This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe 100% CPU Usage - maybe other problems. [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I stumbled across this website via google trying to find a fix for my computer. I'm semi-computer savvy but can't fix this to
save my life. I followed the instructions and ran OTL. These are the results.

OTL logfile created on: 12/16/2011 1:41:44 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\dhickson\Desktop\BL3ND ######!
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 495.94 Mb Available Physical Memory | 48.46% Memory free
1.90 Gb Paging File | 1.52 Gb Available in Paging File | 79.73% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 10.00 Gb Free Space | 29.27% Space Free | Partition Type: NTFS

Computer Name: ORIONS-BROTHER | User Name: dhickson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\dhickson\Desktop\BL3ND ######!\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\WINDOWS\system32\6to4ex.dll ()


========== Win32 Services (SafeList) ==========

SRV - (SolidWorks Licensing Service) – File not found
SRV - (vToolbarUpdater) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe ()
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (6to4) – C:\WINDOWS\system32\6to4ex.dll ()
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (DWMRCS) – C:\WINDOWS\System32\DWRCS.EXE (DameWare Development LLC)
SRV - (NMSSvc) Intel® – C:\WINDOWS\system32\NMSSvc.Exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101019.004\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20101019.004\NAVENG.SYS (Symantec Corporation)
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\MPE.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (vpnva) – C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.)
DRV - (emAudio) – C:\WINDOWS\system32\drivers\emAudio.sys (Pinnacle Systems GmbH)
DRV - (DCamUSBEMPIA) – C:\WINDOWS\system32\drivers\emDevice.sys (eMPIA Technology, Inc.)
DRV - (FiltUSBEMPIA) – C:\WINDOWS\system32\drivers\emFilter.sys (eMPIA Technology, Inc.)
DRV - (ScanUSBEMPIA) – C:\WINDOWS\system32\drivers\emScan.sys (eMPIA Technology, Inc.)
DRV - (MarvinBus) – C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (IPFilter) – C:\WINDOWS\system32\drivers\ipfilter.sys (Microsoft Corporation)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/?src=aim&ncid=snsusaimc00000001
IE - HKCU\..\URLSearchHook: {3ce45c4f-bfff-4988-9a3c-a75c1f491319} - C:\Program Files\ZoneAlarm_Security_Suite\prxtbZone.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "ZoneAlarm Security Suite Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT3015261&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "ZoneAlarm Security Suite Customized Web Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/?ref=hp"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.91
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7Bb82d5ef4-3905-40d7-af8d-3402c9e01bc9%7D&mid=1d3fb5f8d10847d18daad1790ef6eb7e-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.34&lang=en&pr=pr&d=2011-09-14%2012%3A48%3A42&sap=ku&q="
FF - prefs.js..network.proxy.type: 4

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.91: C:\Program Files\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@rsj.de/prodown: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/14 01:12:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/09/15 01:03:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/10/25 23:38:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/08 17:16:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/25 23:40:17 | 000,000,000 | —D | M]

[2010/10/13 01:25:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Extensions
[2011/12/15 23:37:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\extensions
[2011/07/04 21:43:04 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/06 13:43:39 | 000,000,000 | —D | M] (ZoneAlarm Security Suite Community Toolbar) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\extensions\{3ce45c4f-bfff-4988-9a3c-a75c1f491319}
[2011/12/06 13:43:45 | 000,000,000 | —D | M] (BitTorrentBar Community Toolbar) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
[2011/09/07 08:21:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\extensions\nostmp
[2011/09/14 12:10:21 | 000,003,847 | —- | M] () – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\searchplugins\avg-secure-search.xml
[2011/08/31 11:09:50 | 000,000,951 | —- | M] () – C:\Documents and Settings\dhickson\Application Data\Mozilla\Firefox\Profiles\b6vce0z5.default\searchplugins\conduit.xml
[2011/11/09 11:55:13 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/08 17:16:34 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/01 17:08:55 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/08 17:16:34 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1804_0\plugins/avgnpss.dll
CHR - plugin: getPlusPlus for Adobe 16291 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: npFFApi (Enabled) = C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube Options for Google Chrome\u2122 = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn\1.8.49_0\
CHR - Extension: YouTube = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Scrollbar Hide = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\boeokoabnakleidcgonddhmfldpnjaef\4.6_0\
CHR - Extension: SmoothScroll = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cccpiddacjljmfbbgeimpelpndgpoknn\1.0.5_0\
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Google Search = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Tab Wrangler = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\egnjhciaieeiiohknchakcodbpgjnchh\1.3.6_0\
CHR - Extension: Clock for Google Chrome\u2122 = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\1.0_0\
CHR - Extension: Clock for Google Chrome\u2122 = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\1.0_0\~
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1857_0\
CHR - Extension: Reddit Enhancement Suite = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\3.4_0\
CHR - Extension: StayFocusd = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji\1.2.0.15_0\
CHR - Extension: Stop Autoplay for YouTube. = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lgdfnbpkmkkdhgidgcpdkgpdlfjcgnnh\0.11.5.24_0\
CHR - Extension: Google Dictionary (by Google) = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.6_0\
CHR - Extension: BitTorrentBar = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid\2.3.2.4_0\
CHR - Extension: Readability = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oknpjjbmpnndlpmnhmekjpocelpnlfdi\1.8_0\
CHR - Extension: Gmail = C:\Documents and Settings\dhickson\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

Hosts file not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (ZoneAlarm Security Suite Toolbar) - {3ce45c4f-bfff-4988-9a3c-a75c1f491319} - C:\Program Files\ZoneAlarm_Security_Suite\prxtbZone.dll (Conduit Ltd.)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll File not found
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Suite Toolbar) - {3ce45c4f-bfff-4988-9a3c-a75c1f491319} - C:\Program Files\ZoneAlarm_Security_Suite\prxtbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Suite Toolbar) - {3CE45C4F-BFFF-4988-9A3C-A75C1F491319} - C:\Program Files\ZoneAlarm_Security_Suite\prxtbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files\BitTorrentBar\prxtbBitT.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [USB2Check] C:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Reg Error: Value error. File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKLM\..Trusted Domains: flextronics.com ([]http in Local intranet)
O15 - HKLM\..Trusted Domains: flextronics.com ([]https in Local intranet)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {1ED48504-8834-11D5-AC75-0008C73FD642} file://C:\PTC\proeWildfire2\i486_nt\obj\pvx_install.exe (Reg Error: Key error.)
O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} http://www.solidworks.com/plugins/edrawings/download.cfm (Reg Error: Key error.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {55963676-2F5E-4BAF-AC28-CF26AA587566} https://con.synsor.com/CACHE/stc/5/binaries/vpnweb.cab (Cisco AnyConnect VPN Client Web Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{037F4C6A-C6F1-4874-8C46-6E2416993A12}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\dhickson\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\dhickson\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/09/27 17:02:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4ex.dll ()
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.tscc - C:\WINDOWS\System32\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/12/16 09:55:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Conduit
[2011/12/14 01:23:05 | 001,577,264 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\dhickson\Desktop\TDSSKiller.exe
[2011/12/12 21:07:21 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Real
[2011/12/10 23:43:58 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/10 17:53:55 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/10 17:53:49 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/02 18:56:45 | 006,766,520 | —- | C] (Pinnacle Systems ) – C:\Documents and Settings\dhickson\Desktop\PCLEUSB2x32(1).exe
[2011/12/01 20:23:25 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NCH Software
[2011/12/01 20:23:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Video Related Programs
[2011/12/01 20:23:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NCH Software Suite
[2011/12/01 20:23:10 | 000,000,000 | —D | C] – C:\Program Files\NCH Software
[2011/12/01 20:23:07 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Application Data\NCH Software
[2011/12/01 20:09:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\BitTorrentBar
[2011/12/01 19:41:43 | 000,171,520 | —- | C] (Pinnacle Systems GmbH) – C:\WINDOWS\System32\drivers\MarvinBus.sys
[2011/12/01 19:41:30 | 000,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\MPE.sys
[2011/12/01 19:41:30 | 000,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mpe.sys
[2011/12/01 19:41:25 | 000,005,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstee.sys
[2011/12/01 19:41:18 | 000,010,880 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ndisip.sys
[2011/12/01 19:41:16 | 000,022,528 | —- | C] (Pinnacle Systems GmbH) – C:\WINDOWS\System32\drivers\emAudio.sys
[2011/12/01 19:41:14 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ipsink.ax
[2011/12/01 19:41:14 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ipsink.ax
[2011/12/01 19:41:14 | 000,015,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\streamip.sys
[2011/12/01 19:41:12 | 000,011,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\slip.sys
[2011/12/01 19:41:07 | 000,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wstcodec.sys
[2011/12/01 19:40:57 | 000,085,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\nabtsfec.sys
[2011/12/01 19:40:53 | 000,017,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ccdecode.sys
[2011/12/01 19:40:38 | 000,081,920 | —- | C] (Pinnacle Systems) – C:\WINDOWS\System32\PCLECoInst.dll
[2011/12/01 19:40:38 | 000,045,056 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\emVFW.dll
[2011/12/01 19:40:38 | 000,032,768 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\emProp.ax
[2011/12/01 19:40:38 | 000,024,269 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\drivers\emStream.sys
[2011/12/01 19:40:38 | 000,017,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\emYUV.dll
[2011/12/01 19:40:38 | 000,009,739 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\emUSD.dll
[2011/12/01 19:40:38 | 000,004,493 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\drivers\emScan.sys
[2011/12/01 19:40:37 | 000,100,957 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\drivers\emDevice.sys
[2011/12/01 19:40:37 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\vfwwdm32.dll
[2011/12/01 19:40:37 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\vfwwdm32.dll
[2011/12/01 19:40:37 | 000,005,245 | —- | C] (eMPIA Technology, Inc.) – C:\WINDOWS\System32\drivers\emFilter.sys
[2011/12/01 19:40:35 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kswdmcap.ax
[2011/12/01 19:40:35 | 000,091,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kswdmcap.ax
[2011/12/01 19:40:35 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\kstvtune.ax
[2011/12/01 19:40:35 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\kstvtune.ax
[2011/12/01 19:40:35 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ksxbar.ax
[2011/12/01 19:40:35 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ksxbar.ax
[2011/12/01 19:40:34 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2011/12/01 19:40:34 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\BdaPlgIn.ax
[2011/12/01 19:40:34 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\BdaSup.sys
[2011/12/01 19:40:34 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bdasup.sys
[2011/12/01 19:40:23 | 000,000,000 | —D | C] – C:\Program Files\Pinnacle
[2011/12/01 19:40:10 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Local Settings\Application Data\Downloaded Installations
[2011/12/01 19:38:12 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2011/11/29 17:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Desktop\JUNK
[2011/11/29 14:40:19 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/26 16:09:55 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Local Settings\Application Data\BitTorrentBar
[2011/11/26 16:09:52 | 000,000,000 | —D | C] – C:\Program Files\BitTorrentBar
[2011/11/26 16:09:17 | 000,000,000 | —D | C] – C:\Program Files\BitTorrent
[2011/11/26 16:08:37 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Local Settings\Application Data\BitTorrent
[2011/11/26 16:08:37 | 000,000,000 | —D | C] – C:\Documents and Settings\dhickson\Application Data\BitTorrent
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/16 13:23:37 | 000,444,456 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/16 13:23:37 | 000,072,332 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/16 13:19:08 | 000,186,097 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/16 13:19:07 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-527237240-515967899-725345543-1007.job
[2011/12/16 13:19:06 | 000,000,386 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup 2011 Integrator Start On dhickson Logon.job
[2011/12/16 13:19:06 | 000,000,280 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/12/16 13:18:22 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/16 13:17:16 | 000,030,276 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000004-00000000-00000007-00001102-00000002-80651102}.rfx
[2011/12/16 13:17:16 | 000,030,276 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000004-00000000-00000007-00001102-00000002-80651102}.rfx
[2011/12/16 13:17:16 | 000,017,596 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000004-00000000-00000007-00001102-00000002-80651102}.rfx
[2011/12/16 13:17:16 | 000,017,596 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000004-00000000-00000007-00001102-00000002-80651102}.rfx
[2011/12/16 13:17:16 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/16 13:17:16 | 000,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/12/16 13:17:16 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000004-00000000-00000007-00001102-00000002-80651102}.dat
[2011/12/16 13:17:16 | 000,000,024 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000004-00000000-00000007-00001102-00000002-80651102}.dat
[2011/12/16 13:14:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At28.job
[2011/12/16 13:14:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At27.job
[2011/12/16 12:14:25 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At25.job
[2011/12/16 12:14:03 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At26.job
[2011/12/16 12:03:17 | 000,000,990 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-527237240-515967899-725345543-1007UA.job
[2011/12/16 11:14:47 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At24.job
[2011/12/16 11:14:47 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At23.job
[2011/12/16 11:03:57 | 000,000,288 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/12/16 10:14:47 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At22.job
[2011/12/16 10:14:03 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At21.job
[2011/12/16 09:14:05 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At20.job
[2011/12/16 09:14:03 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At19.job
[2011/12/16 08:15:48 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At18.job
[2011/12/16 08:14:09 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At17.job
[2011/12/16 07:54:34 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\VIF7n.exe.b
[2011/12/16 07:54:33 | 000,000,112 | —- | M] () – C:\Documents and Settings\All Users\Application Data\60DVv6mS.dat
[2011/12/16 07:54:30 | 000,078,848 | —- | M] () – C:\WINDOWS\System32\VIF7n.exe_
[2011/12/16 07:46:01 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At48.job
[2011/12/16 07:46:00 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At46.job
[2011/12/16 07:46:00 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At47.job
[2011/12/16 07:45:58 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At44.job
[2011/12/16 07:45:58 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At42.job
[2011/12/16 07:45:58 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At40.job
[2011/12/16 07:45:58 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At45.job
[2011/12/16 07:45:58 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At43.job
[2011/12/16 07:45:58 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At41.job
[2011/12/16 07:45:58 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At39.job
[2011/12/16 07:45:55 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At38.job
[2011/12/16 07:45:55 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At36.job
[2011/12/16 07:45:55 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At34.job
[2011/12/16 07:45:55 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At37.job
[2011/12/16 07:45:55 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At35.job
[2011/12/16 07:45:55 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At33.job
[2011/12/16 07:45:54 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At32.job
[2011/12/16 07:45:54 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At30.job
[2011/12/16 07:45:54 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At31.job
[2011/12/16 07:45:54 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At29.job
[2011/12/16 07:45:48 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At16.job
[2011/12/16 07:45:48 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At14.job
[2011/12/16 07:45:48 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At12.job
[2011/12/16 07:45:48 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At15.job
[2011/12/16 07:45:48 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At13.job
[2011/12/16 07:45:40 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At10.job
[2011/12/16 07:45:40 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At11.job
[2011/12/16 07:45:39 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At9.job
[2011/12/16 07:45:38 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At8.job
[2011/12/16 07:45:38 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At6.job
[2011/12/16 07:45:38 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At7.job
[2011/12/16 07:45:37 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At4.job
[2011/12/16 07:45:37 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At5.job
[2011/12/16 07:45:36 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At3.job
[2011/12/16 07:45:35 | 000,000,346 | —- | M] () – C:\WINDOWS\tasks\At2.job
[2011/12/16 07:45:34 | 000,000,344 | —- | M] () – C:\WINDOWS\tasks\At1.job
[2011/12/15 23:20:12 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/14 19:06:21 | 000,002,309 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\Google Chrome.lnk
[2011/12/14 19:06:21 | 000,002,287 | —- | M] () – C:\Documents and Settings\dhickson\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/14 18:43:01 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-515967899-725345543-1007.job
[2011/12/14 13:03:02 | 000,000,938 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-527237240-515967899-725345543-1007Core.job
[2011/12/13 10:41:02 | 001,577,264 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\dhickson\Desktop\TDSSKiller.exe
[2011/12/12 13:32:06 | 000,001,984 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/10 17:38:20 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\dhickson\Local Settings\Application Data\528017s5q641w064w571h1hxm2c8
[2011/12/10 17:38:20 | 000,001,130 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\528017s5q641w064w571h1hxm2c8
[2011/12/08 20:09:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/07 15:44:55 | 002,093,090 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\21lommv.gif
[2011/12/07 00:53:49 | 000,214,826 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\ADSEt.jpg
[2011/12/06 22:36:52 | 000,040,745 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\mkaxI.png
[2011/12/06 22:20:53 | 000,083,926 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\Kizer 12.jpeg
[2011/12/02 19:19:45 | 000,000,696 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\Shortcut to moviemk.exe.lnk
[2011/12/02 19:00:09 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2011/12/02 18:57:41 | 006,766,520 | —- | M] (Pinnacle Systems ) – C:\Documents and Settings\dhickson\Desktop\PCLEUSB2x32(1).exe
[2011/12/02 18:13:43 | 000,029,184 | —- | M] () – C:\Documents and Settings\dhickson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/01 20:21:26 | 000,001,056 | —- | M] () – C:\Documents and Settings\dhickson\Desktop\Install Corel VideoStudio Pro.lnk
[2011/11/29 14:40:19 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/26 16:09:20 | 000,000,668 | —- | M] () – C:\Documents and Settings\dhickson\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/11/26 16:09:20 | 000,000,650 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/16 12:46:25 | 000,078,848 | —- | C] () – C:\WINDOWS\System32\VIF7n.exe_
[2011/12/16 10:05:52 | 000,000,280 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2011/12/16 10:05:46 | 000,000,288 | —- | C] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2011/12/16 07:54:34 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\VIF7n.exe.b
[2011/12/16 07:46:01 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\60DVv6mS.dat
[2011/12/16 07:46:00 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At48.job
[2011/12/16 07:45:59 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At47.job
[2011/12/16 07:45:58 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At46.job
[2011/12/16 07:45:58 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At45.job
[2011/12/16 07:45:57 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At44.job
[2011/12/16 07:45:56 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At42.job
[2011/12/16 07:45:56 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At43.job
[2011/12/16 07:45:55 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At40.job
[2011/12/16 07:45:55 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At41.job
[2011/12/16 07:45:54 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At39.job
[2011/12/16 07:45:53 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At38.job
[2011/12/16 07:45:53 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At37.job
[2011/12/16 07:45:52 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At36.job
[2011/12/16 07:45:52 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At35.job
[2011/12/16 07:45:51 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At34.job
[2011/12/16 07:45:51 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At33.job
[2011/12/16 07:45:50 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At32.job
[2011/12/16 07:45:50 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At31.job
[2011/12/16 07:45:49 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At30.job
[2011/12/16 07:45:49 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At28.job
[2011/12/16 07:45:49 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At29.job
[2011/12/16 07:45:48 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At27.job
[2011/12/16 07:45:47 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At26.job
[2011/12/16 07:45:47 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At25.job
[2011/12/16 07:45:46 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At24.job
[2011/12/16 07:45:46 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At23.job
[2011/12/16 07:45:45 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At22.job
[2011/12/16 07:45:45 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At21.job
[2011/12/16 07:45:44 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At20.job
[2011/12/16 07:45:44 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At19.job
[2011/12/16 07:45:43 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At18.job
[2011/12/16 07:45:43 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At17.job
[2011/12/16 07:45:42 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At16.job
[2011/12/16 07:45:42 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At15.job
[2011/12/16 07:45:41 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At14.job
[2011/12/16 07:45:41 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At13.job
[2011/12/16 07:45:40 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At12.job
[2011/12/16 07:45:40 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At11.job
[2011/12/16 07:45:39 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At10.job
[2011/12/16 07:45:39 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At9.job
[2011/12/16 07:45:38 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At8.job
[2011/12/16 07:45:37 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At6.job
[2011/12/16 07:45:37 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At7.job
[2011/12/16 07:45:36 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At5.job
[2011/12/16 07:45:35 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At4.job
[2011/12/16 07:45:35 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At3.job
[2011/12/16 07:45:34 | 000,000,346 | —- | C] () – C:\WINDOWS\tasks\At2.job
[2011/12/16 07:45:33 | 000,000,344 | —- | C] () – C:\WINDOWS\tasks\At1.job
[2011/12/10 17:38:20 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\dhickson\Local Settings\Application Data\528017s5q641w064w571h1hxm2c8
[2011/12/10 17:38:20 | 000,001,130 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\528017s5q641w064w571h1hxm2c8
[2011/12/07 15:44:54 | 002,093,090 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\21lommv.gif
[2011/12/07 00:53:48 | 000,214,826 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\ADSEt.jpg
[2011/12/06 22:36:52 | 000,040,745 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\mkaxI.png
[2011/12/06 22:20:52 | 000,083,926 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\Kizer 12.jpeg
[2011/12/02 19:19:45 | 000,000,696 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\Shortcut to moviemk.exe.lnk
[2011/12/01 19:51:47 | 000,001,056 | —- | C] () – C:\Documents and Settings\dhickson\Desktop\Install Corel VideoStudio Pro.lnk
[2011/12/01 19:40:37 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\PsisRndr.ax
[2011/12/01 19:40:37 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\dllcache\psisrndr.ax
[2011/12/01 19:40:36 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2011/12/01 19:40:36 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\dllcache\psisdecd.dll
[2011/12/01 19:40:36 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\MSDvbNP.ax
[2011/12/01 19:40:36 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2011/11/26 16:09:20 | 000,000,668 | —- | C] () – C:\Documents and Settings\dhickson\Application Data\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk
[2011/11/26 16:09:20 | 000,000,650 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2011/10/10 01:31:12 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/10/10 01:31:12 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/09/14 00:12:49 | 000,000,224 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjk
[2011/09/14 00:12:49 | 000,000,168 | —- | C] () – C:\Documents and Settings\All Users\Application Data\~6DSS92c31Apgjkr
[2011/09/14 00:12:41 | 000,000,336 | —- | C] () – C:\Documents and Settings\All Users\Application Data\6DSS92c31Apgjk
[2011/09/01 18:09:08 | 000,000,584 | —- | C] () – C:\WINDOWS\eReg.dat
[2010/10/26 00:38:53 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/10/20 01:52:38 | 000,029,184 | —- | C] () – C:\Documents and Settings\dhickson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/13 01:25:32 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/28 14:34:12 | 000,004,212 | —- | C] () – C:\WINDOWS\System32\zllictbl.dat
[2010/03/28 10:47:25 | 000,000,056 | —- | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/03/23 18:05:22 | 000,001,984 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/03/15 03:17:31 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/03/15 03:17:31 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/03/15 03:17:31 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/03/15 03:17:31 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/03/15 03:17:31 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/02/10 03:35:22 | 000,000,055 | —- | C] () – C:\WINDOWS\msicpl.ini
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 14:07:42 | 000,230,768 | —- | C] () – C:\WINDOWS\System32\OGAEXEC.exe
[2008/05/16 13:01:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/16 13:01:00 | 001,630,208 | —- | C] () – C:\WINDOWS\System32\nwiz.exe
[2008/05/16 13:01:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/16 13:01:00 | 001,339,392 | —- | C] () – C:\WINDOWS\System32\nvdspsch.exe
[2008/05/16 13:01:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/16 13:01:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/16 13:01:00 | 000,442,368 | —- | C] () – C:\WINDOWS\System32\nvappbar.exe
[2008/05/16 13:01:00 | 000,425,984 | —- | C] () – C:\WINDOWS\System32\keystone.exe
[2008/05/16 13:01:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2008/02/16 13:02:20 | 000,000,000 | —- | C] () – C:\WINDOWS\eDrawingOfficeAutomator.INI
[2007/10/19 08:47:06 | 000,000,075 | —- | C] () – C:\WINDOWS\winDecrypt.INI
[2007/10/04 10:56:46 | 000,002,640 | —- | C] () – C:\WINDOWS\System32\DWRCS.INI
[2007/05/16 09:12:50 | 000,016,384 | —- | C] () – C:\WINDOWS\System32\FileOps.exe
[2007/02/22 10:58:58 | 000,000,494 | —- | C] () – C:\WINDOWS\System32\DWRCCMDError.ini
[2006/08/10 14:27:28 | 000,048,586 | —- | C] () – C:\Documents and Settings\All Users\Application Data\xpif-v02030a.dtd
[2006/03/15 12:02:42 | 000,045,128 | —- | C] () – C:\WINDOWS\System32\mlfcache.dat
[2005/08/02 13:24:02 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2005/05/04 10:03:40 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\sw20.exe
[2005/01/25 16:55:18 | 000,039,372 | —- | C] () – C:\WINDOWS\System32\drivers\msicpl.sys
[2004/11/05 14:57:10 | 000,000,210 | —- | C] () – C:\WINDOWS\XDCS_DO2.INI
[2004/11/04 13:24:50 | 000,164,864 | —- | C] () – C:\WINDOWS\System32\UNWISE.EXE
[2004/11/04 13:24:50 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\hsduinst.exe
[2004/11/03 22:09:11 | 000,079,360 | —- | C] () – C:\WINDOWS\System32\acdbres.dll
[2004/11/03 16:06:30 | 000,005,319 | —- | C] () – C:\WINDOWS\BYPART.INI
[2004/11/03 16:06:30 | 000,004,249 | —- | C] () – C:\WINDOWS\BYWORK.INI
[2004/11/03 16:06:30 | 000,003,204 | —- | C] () – C:\WINDOWS\bysoft6.ini
[2004/11/03 16:06:30 | 000,002,709 | —- | C] () – C:\WINDOWS\BYTUBEP.INI
[2004/11/03 16:06:30 | 000,001,987 | —- | C] () – C:\WINDOWS\byview.INI
[2004/11/03 16:06:30 | 000,001,778 | —- | C] () – C:\WINDOWS\bytrace.INI
[2004/11/03 16:06:30 | 000,000,862 | —- | C] () – C:\WINDOWS\bybase.INI
[2004/11/03 16:06:30 | 000,000,516 | —- | C] () – C:\WINDOWS\bydesign.INI
[2004/11/03 16:06:30 | 000,000,123 | —- | C] () – C:\WINDOWS\BYTUBEW.INI
[2004/11/03 16:06:30 | 000,000,058 | —- | C] () – C:\WINDOWS\byorder.ini
[2004/11/03 11:03:20 | 000,000,011 | —- | C] () – C:\WINDOWS\System32\Pctl.ini
[2004/11/03 11:03:15 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\Msvcrt10.dll
[2004/11/03 11:03:08 | 000,659,507 | —- | C] () – C:\WINDOWS\System32\RedlineCtrl.dll
[2004/11/03 11:03:08 | 000,041,027 | —- | C] () – C:\WINDOWS\System32\reportmanager.dll
[2004/11/03 11:03:07 | 001,343,553 | —- | C] () – C:\WINDOWS\System32\agileobjects.dll
[2004/11/03 11:03:07 | 000,770,111 | —- | C] () – C:\WINDOWS\System32\agilereport.dll
[2004/11/03 11:03:07 | 000,282,669 | —- | C] () – C:\WINDOWS\System32\AgPCS.dll
[2004/11/03 10:51:54 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/11/03 10:51:54 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2004/11/03 10:51:50 | 000,000,000 | —- | C] () – C:\WINDOWS\NSREX.INI
[2004/11/03 10:48:38 | 000,000,000 | —- | C] () – C:\WINDOWS\VPC32.INI
[2004/11/03 10:44:33 | 000,062,464 | —- | C] () – C:\WINDOWS\KIX32.EXE
[2004/10/04 15:59:26 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\winsys.exe
[2004/09/28 22:42:17 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000004-00000000-00000007-00001102-00000002-80651102}.dat
[2004/09/28 22:42:17 | 000,000,024 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000004-00000000-00000007-00001102-00000002-80651102}.dat
[2004/09/28 22:29:34 | 000,000,128 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/09/28 22:29:33 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2004/09/28 22:29:33 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/09/28 22:29:20 | 000,037,727 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2004/09/28 22:29:20 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/09/28 22:29:18 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2004/09/28 22:29:18 | 000,179,669 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2004/09/28 22:29:18 | 000,164,044 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2004/09/28 22:29:18 | 000,113,373 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2004/09/28 22:29:18 | 000,113,273 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2004/09/28 22:29:18 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2004/09/28 22:29:18 | 000,044,055 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2004/09/28 22:29:18 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2004/09/28 22:29:18 | 000,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2004/09/27 19:00:44 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/09/27 18:13:43 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2004/09/27 17:12:28 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2004/09/27 17:05:29 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2004/09/27 16:59:42 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2004/09/27 09:54:57 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/09/27 09:53:52 | 001,579,304 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/17 20:00:00 | 000,073,748 | -H– | C] () – LS\x00\x00\x00\x00
Also, this is the Extras.Txt


OTL Extras logfile created on: 12/16/2011 1:41:44 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\dhickson\Desktop\BL3ND ######!
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 495.94 Mb Available Physical Memory | 48.46% Memory free
1.90 Gb Paging File | 1.52 Gb Available in Paging File | 79.73% Paging File free
Paging file location(s): C:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.17 Gb Total Space | 10.00 Gb Free Space | 29.27% Space Free | Partition Type: NTFS

Computer Name: ORIONS-BROTHER | User Name: dhickson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [print] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiSpywareOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 1
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Disabled:Blizzard Downloader: 3724
"80:TCP" = 80:TCP:*:Disabled:Blizzard 1
"1119:TCP" = 1119:TCP:*:Disabled:Blizzard 2
"1120:TCP" = 1120:TCP:*:Disabled:Blizzard 3
"4000:TCP" = 4000:TCP:*:Disabled:Blizzard 4
"6112:TCP" = 6112:TCP:*:Disabled:Blizzard 5

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\BitTorrent\BitTorrent.exe" = C:\Program Files\BitTorrent\BitTorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Disabled:Steam
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Disabled:Ventrilo.exe – (Flagship Industries, Inc.)
"C:\Program Files\XBC\XBC_NS.exe" = C:\Program Files\XBC\XBC_NS.exe:*:Disabled:XBConnect – (TGL Microsystems)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{10798AE3-DCBB-43C3-9C93-C23512427E25}" = The Sims Deluxe Edition
"{1B7DCF2E-774A-11E0-9986-0013D3D69929}" = Vegas Pro 10.0
"{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}" = Adobe ExtendScript Toolkit 2
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{229B6751-774A-11E0-BCAE-0013D3D69929}" = MSVCRT Redists
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A7653AA-45C7-4C30-B949-2C72131882DC}" = Flextronics Outlook Help Addin
"{3FCAADB8-EB1B-11D6-AB2D-0090271A23A2}" = Sound Blaster Live! Web 2K/XP
"{40422EDF-8CF6-4A09-9865-1489315F7CC3}" = Waterpark Wild Rides
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E74D41C-5864-4561-9F6B-069372513A0B}" = AVG 2012
"{528E59D9-F2BB-4CFA-A59D-E14BE91E4913}_is1" = Internet Evidence Finder 4.1.0
"{56839333-0802-40D6-9A50-EBB9EB2BF541}" = AVG 2012
"{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}" = Sony USB Driver
"{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}" = Adobe Setup
"{69995C7A-062A-4A90-A4DF-8C22895DF522}" = iTunes
"{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}" = Adobe Color Common Settings
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{848AC794-8B81-440A-81AE-6474337DB527}" = Symantec AntiVirus
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9870C7AE-7C6A-478D-9A75-35827382220F}" = Pinnacle Systems USB-2 Device Drivers
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92A4DB0-CD37-42D1-BE1D-603D53C24328}" = Intel® Processor ID Utility
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AF1B2B2E-03E3-458A-9DEB-32F8C7637374}" = ZoneAlarm Security
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C180FAEF-61D5-4A03-8328-A58D9CDD1C4C}" = ZoneAlarm Firewall
"{C23CD6DA-1958-43A5-ADD0-59396572E02E}" = Apple Mobile Device Support
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CA4EECED-20F3-4C2B-8A93-F39CB2063E71}" = ZoneAlarm Antivirus
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D03482C5-9AD8-496D-B388-692AE04C93AF}" = Bonjour
"{D504303A-717D-414C-BA9F-FE01093E2EF8}" = Adobe Setup
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Image Viewer Plugin" = Adobe Image Viewer Plugin 4.0
"Agile 9.2" = Agile 9.2
"ASM_V_3.0" = ASM CD CATALOG 4.0
"AVG" = AVG 2012
"AVG Secure Search" = AVG Security Toolbar
"BitTorrent" = BitTorrent
"BitTorrentBar Toolbar" = BitTorrentBar Toolbar
"CCleaner" = CCleaner
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"McAfee Security Scan" = McAfee Security Scan Plus
"MeetingPlace for Outlook" = Cisco MeetingPlace for Outlook
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0 (x86 en-US)" = Mozilla Firefox 8.0 (x86 en-US)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Ethernet Adapter and Software
"RealPlayer 12.0" = RealPlayer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinPcapInst" = WinPcap 3.1
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XBC 5.1" = XBC 5.1
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"ZoneAlarm Antivirus" = ZoneAlarm Antivirus
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/27/2011 12:54:36 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 11/27/2011 1:13:05 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 11/29/2011 1:24:52 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 11/29/2011 4:40:22 PM | Computer Name = ORIONS-BROTHER | Source = Application Error | ID = 1000
Description = Faulting application install_flashplayer11x32_mssd_aih.exe, version
3.2.1.3, faulting module downloader.dll, version 3.2.1.3, fault address 0x0000ef2d.

Error - 11/30/2011 3:01:42 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 11/30/2011 3:06:18 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 12/2/2011 9:02:45 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 12/13/2011 6:36:50 PM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 12/16/2011 2:38:55 AM | Computer Name = ORIONS-BROTHER | Source = DWMRCS | ID = 110
Description = Error: DameWare Mini Remote Control System Error: 126 Error Library
Missing (DWRCSET.DLL) Unable to continue.

Error - 12/16/2011 1:16:56 PM | Computer Name = ORIONS-BROTHER | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x006f0074.

[ Cisco AnyConnect VPN Client Events ]
Error - 10/20/2010 3:47:10 AM | Computer Name = ORIONS-BROTHER | Source = vpnva | ID = 50528257
Description = Function: find_remove_va Return code: 259 File: .\VACon.cpp Line: 177
Description:
No more data is available.

[ System Events ]
Error - 12/12/2011 11:50:21 AM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/12/2011 11:57:27 AM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/12/2011 12:02:48 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/12/2011 12:12:35 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/12/2011 12:18:11 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7034
Description = The vToolbarUpdater service terminated unexpectedly. It has done
this 1 time(s).

Error - 12/12/2011 12:18:16 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).

Error - 12/12/2011 12:18:20 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7031
Description = The AVG WatchDog service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 0 milliseconds: Restart
the service.

Error - 12/12/2011 12:18:29 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7031
Description = The ZoneAlarm Toolbar IswSvc service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 5000
milliseconds: Restart the service.

Error - 12/12/2011 12:18:38 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7031
Description = The ZoneAlarm Toolbar IswSvc service terminated unexpectedly. It
has done this 2 time(s). The following corrective action will be taken in 5000
milliseconds: Restart the service.

Error - 12/12/2011 12:18:40 PM | Computer Name = ORIONS-BROTHER | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
Hi,

Please do the following:


Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
Sorry for the late response, I ran the program and about 3 hours in it just stopped. Wouldn't go no further and my computer was basically unusable, it was REALLY slow while the program was running, it took 5+ mins for the task manager to come up, as ping.exe kept running in the background. here is what you asked for. aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-16 14:22:54 —————————– 14:22:54.578 OS Version: Windows 5.1.2600 Service Pack 3 14:22:54.578 Number of processors: 2 586 0x207 14:22:54.578 ComputerName: ORIONS-BROTHER UserName: dhickson 14:22:56.000 Initialize success 14:23:18.406 The log file has been saved successfully to "C:\Documents and Settings\dhickson\Desktop\aswMBR.txt" 14:23:18.734 AVAST engine defs: 11121601 14:23:42.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\adpu160m1Port2Path0Target0Lun0 14:23:42.171 Disk 0 Vendor: SEAGATE_ 0024 Size: 35003MB BusType: 1 14:23:42.171 Device \Driver\adpu160m -> DriverStartIo SCSIPORT.SYS f778340e 14:23:42.187 Disk 0 MBR read successfully 14:23:42.187 Disk 0 MBR scan 14:23:42.203 Disk 0 Windows XP default MBR code 14:23:42.218 Disk 0 scanning sectors +71665965 14:23:42.265 Disk 0 scanning C:\WINDOWS\system32\drivers 14:37:06.843 File: C:\WINDOWS\system32\drivers\ipsec.sys **INFECTED** Win32:Alureon-AOV [Rtk] 14:50:24.796 Service scanning 14:50:26.296 Modules scanning 15:17:09.281 Module: C:\WINDOWS\System32\DRIVERS\ipsec.sys **SUSPICIOUS** 15:42:08.171 Disk 0 trace - called modules: 15:42:08.187 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x855e2f10]<< 15:42:08.187 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87344ab8] 15:42:08.187 3 CLASSPNP.SYS[f78aefd7] -> nt!IofCallDriver -> [0x868df6f8] 15:42:08.187 \Driver\00002060[0x866a78c0] -> IRP_MJ_CREATE -> 0x855e2f10 15:42:19.890 AVAST engine scan C:\WINDOWS 15:45:44.156 AVAST engine scan C:\WINDOWS\system32 15:45:44.921 File: C:\WINDOWS\system32\6to4ex.dll **INFECTED** Win32:Spyware-gen [Spy] 17:35:58.765 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\dhickson\Desktop\MBR.dat" 17:35:58.765 The log file has been saved successfully to "C:\Documents and Settings\dhickson\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI