, but combofix didn't like avg. It kept asking for it to be shut down when I had already done it?

Regards

HB
Hi henrbowers,

You posted the wrong OTL log I need to see the one from post #12, you can find it here see below.

A copy of an OTL fix log is saved in a text file at

:\_OTL\MovedFiles
in most cases this will be C:\_OTL\MovedFiles
=================
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

=====================================
NEXT

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.
=================================
Please include in your next reply:
1. Any problem executing the instructions?
2. OTL log
3. MBAM log
4. ESET log
4. How is the computer behaving?
Hi PB OTL Log All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== File eaterestorepoint] not found. File rity] not found. File ptytemp] not found. File boot] not found. OTL by OldTimer - Version 3.2.31.0 log created on 11102011_221437 Files\Folders moved on Reboot… Registry entries deleted on Reboot… MBAM Log Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8142 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/11/2011 22:02:15 mbam-log-2011-11-11 (22-02-15).txt Scan type: Quick scan Objects scanned: 233481 Time elapsed: 14 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\program files\windows media player\KeyMaker.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully. ESET Log ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=6c6f7c6ff944634d89c7bb8a4ea193b5 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-11-12 05:57:10 # local_time=2011-11-12 05:57:10 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 1302828 1302828 0 0 # compatibility_mode=1024 16777175 100 0 106990158 106990158 0 0 # compatibility_mode=8192 67108863 100 0 4029 4029 0 0 # scanned=162326 # found=24 # cleaned=0 # scan_time=26720 C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP362\A0161690.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161698.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161700.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161701.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161702.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161703.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161704.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161705.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161706.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161707.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161708.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161709.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161710.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161711.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161712.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161713.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP363\A0161714.exe a variant of Win32/Kryptik.PYS trojan (unable to clean) 00000000000000000000000000000000 I G:\My Documents\Downloads\Incomplete\Android Mega Pack 2010\Android Mega Pack\Apps\flashrec.apk Linux/Exploit.Lotoor.AG trojan (unable to clean) 00000000000000000000000000000000 I G:\My Documents\Downloads\Incomplete\ZoneAlarm Pro 10.0.240.000\ZoneAlarm Pro 10.0.240.000\Keygen\keygen.exe a variant of Win32/Keygen.BJ application (unable to clean) 00000000000000000000000000000000 I I:\Downloads\Games\DS\Apps\R4\imgview0.6 for R4\misc\??IPK?????????.exe probably a variant of Win32/Agent.KYYNECF trojan (unable to clean) 00000000000000000000000000000000 I I:\Downloads\Software\cnet_free-wma-mp3-converter_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I I:\Downloads\Software\AVG Anti-Virus Professional 9.0 Build 663a1706 + Keygen [RH]\AVGAV.9.0.663a1706_[RH].rar probably a variant of Win32/Agent.GQQTOSM trojan (unable to clean) 00000000000000000000000000000000 I PC OK Regards, HB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI