Thanks for the quick responses! I may have fired off the AswMBR log too, so I saved it again. I don't think it screwed anything up, but let me know if I need to rerun. It definitely found several problems.
BMan
OTL logfile created on: 12/23/2011 12:56:52 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.48 Mb Total Physical Memory | 553.87 Mb Available Physical Memory | 54.17% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.61% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.60 Gb Total Space | 128.20 Gb Free Space | 70.60% Space Free | Partition Type: NTFS
Drive D: | 4.70 Gb Total Space | 2.73 Gb Free Space | 57.98% Space Free | Partition Type: FAT32
Drive F: | 56.76 Gb Total Space | 7.22 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive G: | 76.37 Gb Total Space | 11.18 Gb Free Space | 14.64% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 11.46 Gb Free Space | 58.68% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 3.58 Gb Free Space | 3.20% Space Free | Partition Type: NTFS
Computer Name: GAMEBOX | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\6to4v32.dll ()
MOD - C:\WINDOWS\system32\USB3Nw32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (PLFlash DeviceIoControl Service) – File not found
SRV - (6to4) – C:\WINDOWS\system32\6to4v32.dll ()
SRV - (NecUsb) – C:\WINDOWS\system32\NUSB3w32.dll (Intel Corporation )
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
SRV - (FolderSize) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
========== Driver Services (SafeList) ==========
DRV - (SSHDRV65) – C:\WINDOWS\system32\drivers\SSHDRV65.sys ()
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (Net6IM) – C:\WINDOWS\system32\drivers\net6im51.sys (Citrix Systems, Inc.)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SSHDRV85) – C:\WINDOWS\system32\drivers\SSHDRV85.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (OmniUsb) – C:\WINDOWS\system32\drivers\OmniUsb.sys (Ideazon)
DRV - (OmniUsbl) – C:\WINDOWS\system32\drivers\OmniUsbl.sys (Ideazon)
DRV - (bcgame) – C:\WINDOWS\system32\drivers\bcgame.sys (Belkin Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "
http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.126
FF - prefs.js..keyword.URL: "
http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="
FF - user.js..keyword.URL: "
http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/08/18 09:27:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/12 18:33:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:33:08 | 000,000,000 | —D | M]
[2010/03/01 12:28:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Extensions
[2011/12/07 11:56:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions
[2010/07/29 14:23:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 16:24:51 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2011/02/13 01:02:50 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/12/05 11:05:31 | 000,000,000 | —D | M] (Panda3D Game Engine Plug-In) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\[removed]
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\searchplugins\google-search.xml
[2011/12/12 18:33:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/11/06 18:38:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/12 18:32:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/02/13 01:02:43 | 000,002,191 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/12 18:32:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml
[2011/12/12 18:32:50 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Free Realms Installer (Enabled) = C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\
Hosts file not found
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk = C:\WINDOWS\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715}
http://www.creative.com/softwareupdate/su/…031/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://support.gateway.com/support/profiler/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E}
http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1164590853718 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Groove Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94}
http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} http://ak.g.gametap.com/static/cab_headles…pWebUpdater.cab (GameTap Web Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A}
http://www.miniclip.com/igloader/igloader.CAB (igLoader Content on Demand)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://www.creative.com/softwareupdate/su/…15034/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613FD09C-E86D-49AD-8B65-E2D3345F44F6}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Gone Fishing.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Gone Fishing.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/16 17:32:00 | 000,000,000 | —D | M] - G:\Autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*
NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/23 12:39:21 | 001,917,952 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 08:47:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/20 10:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/12/20 10:38:47 | 000,157,184 | —- | C] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/05 11:49:38 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/02 09:07:20 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/01 14:34:18 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/30 17:23:46 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/11/30 17:23:46 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/11/30 17:23:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/11/30 17:23:46 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/11/30 17:22:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/11/30 17:21:30 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/30 17:00:35 | 004,325,721 | R— | C] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/11/28 10:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files
[2011/11/28 08:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/11/23 14:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2008/01/27 11:07:40 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/23 12:39:29 | 001,917,952 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 11:55:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/23 10:32:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/23 10:32:18 | 1072,222,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 08:47:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/22 16:39:31 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Owner.job
[2011/12/21 11:49:01 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/21 09:13:51 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 09:13:51 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | M] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,157,184 | —- | M] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:04:17 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.CDF
[2011/12/19 19:20:38 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.BAK
[2011/12/19 16:51:28 | 000,001,554 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/12/15 16:39:59 | 000,120,320 | —- | M] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/14 09:40:19 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/14 03:38:37 | 000,169,096 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 03:18:07 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/08 11:48:35 | 000,242,176 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/06 11:24:22 | 000,000,058 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/12/06 11:24:22 | 000,000,020 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/12/05 18:00:15 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/12/03 16:33:39 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/12/02 09:07:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/02 09:04:55 | 004,325,721 | R— | M] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/12/01 13:40:49 | 000,000,339 | —- | M] () – C:\Boot.bak
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/20 15:55:02 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:42:31 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:28:21 | 1072,222,208 | -HS- | C] () – C:\hiberfil.sys
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/15 16:39:59 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/12 18:33:12 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/30 17:27:35 | 000,000,339 | —- | C] () – C:\Boot.bak
[2011/11/30 17:27:32 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/11/30 17:23:46 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/30 17:23:46 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/30 17:23:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/30 17:23:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/30 17:23:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/11/19 13:41:12 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\vUJh4.com.b
[2011/11/19 10:29:50 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\M70hHbEm.dat
[2011/10/25 19:58:29 | 000,000,057 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Ament.ini
[2011/10/23 10:18:51 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/09/22 16:15:55 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/09 08:18:45 | 000,165,155 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2011/07/09 08:18:44 | 000,007,262 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2011/04/06 16:50:00 | 000,019,333 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/10/10 14:56:23 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/10/10 14:56:23 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/09/30 16:01:04 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/30 16:01:00 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/30 16:01:00 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/09/15 07:07:37 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/10 05:03:00 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/04/24 23:04:15 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2009/04/24 23:00:51 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/04/24 22:12:34 | 000,000,468 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SamsungLiveUpdateConfig.ini
[2009/03/15 12:30:44 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/03/14 14:42:35 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PnkBstrK.sys
[2009/01/09 21:45:34 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/01/03 20:10:44 | 000,004,580 | —- | C] () – C:\WINDOWS\fred2_open_3_6_9.INI
[2008/11/30 21:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2008/11/27 09:29:04 | 000,018,523 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kibyjed.inf
[2008/11/27 09:29:04 | 000,018,463 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\opanogohi.vbs
[2008/11/27 09:29:04 | 000,017,581 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\xizumafuw._dl
[2008/11/27 09:29:04 | 000,017,525 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ober.scr
[2008/11/27 09:29:04 | 000,016,731 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\dujevule.com
[2008/11/27 09:29:04 | 000,015,568 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\nocox.pif
[2008/11/27 09:29:04 | 000,014,980 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nihivizi.dat
[2008/11/27 09:29:04 | 000,014,823 | —- | C] () – C:\Program Files\Common Files\alyxit._sy
[2008/11/27 09:29:04 | 000,014,730 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\apog.bat
[2008/11/27 09:29:04 | 000,011,969 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\sydyfubymu.scr
[2008/11/27 09:29:04 | 000,011,460 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\wybopom.ban
[2008/11/27 09:29:04 | 000,010,984 | —- | C] () – C:\Documents and Settings\All Users\Application Data\qijamete.sys
[2008/11/27 09:29:04 | 000,010,758 | —- | C] () – C:\WINDOWS\System32\naza.dat
[2008/11/27 08:59:41 | 000,013,285 | —- | C] () – C:\Documents and Settings\All Users\Application Data\deragytusy.dl
[2008/11/23 15:27:06 | 000,010,905 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\quluruve.pif
[2008/11/23 15:27:04 | 000,019,121 | —- | C] () – C:\Documents and Settings\All Users\Application Data\xozisixa.dl
[2008/11/23 15:27:04 | 000,013,147 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\zavi.lib
[2008/11/23 15:27:04 | 000,012,953 | —- | C] () – C:\WINDOWS\lizefo.sys
[2008/11/23 15:27:02 | 000,016,463 | —- | C] () – C:\Program Files\Common Files\vagawus.vbs
[2008/11/23 15:27:02 | 000,015,842 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edetamilo.sys
[2008/11/23 15:27:02 | 000,015,758 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\mypiryhive.lib
[2008/11/23 15:27:02 | 000,010,549 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xofiwu._sy
[2008/11/23 15:27:01 | 000,019,694 | —- | C] () – C:\Program Files\Common Files\uqorezyli._dl
[2008/11/23 15:27:01 | 000,014,346 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edynozyh.sys
[2008/11/23 15:27:00 | 000,012,439 | —- | C] () – C:\Program Files\Common Files\rabyrigit._sy
[2008/11/20 10:27:27 | 000,018,915 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\jobaf.inf
[2008/11/20 10:27:27 | 000,018,370 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nobogila.exe
[2008/11/20 10:27:27 | 000,016,794 | —- | C] () – C:\Documents and Settings\All Users\Application Data\cihyjamo.bin
[2008/11/20 10:27:27 | 000,016,036 | —- | C] () – C:\Program Files\Common Files\duxugi.sys
[2008/11/20 10:27:27 | 000,015,737 | —- | C] () – C:\Program Files\Common Files\yrura.com
[2008/11/20 10:27:27 | 000,014,557 | —- | C] () – C:\WINDOWS\System32\poxufe.com
[2008/11/20 10:27:27 | 000,012,088 | —- | C] () – C:\Program Files\Common Files\medaxoruh.lib
[2008/11/20 10:27:27 | 000,011,695 | —- | C] () – C:\Documents and Settings\All Users\Application Data\wasalagasi.dat
[2008/11/20 10:27:27 | 000,011,243 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\oqodezutub.ban
[2008/11/20 10:27:26 | 000,019,418 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\anucec.reg
[2008/11/20 10:27:26 | 000,017,242 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ticex.dl
[2008/11/20 10:27:26 | 000,014,664 | —- | C] () – C:\WINDOWS\refobuxo.sys
[2008/11/20 10:27:26 | 000,013,492 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\betuma.lib
[2008/11/20 10:27:26 | 000,012,888 | —- | C] () – C:\WINDOWS\System32\adiky.exe
[2008/11/20 10:27:26 | 000,011,632 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\iripo.dl
[2008/11/20 10:27:26 | 000,011,113 | —- | C] () – C:\WINDOWS\vyvuqa.com
[2008/11/20 09:50:13 | 000,018,974 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\warem.pif
[2008/11/20 09:50:13 | 000,015,151 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ulyxoto.exe
[2008/11/20 09:50:04 | 000,019,547 | —- | C] () – C:\WINDOWS\System32\doci.dll
[2008/11/20 09:50:04 | 000,018,231 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\gonyqeqeci.reg
[2008/11/20 09:50:04 | 000,017,881 | —- | C] () – C:\WINDOWS\omolygedy.bin
[2008/11/20 09:50:04 | 000,017,705 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sofozofufy.lib
[2008/11/20 09:50:04 | 000,016,990 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xosat.pif
[2008/11/20 09:50:04 | 000,010,386 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xesyca._sy
[2008/11/20 09:50:03 | 000,011,975 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\neqolim._dl
[2008/11/20 09:49:59 | 000,017,831 | —- | C] () – C:\Program Files\Common Files\akisyfus.dll
[2008/11/20 09:49:59 | 000,017,701 | —- | C] () – C:\Documents and Settings\All Users\Application Data\enilokax.vbs
[2008/11/20 09:49:59 | 000,016,902 | —- | C] () – C:\WINDOWS\System32\palon.sys
[2008/11/20 09:49:58 | 000,019,572 | —- | C] () – C:\Documents and Settings\All Users\Application Data\refux.dl
[2008/11/02 14:37:47 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/23 09:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/05/26 08:44:55 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/26 08:44:55 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/26 08:44:55 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/27 12:48:21 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/20 09:03:29 | 000,107,832 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/02/18 09:55:08 | 000,000,031 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:09:02 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/01/27 11:09:01 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2008/01/27 11:08:12 | 000,035,674 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2008/01/27 11:08:12 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/01/27 11:08:01 | 000,251,970 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2008/01/27 11:08:00 | 000,189,490 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2008/01/27 11:08:00 | 000,142,968 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2008/01/27 11:08:00 | 000,114,972 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2008/01/27 11:08:00 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2008/01/27 11:07:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2008/01/27 11:07:53 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2008/01/27 11:07:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2008/01/27 11:07:51 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/01/27 11:07:51 | 000,000,192 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/01/26 21:19:36 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2007/11/13 11:43:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/11/09 18:16:09 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2007/10/28 09:50:40 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\UPDATE.INI
[2007/10/28 09:28:46 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/09/22 17:33:40 | 000,020,394 | —- | C] () – C:\WINDOWS\W2BNEUnin.dat
[2007/08/10 20:11:13 | 000,078,848 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2007/03/07 21:30:47 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2007/03/07 21:30:46 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/02/17 20:19:58 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2007/02/02 09:29:23 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/18 23:05:38 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/11/18 23:05:38 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/11/18 23:05:38 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/18 23:05:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/11/18 23:05:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\vorbisfile.dll
[2006/11/18 23:05:36 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/11/18 23:00:05 | 000,242,176 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 16:57:03 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\jesterss.dll
[2006/09/08 16:54:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 16:53:25 | 000,550,912 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2006/09/08 16:53:25 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2006/09/08 16:53:25 | 000,042,040 | —- | C] () – C:\WINDOWS\PatchWnd.exe
[2006/09/08 16:53:25 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2006/09/08 16:53:25 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/09/08 16:53:25 | 000,011,776 | —- | C] () – C:\WINDOWS\HIDMNT.dll
[2006/09/08 16:53:04 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2006/09/08 16:50:04 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/09/08 16:41:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/08 16:16:44 | 000,112,421 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/08/11 18:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 18:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/30 03:27:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/30 02:53:00 | 000,352,256 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2006/05/31 20:35:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/31 20:29:32 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/31 20:17:16 | 000,001,202 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/31 20:17:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2006/05/31 20:16:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/05/31 20:16:58 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/31 20:16:58 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/05/31 20:16:58 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/31 20:16:58 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/05/31 20:16:57 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/05/31 20:16:57 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/05/31 20:16:57 | 000,049,156 | —- | C] () – C:\WINDOWS\System32\certstore.dat
[2006/05/31 20:16:57 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/05/31 20:16:57 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/05/31 20:16:57 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/31 20:16:52 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/05/31 20:16:51 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/05/31 13:24:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/31 13:23:17 | 000,169,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/03 23:15:54 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 11:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 16:04:24 | 001,163,264 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 16:04:24 | 001,040,384 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 16:04:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 16:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/06/27 12:31:00 | 000,039,611 | —- | C] () – C:\WINDOWS\System32\biosid.exe
[1999/01/22 11:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
========== LOP Check ==========
[2009/10/02 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activision
[2009/10/16 13:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dingogames
[2009/12/23 19:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Divinity 2
[2008/04/27 14:28:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/09/09 17:00:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/09/03 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2008/11/14 18:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/02/02 11:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap Web Player
[2009/04/25 10:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/02/27 21:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell1
[2011/02/27 21:10:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell4
[2009/12/08 11:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/09/30 15:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/25 15:23:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/10 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/04/27 12:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/02/17 15:36:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Shockwave
[2009/10/30 17:14:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2010/01/15 08:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/15 17:07:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/30 17:14:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F8999601-BE77-433E-A70A-B7766E47AE73}
[2009/10/02 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\acccore
[2008/07/24 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Ace
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Activision
[2010/01/15 08:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Aim
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Belkin
[2010/04/30 17:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Bioshock
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\dingogames
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GamesFaction
[2009/09/12 07:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GrabPro
[2010/08/27 12:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Helios
[2007/03/22 21:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Leadertech
[2008/11/13 18:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mushroom Age
[2011/12/20 10:04:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Orbit
[2009/05/21 15:08:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Pi Eye Games
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PlayFirst
[2010/08/03 06:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ProgSense
[2008/06/21 18:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sahmon Games
[2006/09/08 16:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SampleView
[2008/02/08 15:19:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sierra Entertainment
[2011/02/11 16:37:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sony Online Entertainment
[2009/10/30 17:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Stardock
[2008/10/04 16:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\StoneLoopsSW
[2008/09/05 18:57:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\ApplicaLS\x00\x00\x00\x00