This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.exe virus

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, i discovered my computer started to lag a few days ago and when i went to the windows task manager, i found out that there was this PING.exe that was causing it to lag. so i Google on it and came to this forum. i hope you would help me solve my problem, thanks! and there were times when another file lsmass.exe also start to eat up mu cpu space:(
Hi there, first I will need a look at your system

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply

[external image: Posted Image]

THEN

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs
Hi, here is the log from the first file! aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-20 01:43:03 —————————– 01:43:03.391 OS Version: Windows 6.1.7601 Service Pack 1 01:43:03.391 Number of processors: 4 586 0x403 01:43:03.392 ComputerName: HENRY-PC UserName: Henry 01:43:20.607 Initialize success 01:43:44.225 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006a 01:43:44.235 Disk 0 Vendor: ST350041 CC38 Size: 476940MB BusType: 3 01:43:46.248 Disk 0 MBR read successfully 01:43:46.248 Disk 0 MBR scan 01:43:46.248 Disk 0 Windows 7 default MBR code 01:43:46.248 Disk 0 scanning sectors +976769024 01:43:46.318 Disk 0 scanning C:\Windows\system32\drivers 01:43:53.059 Service scanning 01:43:53.837 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32 01:43:54.427 Modules scanning 01:43:55.738 Module: C:\Windows\system32\DRIVERS\tdx.sys **SUSPICIOUS** 01:44:03.979 Disk 0 trace - called modules: 01:44:03.989 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86eaaf10]<< 01:44:03.989 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86a91030] 01:44:03.999 3 CLASSPNP.SYS[8bbba59e] -> nt!IofCallDriver -> [0x86e584d8] 01:44:04.009 \Driver\00000463[0x86e58030] -> IRP_MJ_CREATE -> 0x86eaaf10 01:44:04.019 Scan finished successfully 01:45:12.433 Disk 0 MBR has been saved successfully to "C:\Users\Henry\Desktop\MBR.dat" 01:45:12.433 The log file has been saved successfully to "C:\Users\Henry\Desktop\aswMBR.txt"
OTL logfile created on: 11/20/2011 1:50:54 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.56% Memory free
6.00 Gb Paging File | 4.04 Gb Available in Paging File | 67.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 126.07 Gb Free Space | 48.82% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
PRC - [2011/11/18 21:11:13 | 000,196,608 | —- | M] (Lenovo Corporation) – C:\Windows\System32\svdhalp.exe
PRC - [2011/11/17 20:15:12 | 000,031,744 | -H– | M] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
PRC - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe
PRC - [2011/09/02 09:56:36 | 001,479,408 | —- | M] (Funshion Online Technologies Ltd.) – C:\Program Files\Funshion Online\Funshion\FunshionService.exe
PRC - [2011/08/09 16:56:40 | 000,417,112 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/08/09 16:40:34 | 000,763,224 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/06/24 12:22:20 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
PRC - [2011/05/26 04:07:14 | 024,176,560 | —- | M] (Dropbox, Inc.) – C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
PRC - [2011/02/10 22:00:24 | 000,116,752 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2011/02/10 21:57:40 | 001,035,512 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
PRC - [2010/11/20 20:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2010/08/08 18:35:32 | 000,138,640 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
PRC - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010/03/05 10:15:04 | 000,411,864 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2010/02/10 14:52:20 | 001,713,152 | R— | M] (VIA) – C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2010/02/03 16:17:18 | 005,756,544 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
PRC - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
PRC - [2009/11/24 15:25:28 | 001,874,432 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\Turbo Key\TurboKey.exe
PRC - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) – C:\ASUS.SYS\config\DVMExportService.exe
PRC - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
PRC - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2009/07/14 09:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PING.EXE
PRC - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/10/13 23:31:30 | 001,051,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\1049a76b3de293df726d380932215c91\System.Management.ni.dll
MOD - [2011/10/13 23:17:16 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/13 23:17:14 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/13 23:17:11 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/13 23:17:05 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/09/02 10:04:04 | 000,230,128 | —- | M] () – C:\Program Files\Funshion Online\Funshion\fptassrv.dll
MOD - [2011/09/02 10:04:02 | 000,140,016 | —- | M] () – C:\Program Files\Funshion Online\Funshion\fpsrv.dll
MOD - [2011/09/02 09:54:18 | 000,160,496 | —- | M] () – C:\Program Files\Funshion Online\Funshion\GetMACAddress.dll
MOD - [2011/09/02 09:54:02 | 000,299,760 | —- | M] () – C:\Program Files\Funshion Online\Funshion\Dump.dll
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2010/08/10 00:01:06 | 000,067,872 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/08/08 18:35:32 | 000,057,344 | —- | M] () – C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll
MOD - [2010/08/08 18:35:32 | 000,049,152 | —- | M] () – C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll
MOD - [2009/11/03 11:11:50 | 047,628,288 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
MOD - [2009/09/30 11:33:08 | 000,024,576 | R— | M] () – C:\Windows\System32\AsIO.dll
MOD - [2009/07/31 21:39:08 | 000,503,202 | —- | M] () – C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009/05/07 16:53:18 | 000,106,496 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009/05/07 16:50:46 | 000,073,728 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2009/04/29 14:24:44 | 000,253,952 | —- | M] () – C:\Program Files\ASUS\Turbo Key\pngio.dll
MOD - [2009/04/29 14:24:44 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\Turbo Key\AiNap.dll
MOD - [2009/04/29 14:24:44 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\Turbo Key\vvc.dll
MOD - [2009/03/25 16:53:14 | 000,053,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AsSpindownTimeout.dll
MOD - [2009/03/19 22:35:52 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
MOD - [2009/03/19 22:35:50 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\vvc.dll
MOD - [2009/01/15 14:55:10 | 000,565,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
MOD - [2008/02/14 13:57:00 | 000,094,208 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll
MOD - [1998/10/31 04:55:56 | 000,005,120 | —- | M] () – C:\Program Files\Vtune\TBMANAGE.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () [Auto | Running] – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe – (ONETWO)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Running] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

Hosts file not found
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (E5C717B8-A0FF-B310-A1A9-466308D906EA Class) - {E5C717B8-A0FF-B310-A1A9-466308D906EA} - C:\Program Files\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll ()
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe (Funshion Online Technologies Ltd.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [Windows-Audio Driver] C:\ProgramData\wscntfy.exe (Microsoft)
O4 - HKU\.DEFAULT..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
O4 - HKU\S-1-5-18..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [EPSON K200 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIG3P.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe (Funshion Online Technologies Ltd.)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows-Network Component = C:\Program Files\Common Files\lsmass.exe (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (svdhalp.exe) -C:\Windows\System32\svdhalp.exe (Lenovo Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell\AutoRun\command - "" = F:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 01:42:42 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
[2011/11/20 01:42:30 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Henry\Desktop\aswMBR.exe
[2011/11/20 01:13:24 | 000,031,744 | -H– | C] (Microsoft) – C:\ProgramData\wscntfy.exe
[2011/11/18 02:20:41 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Bowling For Soup - Fishin' For Woos MP3 VBR BLOWA TLS
[2011/11/17 20:15:39 | 000,031,744 | -H– | C] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/13 00:35:10 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org The.Big.Bang.Theory.S05E09.720p.HDTV.x264-ORENJI[ss]
[2011/11/11 23:02:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Secret Circle S01E09 HDTV By Johnnyboy187
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/11 01:07:22 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Christian Classics Library (re-seeding)
[2011/11/07 21:07:39 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Tutorials
[2011/11/06 00:06:03 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Computing Tutorial Solutions
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/04 01:11:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Football Manager 2012.v12.0.3 Update CrackFix-SKIDROW
[2011/11/02 00:28:28 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org Football.Manager.2012-SKIDROW[ss]
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 01:46:40 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 01:45:12 | 000,000,512 | —- | M] () – C:\Users\Henry\Desktop\MBR.dat
[2011/11/20 01:44:43 | 000,003,554 | —- | M] () – C:\Users\Henry\funshion.ini
[2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
[2011/11/20 01:42:29 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Henry\Desktop\aswMBR.exe
[2011/11/20 01:18:22 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 01:11:01 | 000,000,000 | —- | M] () – C:\Windows\System32\FunshionService.timestamp
[2011/11/20 01:07:49 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 01:07:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 01:07:36 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/19 15:15:35 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/19 15:15:35 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/19 15:07:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/19 09:57:47 | 000,002,397 | —- | M] () – C:\Users\Henry\Desktop\Google Chrome.lnk
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 21:11:13 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv
[2011/11/18 20:54:28 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/18 03:16:32 | 009,291,190 | —- | M] () – C:\Users\Henry\Desktop\Kelly Clarkson - Mr Know It All.mp3
[2011/11/18 03:00:06 | 009,629,736 | —- | M] () – C:\Users\Henry\Desktop\Dappy - No Regrets.mp3
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 01:38:46 | 002,041,806 | —- | M] () – C:\Users\Henry\Desktop\One Way Drive - Intercept.mp3
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/16 23:05:47 | 004,013,230 | —- | M] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/15 00:57:48 | 000,048,045 | —- | M] () – C:\Users\Henry\Desktop\Nov 14 - Nov 20.pdf
[2011/11/11 01:14:01 | 000,001,179 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[2011/11/04 11:32:38 | 000,000,937 | —- | M] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/04 10:19:48 | 000,000,017 | —- | M] () – C:\Windows\keys.ini
[2011/11/01 12:35:21 | 000,044,475 | —- | M] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 01:45:12 | 000,000,512 | —- | C] () – C:\Users\Henry\Desktop\MBR.dat
[2011/11/18 21:11:13 | 000,000,017 | —- | C] () – C:\Windows\syskey2i.drv
[2011/11/18 03:20:34 | 009,629,736 | —- | C] () – C:\Users\Henry\Desktop\Dappy - No Regrets.mp3
[2011/11/18 03:20:34 | 009,291,190 | —- | C] () – C:\Users\Henry\Desktop\Kelly Clarkson - Mr Know It All.mp3
[2011/11/18 01:38:32 | 002,041,806 | —- | C] () – C:\Users\Henry\Desktop\One Way Drive - Intercept.mp3
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/16 23:05:26 | 004,013,230 | —- | C] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/15 00:57:48 | 000,048,045 | —- | C] () – C:\Users\Henry\Desktop\Nov 14 - Nov 20.pdf
[2011/11/11 01:14:01 | 000,001,179 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/11/04 10:19:48 | 000,000,017 | —- | C] () – C:\Windows\keys.ini
[2011/11/04 10:08:01 | 000,000,937 | —- | C] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/01 12:35:23 | 000,044,475 | —- | C] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 01:16:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/19 15:15:10 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/08/07 23:03:42 | 000,000,384 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2011/02/26 13:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 09:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 13:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 13:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 13:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 20:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 13:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 13:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 14:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 09:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/14 09:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 20:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 20:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 09:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 14:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 13:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 20:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 20:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 09:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Files - Unicode (All) ==========
[2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >
OTL logfile created on: 11/20/2011 1:50:54 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.56% Memory free
6.00 Gb Paging File | 4.04 Gb Available in Paging File | 67.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 126.07 Gb Free Space | 48.82% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
PRC - [2011/11/18 21:11:13 | 000,196,608 | —- | M] (Lenovo Corporation) – C:\Windows\System32\svdhalp.exe
PRC - [2011/11/17 20:15:12 | 000,031,744 | -H– | M] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
PRC - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe
PRC - [2011/09/02 09:56:36 | 001,479,408 | —- | M] (Funshion Online Technologies Ltd.) – C:\Program Files\Funshion Online\Funshion\FunshionService.exe
PRC - [2011/08/09 16:56:40 | 000,417,112 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/08/09 16:40:34 | 000,763,224 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/06/24 12:22:20 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
PRC - [2011/05/26 04:07:14 | 024,176,560 | —- | M] (Dropbox, Inc.) – C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
PRC - [2011/02/10 22:00:24 | 000,116,752 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2011/02/10 21:57:40 | 001,035,512 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiSeAgnt.exe
PRC - [2010/11/20 20:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2010/08/08 18:35:32 | 000,138,640 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
PRC - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010/03/05 10:15:04 | 000,411,864 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2010/02/10 14:52:20 | 001,713,152 | R— | M] (VIA) – C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2010/02/03 16:17:18 | 005,756,544 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
PRC - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
PRC - [2009/11/24 15:25:28 | 001,874,432 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\Turbo Key\TurboKey.exe
PRC - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) – C:\ASUS.SYS\config\DVMExportService.exe
PRC - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
PRC - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2009/07/14 09:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PING.EXE
PRC - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/10/13 23:31:30 | 001,051,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\1049a76b3de293df726d380932215c91\System.Management.ni.dll
MOD - [2011/10/13 23:17:16 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/13 23:17:14 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/13 23:17:11 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/13 23:17:05 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/09/02 10:04:04 | 000,230,128 | —- | M] () – C:\Program Files\Funshion Online\Funshion\fptassrv.dll
MOD - [2011/09/02 10:04:02 | 000,140,016 | —- | M] () – C:\Program Files\Funshion Online\Funshion\fpsrv.dll
MOD - [2011/09/02 09:54:18 | 000,160,496 | —- | M] () – C:\Program Files\Funshion Online\Funshion\GetMACAddress.dll
MOD - [2011/09/02 09:54:02 | 000,299,760 | —- | M] () – C:\Program Files\Funshion Online\Funshion\Dump.dll
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2010/08/10 00:01:06 | 000,067,872 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/08/08 18:35:32 | 000,057,344 | —- | M] () – C:\Program Files\Trend Micro\AMSP\boost_date_time-vc80-mt-1_36.dll
MOD - [2010/08/08 18:35:32 | 000,049,152 | —- | M] () – C:\Program Files\Trend Micro\AMSP\boost_thread-vc80-mt-1_36.dll
MOD - [2009/11/03 11:11:50 | 047,628,288 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
MOD - [2009/09/30 11:33:08 | 000,024,576 | R— | M] () – C:\Windows\System32\AsIO.dll
MOD - [2009/07/31 21:39:08 | 000,503,202 | —- | M] () – C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009/05/07 16:53:18 | 000,106,496 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009/05/07 16:50:46 | 000,073,728 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2009/04/29 14:24:44 | 000,253,952 | —- | M] () – C:\Program Files\ASUS\Turbo Key\pngio.dll
MOD - [2009/04/29 14:24:44 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\Turbo Key\AiNap.dll
MOD - [2009/04/29 14:24:44 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\Turbo Key\vvc.dll
MOD - [2009/03/25 16:53:14 | 000,053,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AsSpindownTimeout.dll
MOD - [2009/03/19 22:35:52 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
MOD - [2009/03/19 22:35:50 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\vvc.dll
MOD - [2009/01/15 14:55:10 | 000,565,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
MOD - [2008/02/14 13:57:00 | 000,094,208 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll
MOD - [1998/10/31 04:55:56 | 000,005,120 | —- | M] () – C:\Program Files\Vtune\TBMANAGE.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () [Auto | Running] – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe – (ONETWO)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Running] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

Hosts file not found
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (E5C717B8-A0FF-B310-A1A9-466308D906EA Class) - {E5C717B8-A0FF-B310-A1A9-466308D906EA} - C:\Program Files\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll ()
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe (Funshion Online Technologies Ltd.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [Windows-Audio Driver] C:\ProgramData\wscntfy.exe (Microsoft)
O4 - HKU\.DEFAULT..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
O4 - HKU\S-1-5-18..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [EPSON K200 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIG3P.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe (Funshion Online Technologies Ltd.)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows-Network Component = C:\Program Files\Common Files\lsmass.exe (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (svdhalp.exe) -C:\Windows\System32\svdhalp.exe (Lenovo Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell\AutoRun\command - "" = F:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 01:42:42 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
[2011/11/20 01:42:30 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Henry\Desktop\aswMBR.exe
[2011/11/20 01:13:24 | 000,031,744 | -H– | C] (Microsoft) – C:\ProgramData\wscntfy.exe
[2011/11/18 02:20:41 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Bowling For Soup - Fishin' For Woos MP3 VBR BLOWA TLS
[2011/11/17 20:15:39 | 000,031,744 | -H– | C] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/13 00:35:10 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org The.Big.Bang.Theory.S05E09.720p.HDTV.x264-ORENJI[ss]
[2011/11/11 23:02:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Secret Circle S01E09 HDTV By Johnnyboy187
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/11 01:07:22 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Christian Classics Library (re-seeding)
[2011/11/07 21:07:39 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Tutorials
[2011/11/06 00:06:03 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Computing Tutorial Solutions
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/04 01:11:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Football Manager 2012.v12.0.3 Update CrackFix-SKIDROW
[2011/11/02 00:28:28 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org Football.Manager.2012-SKIDROW[ss]
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 01:46:40 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 01:45:12 | 000,000,512 | —- | M] () – C:\Users\Henry\Desktop\MBR.dat
[2011/11/20 01:44:43 | 000,003,554 | —- | M] () – C:\Users\Henry\funshion.ini
[2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\OTL.exe
[2011/11/20 01:42:29 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Henry\Desktop\aswMBR.exe
[2011/11/20 01:18:22 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 01:11:01 | 000,000,000 | —- | M] () – C:\Windows\System32\FunshionService.timestamp
[2011/11/20 01:07:49 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 01:07:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 01:07:36 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/19 15:15:35 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/19 15:15:35 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/19 15:07:04 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/19 09:57:47 | 000,002,397 | —- | M] () – C:\Users\Henry\Desktop\Google Chrome.lnk
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 21:11:13 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv
[2011/11/18 20:54:28 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/18 03:16:32 | 009,291,190 | —- | M] () – C:\Users\Henry\Desktop\Kelly Clarkson - Mr Know It All.mp3
[2011/11/18 03:00:06 | 009,629,736 | —- | M] () – C:\Users\Henry\Desktop\Dappy - No Regrets.mp3
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 01:38:46 | 002,041,806 | —- | M] () – C:\Users\Henry\Desktop\One Way Drive - Intercept.mp3
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/16 23:05:47 | 004,013,230 | —- | M] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/15 00:57:48 | 000,048,045 | —- | M] () – C:\Users\Henry\Desktop\Nov 14 - Nov 20.pdf
[2011/11/11 01:14:01 | 000,001,179 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[2011/11/04 11:32:38 | 000,000,937 | —- | M] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/04 10:19:48 | 000,000,017 | —- | M] () – C:\Windows\keys.ini
[2011/11/01 12:35:21 | 000,044,475 | —- | M] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 01:45:12 | 000,000,512 | —- | C] () – C:\Users\Henry\Desktop\MBR.dat
[2011/11/18 21:11:13 | 000,000,017 | —- | C] () – C:\Windows\syskey2i.drv
[2011/11/18 03:20:34 | 009,629,736 | —- | C] () – C:\Users\Henry\Desktop\Dappy - No Regrets.mp3
[2011/11/18 03:20:34 | 009,291,190 | —- | C] () – C:\Users\Henry\Desktop\Kelly Clarkson - Mr Know It All.mp3
[2011/11/18 01:38:32 | 002,041,806 | —- | C] () – C:\Users\Henry\Desktop\One Way Drive - Intercept.mp3
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/16 23:05:26 | 004,013,230 | —- | C] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/15 00:57:48 | 000,048,045 | —- | C] () – C:\Users\Henry\Desktop\Nov 14 - Nov 20.pdf
[2011/11/11 01:14:01 | 000,001,179 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/11/04 10:19:48 | 000,000,017 | —- | C] () – C:\Windows\keys.ini
[2011/11/04 10:08:01 | 000,000,937 | —- | C] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/01 12:35:23 | 000,044,475 | —- | C] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 01:16:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/19 15:15:10 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/08/07 23:03:42 | 000,000,384 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2011/02/26 13:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/14 09:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 13:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 13:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 13:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 20:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 13:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 13:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 14:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 09:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/14 09:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 20:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 20:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/14 09:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 14:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 13:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 20:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 20:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/14 09:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Files - Unicode (All) ==========
[2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >
OTL Extras logfile created on: 11/20/2011 1:50:54 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.56% Memory free
6.00 Gb Paging File | 4.04 Gb Available in Paging File | 67.34% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 126.07 Gb Free Space | 48.82% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{46F8CF66-AB83-38A7-99B2-A5BE507EE472}" = Microsoft Visual C++ 2010 Express - ENU
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{99AD9D6D-A456-49EE-8360-F22EE7AA1272}" = Express Gate
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro Titanium Maximum Security
"{ABBD4BA9-6703-40D2-AB1E-5BB1F7DB49A4}" = Trend Micro™ Titanium™ Maximum Security
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B83F7FA5-3191-4E39-A1F2-8A9038BD0B04}" = Turbo Key
"{BA88EE67-8974-459D-A1DB-C8281D9AC6F6}" = Browser Configuration Utility
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CD232781-26CA-4E18-BC70-4343A2F0D583}" = Microsoft IntelliPoint 8.0
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Advanced SystemCare 4_is1" = Advanced SystemCare 4
"BlackShot" = BlackShot Á¦°Å
"CCleaner" = CCleaner
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON K200 Series" = EPSON K200 Series Printer Uninstall
"EPSON K200 Series Manual" = EPSON K200 Series Manual
"EPSON K200 Series Network Guide" = EPSON K200 Series Network Guide
"EPSON Scanner" = EPSON Scan
"Football Manager 2011 Russian" = Football Manager 2011 Russian
"Football Manager 2012_is1" = Football Manager 2012
"Funshion" = Funshion
"Garena" = Garena 2010
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}" = NVIDIA ForceWare Network Access Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.3.0
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Visual C++ 2010 Express - ENU" = Microsoft Visual C++ 2010 Express - ENU
"MpcStar" = MpcStar 5.3
"MsJavaVM" = Microsoft VM for Java
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"SopCast" = SopCast 3.2.9
"Steam App 10" = Counter-Strike
"Steam App 80" = Counter-Strike: Condition Zero
"TVAnts 1.0" = TVAnts 1.0
"TVUPlayer" = TVUPlayer [removed]
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.18
"VLC media player" = VLC media player 1.1.11
"vShare" = vShare Plugin
"Vtune_is1" = Vtune 7.6
"Warcraft III" = Warcraft III
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YU2010_is1" = Your Uninstaller! 2010

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/18/2011 5:34:41 PM | Computer Name = Henry-PC | Source = SideBySide | ID = 16842811
Description = Activation context generation failed for "c:\program files\microsoft\search
enhancement pack\search helper\searchhelper.dll".Error in manifest or policy file
"c:\program files\microsoft\search enhancement pack\search helper\searchhelper.dll"
on line 2. Invalid Xml syntax.

Error - 11/18/2011 6:11:13 PM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/18/2011 9:58:26 PM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/18/2011 10:09:31 PM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/18/2011 11:01:43 PM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/19/2011 12:08:21 AM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/19/2011 1:00:37 AM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/19/2011 2:01:16 AM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/19/2011 3:11:41 AM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 11/19/2011 1:10:49 PM | Computer Name = Henry-PC | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ OSession Events ]
Error - 5/21/2011 12:03:06 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/21/2011 12:03:44 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/21/2011 12:03:59 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/21/2011 12:04:15 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 5/27/2011 1:04:03 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 3
seconds with 0 seconds of active time. This session ended with a crash.

Error - 6/11/2011 12:46:43 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/6/2011 1:55:45 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 9/13/2011 1:02:56 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 10/23/2011 8:35:11 PM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 4 seconds with 0 seconds of active time. This session ended with a crash.

Error - 10/27/2011 1:30:55 AM | Computer Name = Henry-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 5/22/2011 1:14:20 PM | Computer Name = Henry-PC | Source = DCOM | ID = 10010
Description =

Error - 5/23/2011 7:11:50 AM | Computer Name = Henry-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR3.

Error - 5/23/2011 7:11:51 AM | Computer Name = Henry-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR3.

Error - 5/23/2011 7:11:51 AM | Computer Name = Henry-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR3.

Error - 5/23/2011 7:11:52 AM | Computer Name = Henry-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR3.

Error - 5/23/2011 2:36:34 PM | Computer Name = Henry-PC | Source = DCOM | ID = 10010
Description =

Error - 5/27/2011 8:25:11 PM | Computer Name = Henry-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 3:30:54 AM on ?5/?28/?2011 was unexpected.

Error - 6/2/2011 1:53:13 PM | Computer Name = Henry-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
Client Service service to connect.

Error - 6/2/2011 1:53:13 PM | Computer Name = Henry-PC | Source = Service Control Manager | ID = 7000
Description = The Steam Client Service service failed to start due to the following
error: %%1053

Error - 6/9/2011 12:47:01 PM | Computer Name = Henry-PC | Source = DCOM | ID = 10010
Description =


< End of report >
Hi there you have some infected system files - probably as a result of using cracks, a very good vehicle for malware

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O2 - BHO: (E5C717B8-A0FF-B310-A1A9-466308D906EA Class) - {E5C717B8-A0FF-B310-A1A9-466308D906EA} - C:\Program Files\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll ()
    O4 - HKLM..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe (Funshion Online Technologies Ltd.)
    O4 - HKU\.DEFAULT..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
    O4 - HKU\S-1-5-18..\Run: [Google Update] C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe ()
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows-Network Component = C:\Program Files\Common Files\lsmass.exe (Microsoft)
    [2011/11/17 20:15:39 | 000,031,744 | -H– | C] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
    [2011/11/20 01:44:43 | 000,003,554 | —- | M] () – C:\Users\Henry\funshion.ini
    [2011/11/20 01:18:22 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
    [2011/11/20 01:11:01 | 000,000,000 | —- | M] () – C:\Windows\System32\FunshionService.timestamp
    [2011/11/18 21:11:13 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv

    :Files
    ipconfig /flushdns /c
    C:\Program Files\Funshion Online

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5C717B8-A0FF-B310-A1A9-466308D906EA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E5C717B8-A0FF-B310-A1A9-466308D906EA}\ deleted successfully.
C:\Program Files\Funshion Online\Funshion\FunshionAddr\funshionAddr.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Funshion deleted successfully.
C:\Program Files\Funshion Online\Funshion\Funshion.exe moved successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe moved successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update not found.
File C:\Windows\System32\config\systemprofile\AppData\Local\Google\Update\gupdate.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\Windows-Network Component deleted successfully.
C:\Program Files\Common Files\lsmass.exe moved successfully.
File C:\Program Files\Common Files\lsmass.exe not found.
C:\Users\Henry\funshion.ini moved successfully.
C:\dvmexp.idx moved successfully.
C:\Windows\System32\FunshionService.timestamp moved successfully.
C:\Windows\syskey2i.drv moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Henry\Desktop\Virus scan file\cmd.bat deleted successfully.
C:\Users\Henry\Desktop\Virus scan file\cmd.txt deleted successfully.
C:\Program Files\Funshion Online\Funshion\skin folder moved successfully.
C:\Program Files\Funshion Online\Funshion\icon folder moved successfully.
C:\Program Files\Funshion Online\Funshion\FunshionAddr folder moved successfully.
C:\Program Files\Funshion Online\Funshion\control folder moved successfully.
C:\Program Files\Funshion Online\Funshion folder moved successfully.
C:\Program Files\Funshion Online folder moved successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Henry
->Temp folder emptied: 53701919 bytes
->Temporary Internet Files folder emptied: 8830416 bytes
->Java cache emptied: 91545 bytes
->Google Chrome cache emptied: 386279243 bytes
->Flash cache emptied: 46276 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1385688 bytes
RecycleBin emptied: 8253173600 bytes

Total Files Cleaned = 8,300.00 mb



OTL by OldTimer - Version 3.2.31.0 log created on 11202011_033154

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
OTL logfile created on: 11/20/2011 3:37:22 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 57.02% Memory free
6.00 Gb Paging File | 4.55 Gb Available in Paging File | 75.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 132.71 Gb Free Space | 51.39% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\Virus scan file\OTL.exe
PRC - [2011/11/18 21:11:13 | 000,196,608 | —- | M] (Lenovo Corporation) – C:\Windows\System32\svdhalp.exe
PRC - [2011/11/17 20:15:12 | 000,031,744 | -H– | M] (Microsoft) – C:\ProgramData\wscntfy.exe
PRC - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe
PRC - [2011/08/09 16:56:40 | 000,417,112 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/08/09 16:40:34 | 000,763,224 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/08/02 14:27:03 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files\Steam\Steam.exe
PRC - [2011/06/24 12:22:20 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
PRC - [2011/05/26 04:07:14 | 024,176,560 | —- | M] (Dropbox, Inc.) – C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
PRC - [2011/02/10 22:00:24 | 000,116,752 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2010/11/20 20:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2010/08/08 18:35:32 | 000,138,640 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
PRC - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010/03/05 10:15:04 | 000,411,864 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2010/02/10 14:52:20 | 001,713,152 | R— | M] (VIA) – C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2010/02/03 16:17:18 | 005,756,544 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
PRC - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
PRC - [2009/11/24 15:25:28 | 001,874,432 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\Turbo Key\TurboKey.exe
PRC - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) – C:\ASUS.SYS\config\DVMExportService.exe
PRC - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
PRC - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/11/14 01:01:53 | 014,410,024 | —- | M] () – C:\Program Files\Steam\bin\libcef.dll
MOD - [2011/11/14 01:01:53 | 000,914,216 | —- | M] () – C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011/11/14 01:01:53 | 000,194,344 | —- | M] () – C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011/11/14 01:01:53 | 000,155,432 | —- | M] () – C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011/11/14 01:01:53 | 000,091,432 | —- | M] () – C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2011/10/13 23:31:30 | 001,051,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\1049a76b3de293df726d380932215c91\System.Management.ni.dll
MOD - [2011/10/13 23:17:16 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/13 23:17:14 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/13 23:17:11 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/13 23:17:05 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2010/08/10 00:01:06 | 000,067,872 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/11/03 11:11:50 | 047,628,288 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
MOD - [2009/09/30 11:33:08 | 000,024,576 | R— | M] () – C:\Windows\System32\AsIO.dll
MOD - [2009/07/31 21:39:08 | 000,503,202 | —- | M] () – C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009/05/07 16:53:18 | 000,106,496 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009/05/07 16:50:46 | 000,073,728 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2009/04/29 14:24:44 | 000,253,952 | —- | M] () – C:\Program Files\ASUS\Turbo Key\pngio.dll
MOD - [2009/04/29 14:24:44 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\Turbo Key\AiNap.dll
MOD - [2009/04/29 14:24:44 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\Turbo Key\vvc.dll
MOD - [2009/03/19 22:35:52 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
MOD - [2009/03/19 22:35:50 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\vvc.dll
MOD - [2009/01/15 14:55:10 | 000,565,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
MOD - [2008/02/14 13:57:00 | 000,094,208 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll
MOD - [1998/10/31 04:55:56 | 000,005,120 | —- | M] () – C:\Program Files\Vtune\TBMANAGE.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () [Auto | Running] – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe – (ONETWO)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Running] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

O1 HOSTS File: ([2011/11/20 03:32:00 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [Windows-Audio Driver] C:\ProgramData\wscntfy.exe (Microsoft)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [EPSON K200 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIG3P.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe startbywindows tray File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows-Network Component = C:\Program Files\Common Files\lsmass.exe (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (svdhalp.exe) -C:\Windows\System32\svdhalp.exe (Lenovo Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell\AutoRun\command - "" = F:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 03:34:29 | 000,031,744 | -H– | C] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/20 03:30:54 | 004,302,402 | —- | C] (Swearware) – C:\Users\Henry\Desktop\ComboFix.exe
[2011/11/20 02:22:44 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Big Bang S05E10 HD
[2011/11/20 02:22:32 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\WWE
[2011/11/20 02:22:05 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Virus scan file
[2011/11/20 01:13:24 | 000,031,744 | -H– | C] (Microsoft) – C:\ProgramData\wscntfy.exe
[2011/11/18 02:20:41 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Bowling For Soup - Fishin' For Woos MP3 VBR BLOWA TLS
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 23:02:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Secret Circle S01E09 HDTV By Johnnyboy187
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/11 01:07:22 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Christian Classics Library (re-seeding)
[2011/11/07 21:07:39 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Tutorials
[2011/11/06 00:06:03 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Computing Tutorial Solutions
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/04 01:11:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Football Manager 2012.v12.0.3 Update CrackFix-SKIDROW
[2011/11/02 00:28:28 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org Football.Manager.2012-SKIDROW[ss]
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 03:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 03:34:14 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv
[2011/11/20 03:34:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 03:33:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 03:33:48 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 03:33:07 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 03:33:06 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 03:32:00 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/11/20 03:31:12 | 004,302,402 | —- | M] (Swearware) – C:\Users\Henry\Desktop\ComboFix.exe
[2011/11/20 03:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 09:57:47 | 000,002,397 | —- | M] () – C:\Users\Henry\Desktop\Google Chrome.lnk
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/16 23:05:47 | 004,013,230 | —- | M] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/11 01:14:01 | 000,001,179 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[2011/11/04 11:32:38 | 000,000,937 | —- | M] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/04 10:19:48 | 000,000,017 | —- | M] () – C:\Windows\keys.ini
[2011/11/01 12:35:21 | 000,044,475 | —- | M] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 03:34:14 | 000,000,017 | —- | C] () – C:\Windows\syskey2i.drv
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/16 23:05:26 | 004,013,230 | —- | C] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/11 01:14:01 | 000,001,179 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/11/04 10:19:48 | 000,000,017 | —- | C] () – C:\Windows\keys.ini
[2011/11/04 10:08:01 | 000,000,937 | —- | C] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/01 12:35:23 | 000,044,475 | —- | C] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/08/07 23:03:42 | 000,000,384 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >

2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

Do you recognise these

Once combofix has completed could you let me know what problems remain
OTL logfile created on: 11/20/2011 3:37:22 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.71 Gb Available Physical Memory | 57.02% Memory free
6.00 Gb Paging File | 4.55 Gb Available in Paging File | 75.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 132.71 Gb Free Space | 51.39% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\Virus scan file\OTL.exe
PRC - [2011/11/18 21:11:13 | 000,196,608 | —- | M] (Lenovo Corporation) – C:\Windows\System32\svdhalp.exe
PRC - [2011/11/17 20:15:12 | 000,031,744 | -H– | M] (Microsoft) – C:\ProgramData\wscntfy.exe
PRC - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe
PRC - [2011/08/09 16:56:40 | 000,417,112 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
PRC - [2011/08/09 16:40:34 | 000,763,224 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\PMonitor.exe
PRC - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011/08/02 14:27:03 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files\Steam\Steam.exe
PRC - [2011/06/24 12:22:20 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
PRC - [2011/05/26 04:07:14 | 024,176,560 | —- | M] (Dropbox, Inc.) – C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
PRC - [2011/02/10 22:00:24 | 000,116,752 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
PRC - [2010/11/20 20:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2010/08/08 18:35:32 | 000,138,640 | —- | M] (Trend Micro Inc.) – C:\Program Files\Trend Micro\AMSP\coreFrameworkHost.exe
PRC - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
PRC - [2010/03/05 10:15:04 | 000,411,864 | —- | M] (DeviceVM, Inc.) – C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
PRC - [2010/02/10 14:52:20 | 001,713,152 | R— | M] (VIA) – C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2010/02/03 16:17:18 | 005,756,544 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe
PRC - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
PRC - [2009/11/24 15:25:28 | 001,874,432 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files\ASUS\Turbo Key\TurboKey.exe
PRC - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) – C:\ASUS.SYS\config\DVMExportService.exe
PRC - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
PRC - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/11/14 01:01:53 | 014,410,024 | —- | M] () – C:\Program Files\Steam\bin\libcef.dll
MOD - [2011/11/14 01:01:53 | 000,914,216 | —- | M] () – C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011/11/14 01:01:53 | 000,194,344 | —- | M] () – C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011/11/14 01:01:53 | 000,155,432 | —- | M] () – C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011/11/14 01:01:53 | 000,091,432 | —- | M] () – C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2011/10/13 23:31:30 | 001,051,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\1049a76b3de293df726d380932215c91\System.Management.ni.dll
MOD - [2011/10/13 23:17:16 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/10/13 23:17:14 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/10/13 23:17:11 | 007,963,648 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/10/13 23:17:05 | 011,490,304 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 20:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2010/08/10 00:01:06 | 000,067,872 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2009/11/03 11:11:50 | 047,628,288 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\skin.dll
MOD - [2009/10/05 18:05:12 | 002,158,592 | —- | M] () – C:\Program Files\Vtune\TBPANEL.exe
MOD - [2009/09/30 11:33:08 | 000,024,576 | R— | M] () – C:\Windows\System32\AsIO.dll
MOD - [2009/07/31 21:39:08 | 000,503,202 | —- | M] () – C:\Program Files\DeviceVM\Browser Configuration Utility\sqlite3.dll
MOD - [2009/05/07 16:53:18 | 000,106,496 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2009/05/07 16:50:46 | 000,073,728 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2009/04/29 14:24:44 | 000,253,952 | —- | M] () – C:\Program Files\ASUS\Turbo Key\pngio.dll
MOD - [2009/04/29 14:24:44 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\Turbo Key\AiNap.dll
MOD - [2009/04/29 14:24:44 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\Turbo Key\vvc.dll
MOD - [2009/03/19 22:35:52 | 000,208,896 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll
MOD - [2009/03/19 22:35:50 | 000,008,704 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\vvc.dll
MOD - [2009/01/15 14:55:10 | 000,565,248 | —- | M] () – C:\Program Files\ASUS\EPU-4 Engine\pngio.dll
MOD - [2008/02/14 13:57:00 | 000,094,208 | R— | M] () – C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll
MOD - [1998/10/31 04:55:56 | 000,005,120 | —- | M] () – C:\Program Files\Vtune\TBMANAGE.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/16 16:55:32 | 000,076,288 | —- | M] () [Auto | Running] – C:\Windows\System32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe – (ONETWO)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Running] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Running] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Running] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Running] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Running] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Running] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

O1 HOSTS File: ([2011/11/20 03:32:00 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (vShare Plugin) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [Windows-Audio Driver] C:\ProgramData\wscntfy.exe (Microsoft)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [EPSON K200 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIG3P.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Funshion] C:\Program Files\Funshion Online\Funshion\Funshion.exe startbywindows tray File not found
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: Windows-Network Component = C:\Program Files\Common Files\lsmass.exe (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (svdhalp.exe) -C:\Windows\System32\svdhalp.exe (Lenovo Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{b8f7dc09-c38e-11df-8236-485b39f40826}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell - "" = AutoRun
O33 - MountPoints2\{edb04788-d734-11df-b1fd-485b39f40826}\Shell\AutoRun\command - "" = F:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 03:34:29 | 000,031,744 | -H– | C] (Microsoft) – C:\Program Files\Common Files\lsmass.exe
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/20 03:30:54 | 004,302,402 | —- | C] (Swearware) – C:\Users\Henry\Desktop\ComboFix.exe
[2011/11/20 02:22:44 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Big Bang S05E10 HD
[2011/11/20 02:22:32 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\WWE
[2011/11/20 02:22:05 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Virus scan file
[2011/11/20 01:13:24 | 000,031,744 | -H– | C] (Microsoft) – C:\ProgramData\wscntfy.exe
[2011/11/18 02:20:41 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Bowling For Soup - Fishin' For Woos MP3 VBR BLOWA TLS
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 23:02:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Secret Circle S01E09 HDTV By Johnnyboy187
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/11 01:07:22 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\The Christian Classics Library (re-seeding)
[2011/11/07 21:07:39 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Tutorials
[2011/11/06 00:06:03 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Computing Tutorial Solutions
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/04 01:11:36 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\Football Manager 2012.v12.0.3 Update CrackFix-SKIDROW
[2011/11/02 00:28:28 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\download at superseeds.org Football.Manager.2012-SKIDROW[ss]
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 03:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 03:34:14 | 000,000,017 | —- | M] () – C:\Windows\syskey2i.drv
[2011/11/20 03:34:02 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 03:33:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 03:33:48 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 03:33:07 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 03:33:06 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 03:32:00 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/11/20 03:31:12 | 004,302,402 | —- | M] (Swearware) – C:\Users\Henry\Desktop\ComboFix.exe
[2011/11/20 03:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 09:57:47 | 000,002,397 | —- | M] () – C:\Users\Henry\Desktop\Google Chrome.lnk
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/16 23:05:47 | 004,013,230 | —- | M] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/11 01:14:01 | 000,001,179 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[2011/11/04 11:32:38 | 000,000,937 | —- | M] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/04 10:19:48 | 000,000,017 | —- | M] () – C:\Windows\keys.ini
[2011/11/01 12:35:21 | 000,044,475 | —- | M] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 03:34:14 | 000,000,017 | —- | C] () – C:\Windows\syskey2i.drv
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/16 23:05:26 | 004,013,230 | —- | C] () – C:\Users\Henry\Desktop\Depths of Your Love.mp3
[2011/11/11 01:14:01 | 000,001,179 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare 4.lnk
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/11/04 10:19:48 | 000,000,017 | —- | C] () – C:\Windows\keys.ini
[2011/11/04 10:08:01 | 000,000,937 | —- | C] () – C:\Users\Henry\Desktop\fm.exe - Shortcut.lnk
[2011/11/01 12:35:23 | 000,044,475 | —- | C] () – C:\Users\Henry\Desktop\318650_10150342424120810_171254060809_8702774_128857764_n.jpg
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/08/07 23:03:42 | 000,000,384 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >
Hi, thanks for your help so far, but there was a BIG BIG problem, after running combo fix yesterday, the computer was restarted. However, i couldn't get it going as once it loaded onto the windows 7 screen, it suddenly turned into the blue screen of death, with the following file missing - tmtdi.sys. I am now running on safe mode posting this. hope you can solve my problem as soon as possible. Really appreciate your help!
Yep lets have a look see

First could you locate and post the Combofix log - it should be at C:\combofix.txt

Then lets look for a copy of that file, it is part of trend micro


  • Run OTL.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    tmtdi.*
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open just one log.
  • Post the log
ComboFix 11-11-19.04 - Henry 11/20/2011 21:09:05.1.4 - x86 MINIMAL Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3071.2258 [GMT 8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Trend Micro Titanium Maximum Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} SP: Trend Micro Titanium Maximum Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\Common Files\lsmass.exe c:\programdata\wscntfy.exe c:\windows\$NtUninstallKB10323$ c:\windows\$NtUninstallKB10323$\3529767472\@ c:\windows\$NtUninstallKB10323$\3529767472\bckfg.tmp c:\windows\$NtUninstallKB10323$\3529767472\cfg.ini c:\windows\$NtUninstallKB10323$\3529767472\Desktop.ini c:\windows\$NtUninstallKB10323$\3529767472\kwrd.dll c:\windows\$NtUninstallKB10323$\3529767472\L\xadqgnnk c:\windows\$NtUninstallKB10323$\3529767472\U\00000001.@ c:\windows\$NtUninstallKB10323$\3529767472\U\00000002.@ c:\windows\$NtUninstallKB10323$\3529767472\U\00000004.@ c:\windows\$NtUninstallKB10323$\3529767472\U\80000000.@ c:\windows\$NtUninstallKB10323$\3529767472\U\80000004.@ c:\windows\$NtUninstallKB10323$\3529767472\U\80000032.@ c:\windows\$NtUninstallKB10323$\523665308 c:\windows\keys.ini c:\windows\syskey2i.drv c:\windows\system32\config\systemprofile\AppData\Local\NVIDIA Corporation\Update\daemonupd.exe c:\windows\system32\svdhalp.exe c:\windows\system32\svdhalp.exe.ini . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_COMSysApp ——-\Service_ONETWO . . ((((((((((((((((((((((((( Files Created from 2011-10-20 to 2011-11-20 ))))))))))))))))))))))))))))))) . . 2011-11-20 13:14 . 2011-11-20 13:17 ——– d—–w- c:\users\Henry\AppData\Local\temp 2011-11-19 19:31 . 2011-11-19 19:31 ——– d—–w- C:\_OTL 2011-11-15 15:51 . 2011-11-15 15:51 ——– d—–w- c:\programdata\IObit 2011-11-10 17:13 . 2011-11-10 17:13 ——– d—–w- c:\users\Henry\AppData\Roaming\IObit 2011-11-10 17:13 . 2011-11-10 17:13 ——– d—–w- c:\program files\IObit 2011-11-09 18:41 . 2011-09-29 16:03 1290608 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 18:39 . 2011-11-09 18:39 102400 —-a-w- c:\windows\RegBootClean.exe 2011-11-09 15:50 . 2011-10-01 04:37 708608 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 15:50 . 2011-09-29 03:37 2341888 —-a-w- c:\windows\system32\win32k.sys 2011-11-04 02:20 . 2011-11-04 02:20 ——– d—–w- c:\users\Henry\AppData\Local\Chromium 2011-11-04 02:11 . 2011-11-04 02:11 ——– d—–w- c:\users\Henry\AppData\Local\SKIDROW . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-10-31 02:42 . 2009-08-18 03:30 564632 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll 2011-10-31 02:42 . 2009-08-18 03:24 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-09-28 08:56 . 2011-09-10 13:43 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-23 08:00 . 2011-09-22 17:11 112832 —-a-w- c:\programdata\Microsoft\VCExpress\10.0\1033\ResourceCache.dll 2011-09-01 02:35 . 2011-10-13 07:37 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-09-01 02:28 . 2011-10-13 07:37 1126912 —-a-w- c:\windows\system32\wininet.dll 2011-09-01 02:22 . 2011-10-13 07:37 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-08-27 04:26 . 2011-10-13 02:16 571904 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 04:26 . 2011-10-13 02:16 233472 —-a-w- c:\windows\system32\oleacc.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2010-05-26 07:23 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TBPanel"="c:\program files\Vtune\TBPanel.exe" [2009-10-05 2158592] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-11 39408] "Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304] "Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2010-02-10 1713152] "BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864] "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-12-28 887936] "Turbo Key"="c:\program files\ASUS\Turbo Key\TurboKey.exe" [2009-11-24 1874432] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-01-07 1797488] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-26 421160] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" [2011-02-17 1111568] . c:\users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-26 24176560] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-19 691696] R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2009-07-06 11448] R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536] R2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x] R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-12-28 96896] R2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [2009-10-16 319488] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 136176] R2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys [2010-08-08 64080] R3 GGSAFERDriver;GGSAFER Driver;c:\program files\Garena\safedrv.sys [x] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 136176] R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x] R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-02-24 3432444] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-08-21 66592] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2010-01-11 1119232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-11 1343400] R4 wvchatts;wvchatts; [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2011-11-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-09-11 17:27] . 2011-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . 2011-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job - c:\users\Henry\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-18 17:27] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.254 . - - - - ORPHANS REMOVED - - - - . WebBrowser-{081230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file) HKCU-Run-Funshion - c:\program files\Funshion Online\Funshion\Funshion.exe HKLM-Run-Windows-Audio Driver - c:\programdata\wscntfy.exe AddRemove-Funshion - c:\program files\Funshion Online\Funshion\Uninstall.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wvchatts] "ImagePath"="" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(1784) c:\users\Henry\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . ———————— Other Running Processes ———————— . c:\windows\system32\conhost.exe c:\windows\System32\WerFault.exe c:\windows\helppane.exe . ************************************************************************** . Completion time: 2011-11-20 21:20:05 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-20 13:20 . Pre-Run: 141,768,929,280 bytes free Post-Run: 141,636,268,032 bytes free . - - End Of File - - 42B3309BE57D43E5C0FE05A5891F78BE
opps, i didn't realize i posted the wrong file just now. what do u mean by "Then lets look for a copy of that file, it is part of trend micro "? do i run the OTL now? or wait till u have checked the file? Let's solve the problem now! I cant wait to get it done, thanks alot! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI