PING.exe virus
9 min read
Do you recognise these2011/06/05 01:10:08 | 000,000,000 | —D | M](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/01/21 00:31:50 | 000,000,000 | —D | C](C:\Users\Henry\Desktop\?????) – C:\Users\Henry\Desktop\追风筝的人
Once combofix has completed could you let me know what problems remain
追风筝的人 is a movie file, just that it is in Chinese, it has been in the computer from the start, so it is not a problem. While this, i am not very sure, they are Korean words, i used to download Korean shows and subtitles, so they are probably from one of those sources.
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.17% Memory free
6.00 Gb Paging File | 4.85 Gb Available in Paging File | 80.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 131.96 Gb Free Space | 51.10% Space Free | Partition Type: NTFS
Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file\OTL.exe
PRC - [2011/08/02 14:27:03 | 001,242,448 | —- | M] (Valve Corporation) – C:\Program Files\Steam\Steam.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
MOD - [2011/11/14 01:01:53 | 014,410,024 | —- | M] () – C:\Program Files\Steam\bin\libcef.dll
MOD - [2011/11/14 01:01:53 | 000,914,216 | —- | M] () – C:\Program Files\Steam\bin\avcodec-52.dll
MOD - [2011/11/14 01:01:53 | 000,194,344 | —- | M] () – C:\Program Files\Steam\bin\chromehtml.dll
MOD - [2011/11/14 01:01:53 | 000,155,432 | —- | M] () – C:\Program Files\Steam\bin\avformat-52.dll
MOD - [2011/11/14 01:01:53 | 000,091,432 | —- | M] () – C:\Program Files\Steam\bin\avutil-50.dll
MOD - [2007/01/31 11:33:24 | 000,032,768 | —- | M] () – C:\Program Files\Vtune\TBPanelExt.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Stopped] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Stopped] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Stopped] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)
========== Driver Services (SafeList) ==========
DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Stopped] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\
O1 HOSTS File: ([2011/11/20 21:16:56 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-3206610663-922923999-279685787-1000..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3206610663-922923999-279685787-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/11/20 22:34:35 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\ElevatedDiagnostics
[2011/11/20 21:25:00 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\DESKTOP STUFF
[2011/11/20 21:20:07 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/20 21:17:09 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2011/11/20 21:14:08 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\temp
[2011/11/20 05:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/20 05:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/20 05:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/20 05:16:10 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/20 05:16:08 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/20 22:23:56 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 22:23:56 | 219,344,740 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/11/20 22:23:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 22:22:24 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 21:16:56 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 04:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/20 05:22:10 | 219,344,740 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/11/20 05:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/20 05:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/20 05:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/20 05:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/20 05:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/20 03:44:14 | 000,000,260 | -H– | C] () – C:\dvmexp.idx
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
========== LOP Check ==========
[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: TMTDI.CAT >
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\tmtdi.cat
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.cat
< MD5 for: TMTDI.CAT.CFG >
[2010/08/08 18:35:34 | 000,007,665 | —- | M] () MD5=D9507A70D07A54C824E94C3D27C577BE – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.cat.cfg
< MD5 for: TMTDI.DLL >
[2010/07/20 23:59:54 | 000,111,952 | —- | M] (Trend Micro Inc.) MD5=F78B9DC5284DFFE2CE0B6C8402E00294 – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\tmtdi.dll
< MD5 for: TMTDI.DLL.CFG >
[2010/07/20 23:59:54 | 000,111,952 | —- | M] (Trend Micro Inc.) MD5=F78B9DC5284DFFE2CE0B6C8402E00294 – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679608320l1p1r1o1\6.6.1088\tmtdi.dll.cfg
< MD5 for: TMTDI.INF >
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\TmTdi.inf
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.inf
< MD5 for: TMTDI.INF.CFG >
[2010/08/08 18:35:34 | 000,001,740 | —- | M] () MD5=82AE68820549B3E1439B1D90A65C1113 – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.inf.cfg
< MD5 for: TMTDI.REG >
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\TmTdi.reg
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.reg
< MD5 for: TMTDI.REG.CFG >
[2010/08/08 18:35:34 | 000,000,200 | —- | M] () MD5=B53D779819C1C1A6696693027D43DA2D – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\TmTdi.reg.cfg
< MD5 for: TMTDI.SYS >
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\Helper\tmtdi.sys
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Windows\System32\drivers\tmtdi.sys
< MD5 for: TMTDI.SYS.CFG >
[2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) MD5=5A61679B2277B9AD550E30479A69503B – C:\Program Files\Trend Micro\AMSP\resource\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys.cfg
< C:\Windows\assembly\tmp\U\*.* /s >
========== Files - Unicode (All) ==========
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
========== Alternate Data Streams ==========
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51
< End of report >
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
- Under the Custom Scans/Fixes box at the bottom, paste in the following
:Files
C:\Windows\System32\drivers\tmtdi.sys|C:\Windows\System32\config\systemprofile\AppData\Local\Trend Micro\update\engine\c2t679485440l1p1r1o1\6.5.1234\tmtdi.sys /replace
:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot] - Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 61.45% Memory free
6.00 Gb Paging File | 4.85 Gb Available in Paging File | 80.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 258.24 Gb Total Space | 132.00 Gb Free Space | 51.11% Space Free | Partition Type: NTFS
Computer Name: HENRY-PC | User Name: Henry | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/20 01:42:44 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Henry\Desktop\DESKTOP STUFF\Virus scan file\OTL.exe
PRC - [2011/02/25 13:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/07/14 09:14:44 | 000,360,448 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/15 13:39:54 | 000,420,920 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/15 10:36:18 | 008,593,056 | —- | M] () – C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – – (wvchatts)
SRV - [2011/11/14 01:01:53 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/08/09 16:38:38 | 000,328,536 | —- | M] (IObit) [Auto | Stopped] – C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe – (AdvancedSystemCareService)
SRV - [2011/02/16 15:26:04 | 000,188,272 | —- | M] (Trend Micro Inc.) [Auto | Stopped] – C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe – (Amsp)
SRV - [2010/09/11 21:45:42 | 001,343,400 | —- | M] (Microsoft Corporation) [Unknown | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/03/05 10:15:12 | 000,235,752 | —- | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe – (BCUService)
SRV - [2010/02/25 04:01:00 | 003,432,444 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\Windows\System32\GameMon.des – (npggsvc)
SRV - [2009/12/28 21:33:02 | 000,096,896 | R— | M] (ASUSTeK Computer Inc.) [Auto | Stopped] – C:\Program Files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2009/10/16 10:42:48 | 000,319,488 | -H– | M] (DeviceVM, Inc.) [Auto | Stopped] – C:\ASUS.SYS\config\DVMExportService.exe – (DvmMDES)
SRV - [2009/08/10 15:59:50 | 000,178,720 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe – (nSvcIp)
SRV - [2009/08/10 15:59:48 | 000,387,616 | —- | M] () [Auto | Stopped] – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe – (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2009/07/14 09:16:15 | 000,016,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\StorSvc.dll – (StorSvc)
SRV - [2009/07/14 09:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 09:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2009/07/14 09:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/05/14 17:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Stopped] – C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)
========== Driver Services (SafeList) ==========
DRV - [2011/02/23 08:27:00 | 010,468,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 20:30:17 | 000,296,064 | —- | M] (Microsoft Corporation) [Kernel | System | Stopped] – C:\Windows\System32\drivers\vpcvmm.sys – (vpcvmm)
DRV - [2010/11/20 20:30:17 | 000,172,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vpchbus.sys – (vpcbus)
DRV - [2010/11/20 20:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 20:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 20:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 18:50:38 | 000,078,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\vpcusb.sys – (vpcusb)
DRV - [2010/11/20 18:50:37 | 000,048,128 | —- | M] (Microsoft Corporation) [Kernel | System | Running] – C:\Windows\System32\drivers\vpcnfltr.sys – (vpcnfltr)
DRV - [2010/11/20 18:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 17:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2010/11/20 17:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 17:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/11/20 16:39:17 | 000,074,752 | —- | M] () [Kernel | System | Running] – C:\Windows\System32\drivers\tdx.sys – (tdx)
DRV - [2010/09/19 09:38:10 | 000,691,696 | —- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2010/08/12 12:07:48 | 000,298,216 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmf6232.sys – (NVNET)
DRV - [2010/08/08 18:35:34 | 000,189,520 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmcomm.sys – (tmcomm)
DRV - [2010/08/08 18:35:34 | 000,092,112 | —- | M] (Trend Micro Inc.) [Kernel | System | Stopped] – C:\Windows\System32\drivers\tmtdi.sys – (tmtdi)
DRV - [2010/08/08 18:35:34 | 000,080,464 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmactmon.sys – (tmactmon)
DRV - [2010/08/08 18:35:34 | 000,064,080 | —- | M] (Trend Micro Inc.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\tmevtmgr.sys – (tmevtmgr)
DRV - [2010/01/11 18:02:44 | 001,119,232 | —- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2009/08/22 04:24:03 | 000,066,592 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvhda32v.sys – (NVHDA)
DRV - [2009/08/04 17:43:40 | 000,213,024 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2009/08/04 10:28:18 | 000,011,296 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsIO.sys – (AsIO)
DRV - [2009/07/16 11:36:30 | 000,013,216 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\ASACPI.sys – (MTsensor)
DRV - [2009/07/14 06:02:52 | 000,347,264 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\nvm62x32.sys – (NVENETFD)
DRV - [2009/07/06 10:48:02 | 000,011,448 | R— | M] () [Kernel | System | Stopped] – C:\Windows\System32\drivers\AsUpIO.sys – (AsUpIO)
DRV - [2007/03/16 10:11:38 | 000,012,256 | —- | M] (Windows ® 2000 DDK provider) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\TBPanel.sys – (TBPanel)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {BC86E1AB-EDA5-4059-938F-CE307B0C6F0A} - C:\Program Files\DeviceVM\Browser Configuration Utility\AddressBarSearch.dll (DeviceVM, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Henry\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22181a4d-af90-4ca3-a569-faed9118d6bc}: C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2011/08/07 23:12:54 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1504\6.6.1088\firefoxextension\ [2011/11/14 01:00:40 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = B:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Henry\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Henry\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Metal Slug 3 = C:\Users\Henry\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoohaidjoleeifhoeiipjofgjhkmhppk\4.0_0\
O1 HOSTS File: ([2011/11/20 23:40:46 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O2 - BHO: (TSToolbarBHO) - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Trend Micro Toolbar) - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [BCU] C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Turbo Key] C:\Program Files\ASUS\Turbo Key\TurboKey.exe (ASUSTeK Computer Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe ()
O4 - Startup: C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Henry\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60CEA890-C36F-4408-AE02-53796F7E145C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\KuGoo - No CLSID value found
O18 - Protocol\Handler\KuGoo3 - No CLSID value found
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.6.1010\6.6.1010\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1504\6.6.1088\TmIEPlg.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtb {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmtbim {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll (Trend Micro Inc.)
O18 - Protocol\Handler\vsharechrome - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/20 22:34:35 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\ElevatedDiagnostics
[2011/11/20 21:25:00 | 000,000,000 | —D | C] – C:\Users\Henry\Desktop\DESKTOP STUFF
[2011/11/20 21:20:07 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/20 21:17:09 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2011/11/20 21:14:08 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\temp
[2011/11/20 05:16:15 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/20 05:16:15 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/20 05:16:15 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/20 05:16:10 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/20 05:16:08 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/20 03:31:54 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/15 23:51:52 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/11/11 01:14:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 4
[2011/11/11 01:13:51 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\IObit
[2011/11/11 01:13:49 | 000,000,000 | —D | C] – C:\Program Files\IObit
[2011/11/04 10:20:24 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\Chromium
[2011/11/04 10:11:20 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Local\SKIDROW
[2011/11/04 10:06:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011/11/01 04:36:47 | 000,000,000 | —D | C] – C:\Users\Henry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Haunted - Hells Reach
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/20 23:43:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 23:43:09 | 2415,308,800 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 23:43:09 | 219,488,100 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/11/20 23:41:40 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 23:40:46 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:19:20 | 000,014,336 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 05:07:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 04:46:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000UA.job
[2011/11/20 03:44:14 | 000,000,260 | -H– | M] () – C:\dvmexp.idx
[2011/11/20 02:49:31 | 000,000,911 | —- | M] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/11/19 00:46:01 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3206610663-922923999-279685787-1000Core.job
[2011/11/18 02:22:25 | 000,064,000 | —- | M] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/11/10 15:30:24 | 000,364,976 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/10 02:39:53 | 000,102,400 | —- | M] () – C:\Windows\RegBootClean.exe
[1 C:\Users\Henry\Desktop\*.tmp files -> C:\Users\Henry\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/20 05:22:10 | 219,488,100 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/11/20 05:16:15 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/20 05:16:15 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/20 05:16:15 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/20 05:16:15 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/20 05:16:15 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/11/20 03:44:14 | 000,000,260 | -H– | C] () – C:\dvmexp.idx
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2011/11/17 20:21:37 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2011/11/10 02:39:23 | 000,102,400 | —- | C] () – C:\Windows\RegBootClean.exe
[2011/09/12 02:08:14 | 000,000,288 | —- | C] () – C:\Users\Henry\AppData\Roaming\.backup.dm
[2011/08/31 23:52:52 | 000,000,911 | —- | C] () – C:\Users\Henry\AppData\Roaming\coreavc.ini
[2011/08/25 12:37:23 | 000,000,167 | —- | C] () – C:\Windows\ODBCINST.INI
[2011/08/25 01:54:22 | 000,006,550 | —- | C] () – C:\Windows\jautoexp.dat
[2011/05/26 01:27:04 | 000,051,270 | —- | C] () – C:\Users\Henry\AppData\Roaming\room_v3.dat
[2011/04/24 00:22:26 | 000,000,064 | —- | C] () – C:\Windows\System32\rp_stats.dat
[2011/04/24 00:22:26 | 000,000,044 | —- | C] () – C:\Windows\System32\rp_rules.dat
[2011/04/18 00:57:59 | 000,074,752 | —- | C] () – C:\Windows\System32\drivers\tdx.sys
[2011/04/18 00:57:44 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/03/23 22:08:23 | 000,046,742 | —- | C] () – C:\Users\Henry\AppData\Roaming\room.dat
[2010/12/22 21:44:52 | 000,001,492 | —- | C] () – C:\ProgramData\ss.ini
[2010/12/21 23:05:14 | 000,000,034 | —- | C] () – C:\Users\Henry\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/12/21 23:04:55 | 000,000,033 | —- | C] () – C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/10/14 21:41:22 | 000,044,561 | —- | C] () – C:\Windows\War3Unin.dat
[2010/10/14 15:54:34 | 000,064,000 | —- | C] () – C:\Users\Henry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/28 23:39:13 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/16 23:10:10 | 000,001,015 | —- | C] () – C:\Windows\FOE2.ini
[2010/09/12 01:54:17 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/09/12 01:54:17 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/12 01:54:16 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/09/12 01:54:16 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/09/12 01:54:15 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/09/11 21:06:49 | 000,024,576 | R— | C] () – C:\Windows\System32\AsIO.dll
[2010/09/11 21:06:49 | 000,011,296 | R— | C] () – C:\Windows\System32\drivers\AsIO.sys
[2010/09/11 21:06:46 | 000,011,832 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp64.sys
[2010/09/11 21:06:46 | 000,010,216 | —- | C] () – C:\Windows\System32\drivers\AsInsHelp32.sys
[2010/09/11 21:04:33 | 000,006,136 | R— | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/09/11 21:02:34 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2010/09/11 21:02:32 | 000,022,982 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/07/29 12:57:02 | 000,000,992 | —- | C] () – C:\Windows\System32\funshion.ini
[2009/07/16 11:36:30 | 000,013,216 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,364,976 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,672,584 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,124,842 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/06 10:48:02 | 000,011,448 | R— | C] () – C:\Windows\System32\drivers\AsUpIO.sys
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2009/04/02 20:30:14 | 000,010,296 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/12/01 18:32:32 | 000,362,029 | —- | C] () – C:\Windows\System32\sqlite3.dll
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
========== LOP Check ==========
[2011/09/22 00:19:55 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\ActiveState
[2010/10/01 15:18:08 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\CometPlayer
[2010/09/19 19:33:04 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DAEMON Tools Lite
[2011/09/20 01:46:27 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dev-Cpp
[2010/09/11 21:07:37 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\DeviceVm
[2011/11/20 03:34:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Dropbox
[2011/08/14 02:40:33 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\go
[2011/11/11 01:13:51 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\IObit
[2010/10/18 21:42:06 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Jubler
[2011/06/28 23:34:40 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\KuGou
[2010/09/21 20:54:38 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\OpenOffice.org
[2011/04/27 22:33:36 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Rovio
[2011/11/04 10:11:14 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\Sports Interactive
[2011/05/08 00:27:28 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\tigerplayer
[2010/09/11 21:49:02 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\URSoft
[2011/11/20 03:09:29 | 000,000,000 | —D | M] – C:\Users\Henry\AppData\Roaming\uTorrent
[2011/11/02 22:21:57 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2010/10/28 08:03:14 | 000,000,000 | —D | M](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
[2010/10/28 08:03:14 | 000,000,000 | —D | C](C:\Users\Henry\Documents\?? ???) – C:\Users\Henry\Documents\넥슨 플러그
========== Alternate Data Streams ==========
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:1CE11B51
< End of report >
Well the file is in the right place now
Could you zip the latest two mindump folders please and attach then to your next post
And also uninstall/reinstall Trend
This is an error within trend micro … There is a patchcrash dump file: C:\Windows\Minidump\112011-24445-01.dmp
This was probably caused by the following module: tmtdi.sys (Unloaded_tmtdi.sys+0xE62D)
Bugcheck code: 0xCE (0xFFFFFFFF9079F62D, 0x8, 0xFFFFFFFF9079F62D, 0x0)
Error: DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS
Bug check description: This indicates that a driver failed to cancel pending operations before unloading.
This appears to be a typical software driver bug and is not likely to be caused by a hardware problem.
A third party driver was identified as the probable root cause of this system error. It is suggested you look for an update for the following driver: tmtdi.sys .
Download and install the patch from here install and ensure the firewall is updated as well
2) Re-install Trend Micro YES
3) Use the patch YES
And when i have restarted my computer, will it go to the blue screen of death now? Hopefully NO
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI