This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PING.exe virus

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Intriguing as combofix did not touch that file .. But lets see if we have a spare, if not then a reinstall of Trend should cure it Yep run the OTL scan please

2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人

Do you recognise these

Once combofix has completed could you let me know what problems remain


追风筝的人 is a movie file, just that it is in Chinese, it has been in the computer from the start, so it is not a problem. While this, i am not very sure, they are Korean words, i used to download Korean shows and subtitles, so they are probably from one of those sources.
OTL logfile created on: 11/20/2011 11:22:03 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.17% Memory free
6.00 Gb Paging File | 4.85 Gb Available in Paging File | 80.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 131.96 Gb Free Space | 51.10% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file\OTL.exe
PRC - [2011/08/02 14:27:03 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files\Steam\Steam.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/11/14 01:01:53 | 014,410,024 | —- | M] () – C:\Program Files\Steam\bin\libcef.dll
MOD - [2011/11/14 01:01:53 | 000,914,216 | —- | M] () – C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011/11/14 01:01:53 | 000,194,344 | —- | M] () – C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011/11/14 01:01:53 | 000,155,432 | —- | M] () – C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011/11/14 01:01:53 | 000,091,432 | —- | M] () – C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2007/01/31 11:33:24 | 000,032,768 | —- | M] () – C:\Program Files\Vtune\TBPanelExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Stopped] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Stopped] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Stopped] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Stopped] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

O1 HOSTS File: ([2011/11/20 21:16:56 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 22:34:35 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\ElevatedDiagnostics
[2011/11/20 21:25:00 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\DESKTOP STUFF
[2011/11/20 21:20:07 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/20 21:17:09 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2011/11/20 21:14:08 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\temp
[2011/11/20 05:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/20 05:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/20 05:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/20 05:16:10 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/20 05:16:08 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 22:23:56 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 22:23:56 | 219,344,740 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/11/20 22:23:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 22:22:24 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 21:16:56 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 04:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 05:22:10 | 219,344,740 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/11/20 05:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/20 05:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/20 05:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/20 05:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/20 05:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/20 03:44:14 | 000,000,260 | -H– | C] () – C:\dvmexp.idx
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: TMTDI.CAT >
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\tmtdi.cat
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.cat

< MD5 for: TMTDI.CAT.CFG >
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.cat.cfg

< MD5 for: TMTDI.DLL >
[2010/07/20 23:59:54 | 000,111,952 | —- | M] (Trend Micro Inc.) MD5=F78B9DC5284DFFE2CE0B6C8402E00294 – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\tmtdi.dll

< MD5 for: TMTDI.DLL.CFG >
[2010/07/20 23:59:54 | 000,111,952 | —- | M] (Trend Micro Inc.) MD5=F78B9DC5284DFFE2CE0B6C8402E00294 – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679608320l1p1r1o1\6.6.1088\tmtdi.dll.cfg

< MD5 for: TMTDI.INF >
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\TmTdi.inf
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.inf

< MD5 for: TMTDI.INF.CFG >
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.inf.cfg

< MD5 for: TMTDI.REG >
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\TmTdi.reg
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.reg

< MD5 for: TMTDI.REG.CFG >
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.reg.cfg

< MD5 for: TMTDI.SYS >
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\tmtdi.sys
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Windows\System32\drivers\tmtdi.sys

< MD5 for: TMTDI.SYS.CFG >
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys.cfg

< C:\Windows\assembly\tmp\U\*.* /s >

========== Files - Unicode (All) ==========
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >
OK if this should fail could you try a re-install of Trend micro

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    C:\Windows\System32\drivers\tmtdi.sys|C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys /replace

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Still could not work. but here is what they said regarding the error "Problem signature: Problem Event Name: BlueScreen OS Version: 6.1.7601.2.1.0.256.48 Locale ID: 1033 Additional information about the problem: BCCode: ce BCP1: 9076762D BCP2: 00000008 BCP3: 9076762D BCP4: 00000000 OS Version: 6_1_7601 Service Pack: 1_0 Product: 256_1 Files that help describe the problem: C:\Windows\Minidump\112011-24429-01.dmp C:\Users\Henry\AppData\Local\temp\WER-31777-0.sysdata.xml" Do i still uninstall Trend Micro? I'm running the scan now!
OTL logfile created on: 11/20/2011 11:46:13 PM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 61.45% Memory free
6.00 Gb Paging File | 4.85 Gb Available in Paging File | 80.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 132.00 Gb Free Space | 51.11% Space Free | Partition Type: NTFS

Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file\OTL.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/07/14 09:14:44 | 000,360,448 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Stopped] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Stopped] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Stopped] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)


========== Driver Services (SafeList) ==========

DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Stopped] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\

O1 HOSTS File: ([2011/11/20 23:40:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 22:34:35 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\ElevatedDiagnostics
[2011/11/20 21:25:00 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\DESKTOP STUFF
[2011/11/20 21:20:07 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/20 21:17:09 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2011/11/20 21:14:08 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\temp
[2011/11/20 05:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/20 05:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/20 05:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/20 05:16:10 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/20 05:16:08 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/20 23:43:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 23:43:09 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 23:43:09 | 219,488,100 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/11/20 23:41:40 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 23:40:46 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 04:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/20 05:22:10 | 219,488,100 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/11/20 05:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/20 05:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/20 05:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/20 05:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/20 05:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/20 03:44:14 | 000,000,260 | -H– | C] () – C:\dvmexp.idx
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll

========== LOP Check ==========

[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그

========== Alternate Data Streams ==========

@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51

< End of report >
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Stopped] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)

Well the file is in the right place now
Could you zip the latest two mindump folders please and attach then to your next post

And also uninstall/reinstall Trend

crash dump file: C:\Windows\Minidump\112011-24445-01.dmp
This was probably caused by the following module: tmtdi.sys (Unloaded_tmtdi.sys+0xE62D)
Bugcheck code: 0xCE (0xFFFFFFFF9079F62D, 0x8, 0xFFFFFFFF9079F62D, 0x0)
Error: DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS
Bug check description: This indicates that a driver failed to cancel pending operations before unloading.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: tmtdi.sys .

This is an error within trend micro … There is a patch
Download and install the patch from here install and ensure the firewall is updated as well
so what i do now is restart my computer after i have 1) Un-install Trend Micro 2) Re-install Trend Micro 3) Use the patch And when i have restarted my computer, will it go to the blue screen of death now?
1) Un-install Trend Micro YES

2) Re-install Trend Micro YES

3) Use the patch YES

And when i have restarted my computer, will it go to the blue screen of death now? Hopefully NO B)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI