This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe and 'open with' dialog box problem [Solved]

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well, this is frustrating. I just recently got RID of the ping.exe issue about 3 weeks ago, but it appears to be more widespread and I've picked up another variant. This time, the ping.exe process still sucks up all my CPU and memory and I can still kill it manually in Win TM, but this time, when i try to open programs, an "open with" box appears instead of just opening the program. I'm running WinXP Pro with Symantec AV and MBAM, although Symantec AV now won't run. You all have been great previously, thanks for the help! I was only able to use DDS, so here's the log: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 8:54:57.61 on Fri 12/23/2011 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_24 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.551 [GMT -7:00] . AV: AVG Anti-Virus *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\FolderSize\FolderSizeSvc.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\UAService7.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\System32\svchost.exe -k NecUsbSevice C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Orbitdownloader\orbitdm.exe C:\Program Files\Orbitdownloader\orbitnet.exe C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = hxxp://www.google.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [Power2GoExpress] NA uRunOnce: [Shockwave Updater] "c:\windows\system32\adobe\shockwave 11\SwHelper_1161629.exe" -Update mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [readericon] c:\program files\digital media reader\readericon45G.exe mRun: [CHotkey] zHotkey.exe mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall mRun: [CTHelper] CTHELPER.EXE mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [Jet Detection] "c:\program files\creative\sblive\program\ADGJDet.exe" mRun: [Name of App] c:\program files\samsung\fw liveupdate\FWManager.exe r mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10c.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\loadou~1.lnk - c:\program files\belkin\nostromo\nost_LM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nostro~1.lnk - c:\windows\installer\{548c7b77-8b04-427e-acd0-d0e6e6e59bcf}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201 IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204 IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203 IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: mswsock.dll Trusted Zone: aol.com\free Trusted Zone: clonewarsadventures.com Trusted Zone: freerealms.com Trusted Zone: soe.com Trusted Zone: sony.com DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://support.gateway.com/support/profiler/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.systemrequirementslab.com/sysreqlab2.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164590853718 DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://download.shockwave.com/pub/otoy/OTOYAX.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} - hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} - hxxp://support.gateway.com/support/serialharvest/gwCID.CAB DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://ak.g.gametap.com/static/cab_headless/GameTapWebUpdater.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} - hxxp://www.miniclip.com/igloader/igloader.CAB DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Notify: AtiExtEvent - Ati2evxx.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: NecUsb3Sevice - USB3Nw32.dll Notify: USB3Nw32 - USB3Nw32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe" . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\owner~1.you\applic~1\mozilla\firefox\profiles\0mshh979.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q= FF - component: c:\documents and settings\owner.your-880d7dc693\application data\mozilla\firefox\profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFExternalAlert.dll FF - component: c:\documents and settings\owner.your-880d7dc693\application data\mozilla\firefox\profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\RadioWMPCore.dll FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom.dll FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\documents and settings\owner.your-880d7dc693\application data\mozilla\firefox\profiles\0mshh979.default\extensions\{38ab6a6c-cc4c-4f9e-a3dd-3c5681ef18a1}\plugins\npsoe.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll . —- FIREFOX POLICIES —- FF - user.js: keyword.URL - hxxp://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q= . ============= SERVICES / DRIVERS =============== . R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2008-5-28 337280] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2008-5-28 54656] R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2011-12-15 120320] R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [2007-8-10 78848] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2008-6-24 191848] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2008-6-24 169320] R2 NecUsb;USB Service;c:\windows\system32\svchost.exe -k NecUsbSevice [2006-5-31 14336] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-9-22 2253120] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-10-2 24652] R3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-7-23 22821] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-12-16 106104] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20111216.002\naveng.sys [2011-12-16 86136] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20111216.002\navex15.sys [2011-12-16 1576312] R3 Net6IM;Net6;c:\windows\system32\drivers\net6im51.sys [2008-6-26 48280] S2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2008-9-30 1956792] S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys –> c:\windows\system32\drivers\EagleXNt.sys [?] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2008-9-30 116664] S3 XDva375;XDva375;\??\c:\windows\system32\xdva375.sys –> c:\windows\system32\XDva375.sys [?] . =============== File Associations =============== . .exe=DqF . =============== Created Last 30 ================ . 2011-12-23 15:47:18 94896 —-a-w- c:\windows\system32\drivers\02159170.sys 2011-12-20 17:38:49 53248 —-a-w- c:\windows\system32\6to4v32.dll 2011-12-20 17:38:47 37888 —-a-w- c:\windows\system32\USB3Nw32.dll 2011-12-20 17:38:47 157184 —-a-w- c:\windows\system32\NUSB3w32.dll 2011-12-15 23:39:59 120320 —-a-w- c:\windows\system32\drivers\SSHDRV65.sys 2011-12-13 01:33:00 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-12-13 01:32:59 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-12-13 01:32:58 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-12-13 01:32:56 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-12-13 01:32:56 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-12-13 01:32:56 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-12-13 01:32:54 801752 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-12-13 01:32:54 1989592 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-12-02 16:07:20 ——– d-sha-r- C:\cmdcons 2011-12-01 21:34:18 ——– d—–w- c:\program files\ESET 2011-12-01 00:23:46 98816 —-a-w- c:\windows\sed.exe 2011-12-01 00:23:46 518144 —-a-w- c:\windows\SWREG.exe 2011-12-01 00:23:46 256000 —-a-w- c:\windows\PEV.exe 2011-12-01 00:23:46 208896 —-a-w- c:\windows\MBR.exe 2011-11-28 15:48:25 ——– d—–w- c:\windows\system32\NtmsData . ==================== Find3M ==================== . 2011-12-14 16:40:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-06 01:00:15 107888 —-a-w- c:\windows\system32\CmdLineExt.dll 2011-12-03 23:33:39 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll 2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll 2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-26 00:46:04 285176 —-a-w- c:\windows\system32\nvdrsdb1.bin 2011-10-26 00:46:04 1 —-a-w- c:\windows\system32\nvdrssel.bin 2011-10-26 00:45:57 285176 —-a-w- c:\windows\system32\nvdrsdb0.bin 2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 17:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 17:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 17:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2008-11-23 22:27:02 16463 —-a-w- c:\program files\common files\vagawus.vbs 2008-11-20 17:27:27 16036 —-a-w- c:\program files\common files\duxugi.sys 2008-11-20 17:27:27 15737 —-a-w- c:\program files\common files\yrura.com 2008-11-20 16:49:59 17831 —-a-w- c:\program files\common files\akisyfus.dll . ============= FINISH: 8:56:18.87 ===============
Hi BMan, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

This will give us a bit better look.

Download OTL to your desktop.

*Before you download it please rename it to OTL.scr
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Next


Download aswMBR.exe to your desktop.

*Before you download it please rename it to aswMBR.scr

If asked to download Avast's database please do so.

Double click the aswMBR.scr to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • Both OTL logs
  • aswMBR log
  • mbr.zip(attached)
Thanks for the quick responses! I may have fired off the AswMBR log too, so I saved it again. I don't think it screwed anything up, but let me know if I need to rerun. It definitely found several problems.
BMan


OTL logfile created on: 12/23/2011 12:56:52 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 553.87 Mb Available Physical Memory | 54.17% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.61% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.60 Gb Total Space | 128.20 Gb Free Space | 70.60% Space Free | Partition Type: NTFS
Drive D: | 4.70 Gb Total Space | 2.73 Gb Free Space | 57.98% Space Free | Partition Type: FAT32
Drive F: | 56.76 Gb Total Space | 7.22 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive G: | 76.37 Gb Total Space | 11.18 Gb Free Space | 14.64% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 11.46 Gb Free Space | 58.68% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 3.58 Gb Free Space | 3.20% Space Free | Partition Type: NTFS

Computer Name: GAMEBOX | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\6to4v32.dll ()
MOD - C:\WINDOWS\system32\USB3Nw32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PLFlash DeviceIoControl Service) – File not found
SRV - (6to4) – C:\WINDOWS\system32\6to4v32.dll ()
SRV - (NecUsb) – C:\WINDOWS\system32\NUSB3w32.dll (Intel Corporation )
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
SRV - (FolderSize) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SSHDRV65) – C:\WINDOWS\system32\drivers\SSHDRV65.sys ()
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (Net6IM) – C:\WINDOWS\system32\drivers\net6im51.sys (Citrix Systems, Inc.)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SSHDRV85) – C:\WINDOWS\system32\drivers\SSHDRV85.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (OmniUsb) – C:\WINDOWS\system32\drivers\OmniUsb.sys (Ideazon)
DRV - (OmniUsbl) – C:\WINDOWS\system32\drivers\OmniUsbl.sys (Ideazon)
DRV - (bcgame) – C:\WINDOWS\system32\drivers\bcgame.sys (Belkin Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.126
FF - prefs.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - user.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/08/18 09:27:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/12 18:33:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:33:08 | 000,000,000 | —D | M]

[2010/03/01 12:28:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Extensions
[2011/12/07 11:56:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions
[2010/07/29 14:23:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 16:24:51 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2011/02/13 01:02:50 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/12/05 11:05:31 | 000,000,000 | —D | M] (Panda3D Game Engine Plug-In) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\[removed]
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\searchplugins\google-search.xml
[2011/12/12 18:33:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/11/06 18:38:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/12 18:32:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/02/13 01:02:43 | 000,002,191 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/12 18:32:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml
[2011/12/12 18:32:50 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Free Realms Installer (Enabled) = C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\

Hosts file not found
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk = C:\WINDOWS\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/softwareupdate/su/…031/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://support.gateway.com/support/profiler/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1164590853718 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Groove Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} http://ak.g.gametap.com/static/cab_headles…pWebUpdater.cab (GameTap Web Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} http://www.miniclip.com/igloader/igloader.CAB (igLoader Content on Demand)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15034/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613FD09C-E86D-49AD-8B65-E2D3345F44F6}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Gone Fishing.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Gone Fishing.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/16 17:32:00 | 000,000,000 | —D | M] - G:\Autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/23 12:39:21 | 001,917,952 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 08:47:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/20 10:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/12/20 10:38:47 | 000,157,184 | —- | C] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/05 11:49:38 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/02 09:07:20 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/01 14:34:18 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/30 17:23:46 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/11/30 17:23:46 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/11/30 17:23:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/11/30 17:23:46 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/11/30 17:22:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/11/30 17:21:30 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/30 17:00:35 | 004,325,721 | R— | C] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/11/28 10:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files
[2011/11/28 08:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/11/23 14:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2008/01/27 11:07:40 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/23 12:39:29 | 001,917,952 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 11:55:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/23 10:32:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/23 10:32:18 | 1072,222,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 08:47:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/22 16:39:31 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Owner.job
[2011/12/21 11:49:01 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/21 09:13:51 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 09:13:51 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | M] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,157,184 | —- | M] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:04:17 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.CDF
[2011/12/19 19:20:38 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.BAK
[2011/12/19 16:51:28 | 000,001,554 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/12/15 16:39:59 | 000,120,320 | —- | M] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/14 09:40:19 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/14 03:38:37 | 000,169,096 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 03:18:07 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/08 11:48:35 | 000,242,176 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/06 11:24:22 | 000,000,058 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/12/06 11:24:22 | 000,000,020 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/12/05 18:00:15 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/12/03 16:33:39 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/12/02 09:07:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/02 09:04:55 | 004,325,721 | R— | M] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/12/01 13:40:49 | 000,000,339 | —- | M] () – C:\Boot.bak
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/20 15:55:02 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:42:31 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:28:21 | 1072,222,208 | -HS- | C] () – C:\hiberfil.sys
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/15 16:39:59 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/12 18:33:12 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/30 17:27:35 | 000,000,339 | —- | C] () – C:\Boot.bak
[2011/11/30 17:27:32 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/11/30 17:23:46 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/30 17:23:46 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/30 17:23:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/30 17:23:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/30 17:23:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/11/19 13:41:12 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\vUJh4.com.b
[2011/11/19 10:29:50 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\M70hHbEm.dat
[2011/10/25 19:58:29 | 000,000,057 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Ament.ini
[2011/10/23 10:18:51 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/09/22 16:15:55 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/09 08:18:45 | 000,165,155 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2011/07/09 08:18:44 | 000,007,262 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2011/04/06 16:50:00 | 000,019,333 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/10/10 14:56:23 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/10/10 14:56:23 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/09/30 16:01:04 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/30 16:01:00 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/30 16:01:00 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/09/15 07:07:37 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/10 05:03:00 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/04/24 23:04:15 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2009/04/24 23:00:51 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/04/24 22:12:34 | 000,000,468 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SamsungLiveUpdateConfig.ini
[2009/03/15 12:30:44 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/03/14 14:42:35 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PnkBstrK.sys
[2009/01/09 21:45:34 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/01/03 20:10:44 | 000,004,580 | —- | C] () – C:\WINDOWS\fred2_open_3_6_9.INI
[2008/11/30 21:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2008/11/27 09:29:04 | 000,018,523 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kibyjed.inf
[2008/11/27 09:29:04 | 000,018,463 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\opanogohi.vbs
[2008/11/27 09:29:04 | 000,017,581 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\xizumafuw._dl
[2008/11/27 09:29:04 | 000,017,525 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ober.scr
[2008/11/27 09:29:04 | 000,016,731 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\dujevule.com
[2008/11/27 09:29:04 | 000,015,568 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\nocox.pif
[2008/11/27 09:29:04 | 000,014,980 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nihivizi.dat
[2008/11/27 09:29:04 | 000,014,823 | —- | C] () – C:\Program Files\Common Files\alyxit._sy
[2008/11/27 09:29:04 | 000,014,730 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\apog.bat
[2008/11/27 09:29:04 | 000,011,969 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\sydyfubymu.scr
[2008/11/27 09:29:04 | 000,011,460 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\wybopom.ban
[2008/11/27 09:29:04 | 000,010,984 | —- | C] () – C:\Documents and Settings\All Users\Application Data\qijamete.sys
[2008/11/27 09:29:04 | 000,010,758 | —- | C] () – C:\WINDOWS\System32\naza.dat
[2008/11/27 08:59:41 | 000,013,285 | —- | C] () – C:\Documents and Settings\All Users\Application Data\deragytusy.dl
[2008/11/23 15:27:06 | 000,010,905 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\quluruve.pif
[2008/11/23 15:27:04 | 000,019,121 | —- | C] () – C:\Documents and Settings\All Users\Application Data\xozisixa.dl
[2008/11/23 15:27:04 | 000,013,147 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\zavi.lib
[2008/11/23 15:27:04 | 000,012,953 | —- | C] () – C:\WINDOWS\lizefo.sys
[2008/11/23 15:27:02 | 000,016,463 | —- | C] () – C:\Program Files\Common Files\vagawus.vbs
[2008/11/23 15:27:02 | 000,015,842 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edetamilo.sys
[2008/11/23 15:27:02 | 000,015,758 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\mypiryhive.lib
[2008/11/23 15:27:02 | 000,010,549 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xofiwu._sy
[2008/11/23 15:27:01 | 000,019,694 | —- | C] () – C:\Program Files\Common Files\uqorezyli._dl
[2008/11/23 15:27:01 | 000,014,346 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edynozyh.sys
[2008/11/23 15:27:00 | 000,012,439 | —- | C] () – C:\Program Files\Common Files\rabyrigit._sy
[2008/11/20 10:27:27 | 000,018,915 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\jobaf.inf
[2008/11/20 10:27:27 | 000,018,370 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nobogila.exe
[2008/11/20 10:27:27 | 000,016,794 | —- | C] () – C:\Documents and Settings\All Users\Application Data\cihyjamo.bin
[2008/11/20 10:27:27 | 000,016,036 | —- | C] () – C:\Program Files\Common Files\duxugi.sys
[2008/11/20 10:27:27 | 000,015,737 | —- | C] () – C:\Program Files\Common Files\yrura.com
[2008/11/20 10:27:27 | 000,014,557 | —- | C] () – C:\WINDOWS\System32\poxufe.com
[2008/11/20 10:27:27 | 000,012,088 | —- | C] () – C:\Program Files\Common Files\medaxoruh.lib
[2008/11/20 10:27:27 | 000,011,695 | —- | C] () – C:\Documents and Settings\All Users\Application Data\wasalagasi.dat
[2008/11/20 10:27:27 | 000,011,243 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\oqodezutub.ban
[2008/11/20 10:27:26 | 000,019,418 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\anucec.reg
[2008/11/20 10:27:26 | 000,017,242 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ticex.dl
[2008/11/20 10:27:26 | 000,014,664 | —- | C] () – C:\WINDOWS\refobuxo.sys
[2008/11/20 10:27:26 | 000,013,492 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\betuma.lib
[2008/11/20 10:27:26 | 000,012,888 | —- | C] () – C:\WINDOWS\System32\adiky.exe
[2008/11/20 10:27:26 | 000,011,632 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\iripo.dl
[2008/11/20 10:27:26 | 000,011,113 | —- | C] () – C:\WINDOWS\vyvuqa.com
[2008/11/20 09:50:13 | 000,018,974 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\warem.pif
[2008/11/20 09:50:13 | 000,015,151 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ulyxoto.exe
[2008/11/20 09:50:04 | 000,019,547 | —- | C] () – C:\WINDOWS\System32\doci.dll
[2008/11/20 09:50:04 | 000,018,231 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\gonyqeqeci.reg
[2008/11/20 09:50:04 | 000,017,881 | —- | C] () – C:\WINDOWS\omolygedy.bin
[2008/11/20 09:50:04 | 000,017,705 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sofozofufy.lib
[2008/11/20 09:50:04 | 000,016,990 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xosat.pif
[2008/11/20 09:50:04 | 000,010,386 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xesyca._sy
[2008/11/20 09:50:03 | 000,011,975 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\neqolim._dl
[2008/11/20 09:49:59 | 000,017,831 | —- | C] () – C:\Program Files\Common Files\akisyfus.dll
[2008/11/20 09:49:59 | 000,017,701 | —- | C] () – C:\Documents and Settings\All Users\Application Data\enilokax.vbs
[2008/11/20 09:49:59 | 000,016,902 | —- | C] () – C:\WINDOWS\System32\palon.sys
[2008/11/20 09:49:58 | 000,019,572 | —- | C] () – C:\Documents and Settings\All Users\Application Data\refux.dl
[2008/11/02 14:37:47 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/23 09:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/05/26 08:44:55 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/26 08:44:55 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/26 08:44:55 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/27 12:48:21 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/20 09:03:29 | 000,107,832 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/02/18 09:55:08 | 000,000,031 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:09:02 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/01/27 11:09:01 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2008/01/27 11:08:12 | 000,035,674 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2008/01/27 11:08:12 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/01/27 11:08:01 | 000,251,970 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2008/01/27 11:08:00 | 000,189,490 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2008/01/27 11:08:00 | 000,142,968 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2008/01/27 11:08:00 | 000,114,972 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2008/01/27 11:08:00 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2008/01/27 11:07:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2008/01/27 11:07:53 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2008/01/27 11:07:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2008/01/27 11:07:51 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/01/27 11:07:51 | 000,000,192 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/01/26 21:19:36 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2007/11/13 11:43:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/11/09 18:16:09 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2007/10/28 09:50:40 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\UPDATE.INI
[2007/10/28 09:28:46 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/09/22 17:33:40 | 000,020,394 | —- | C] () – C:\WINDOWS\W2BNEUnin.dat
[2007/08/10 20:11:13 | 000,078,848 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2007/03/07 21:30:47 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2007/03/07 21:30:46 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/02/17 20:19:58 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2007/02/02 09:29:23 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/18 23:05:38 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/11/18 23:05:38 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/11/18 23:05:38 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/18 23:05:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/11/18 23:05:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\vorbisfile.dll
[2006/11/18 23:05:36 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/11/18 23:00:05 | 000,242,176 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 16:57:03 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\jesterss.dll
[2006/09/08 16:54:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 16:53:25 | 000,550,912 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2006/09/08 16:53:25 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2006/09/08 16:53:25 | 000,042,040 | —- | C] () – C:\WINDOWS\PatchWnd.exe
[2006/09/08 16:53:25 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2006/09/08 16:53:25 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/09/08 16:53:25 | 000,011,776 | —- | C] () – C:\WINDOWS\HIDMNT.dll
[2006/09/08 16:53:04 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2006/09/08 16:50:04 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/09/08 16:41:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/08 16:16:44 | 000,112,421 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/08/11 18:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 18:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/30 03:27:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/30 02:53:00 | 000,352,256 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2006/05/31 20:35:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/31 20:29:32 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/31 20:17:16 | 000,001,202 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/31 20:17:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2006/05/31 20:16:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/05/31 20:16:58 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/31 20:16:58 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/05/31 20:16:58 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/31 20:16:58 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/05/31 20:16:57 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/05/31 20:16:57 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/05/31 20:16:57 | 000,049,156 | —- | C] () – C:\WINDOWS\System32\certstore.dat
[2006/05/31 20:16:57 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/05/31 20:16:57 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/05/31 20:16:57 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/31 20:16:52 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/05/31 20:16:51 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/05/31 13:24:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/31 13:23:17 | 000,169,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/03 23:15:54 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 11:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 16:04:24 | 001,163,264 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 16:04:24 | 001,040,384 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 16:04:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 16:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/06/27 12:31:00 | 000,039,611 | —- | C] () – C:\WINDOWS\System32\biosid.exe
[1999/01/22 11:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2009/10/02 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activision
[2009/10/16 13:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dingogames
[2009/12/23 19:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Divinity 2
[2008/04/27 14:28:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/09/09 17:00:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/09/03 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2008/11/14 18:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/02/02 11:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap Web Player
[2009/04/25 10:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/02/27 21:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell1
[2011/02/27 21:10:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell4
[2009/12/08 11:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/09/30 15:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/25 15:23:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/10 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/04/27 12:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/02/17 15:36:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Shockwave
[2009/10/30 17:14:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2010/01/15 08:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/15 17:07:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/30 17:14:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F8999601-BE77-433E-A70A-B7766E47AE73}
[2009/10/02 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\acccore
[2008/07/24 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Ace
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Activision
[2010/01/15 08:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Aim
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Belkin
[2010/04/30 17:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Bioshock
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\dingogames
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GamesFaction
[2009/09/12 07:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GrabPro
[2010/08/27 12:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Helios
[2007/03/22 21:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Leadertech
[2008/11/13 18:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mushroom Age
[2011/12/20 10:04:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Orbit
[2009/05/21 15:08:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Pi Eye Games
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PlayFirst
[2010/08/03 06:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ProgSense
[2008/06/21 18:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sahmon Games
[2006/09/08 16:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SampleView
[2008/02/08 15:19:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sierra Entertainment
[2011/02/11 16:37:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sony Online Entertainment
[2009/10/30 17:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Stardock
[2008/10/04 16:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\StoneLoopsSW
[2008/09/05 18:57:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\ApplicaLS\x00\x00\x00\x00
Thanks for the quick responses! I may have fired off the AswMBR log too, so I saved it again. I don't think it screwed anything up, but let me know if I need to rerun. It definitely found several problems.
BMan


OTL logfile created on: 12/23/2011 12:56:52 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 553.87 Mb Available Physical Memory | 54.17% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.61% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.60 Gb Total Space | 128.20 Gb Free Space | 70.60% Space Free | Partition Type: NTFS
Drive D: | 4.70 Gb Total Space | 2.73 Gb Free Space | 57.98% Space Free | Partition Type: FAT32
Drive F: | 56.76 Gb Total Space | 7.22 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive G: | 76.37 Gb Total Space | 11.18 Gb Free Space | 14.64% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 11.46 Gb Free Space | 58.68% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 3.58 Gb Free Space | 3.20% Space Free | Partition Type: NTFS

Computer Name: GAMEBOX | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\6to4v32.dll ()
MOD - C:\WINDOWS\system32\USB3Nw32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PLFlash DeviceIoControl Service) – File not found
SRV - (6to4) – C:\WINDOWS\system32\6to4v32.dll ()
SRV - (NecUsb) – C:\WINDOWS\system32\NUSB3w32.dll (Intel Corporation )
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
SRV - (FolderSize) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SSHDRV65) – C:\WINDOWS\system32\drivers\SSHDRV65.sys ()
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (Net6IM) – C:\WINDOWS\system32\drivers\net6im51.sys (Citrix Systems, Inc.)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SSHDRV85) – C:\WINDOWS\system32\drivers\SSHDRV85.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (OmniUsb) – C:\WINDOWS\system32\drivers\OmniUsb.sys (Ideazon)
DRV - (OmniUsbl) – C:\WINDOWS\system32\drivers\OmniUsbl.sys (Ideazon)
DRV - (bcgame) – C:\WINDOWS\system32\drivers\bcgame.sys (Belkin Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.126
FF - prefs.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - user.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/08/18 09:27:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/12 18:33:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:33:08 | 000,000,000 | —D | M]

[2010/03/01 12:28:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Extensions
[2011/12/07 11:56:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions
[2010/07/29 14:23:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 16:24:51 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2011/02/13 01:02:50 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/12/05 11:05:31 | 000,000,000 | —D | M] (Panda3D Game Engine Plug-In) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\[removed]
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\searchplugins\google-search.xml
[2011/12/12 18:33:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/11/06 18:38:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/12 18:32:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/02/13 01:02:43 | 000,002,191 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/12 18:32:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml
[2011/12/12 18:32:50 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Free Realms Installer (Enabled) = C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\

Hosts file not found
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk = C:\WINDOWS\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/softwareupdate/su/…031/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://support.gateway.com/support/profiler/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1164590853718 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Groove Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} http://ak.g.gametap.com/static/cab_headles…pWebUpdater.cab (GameTap Web Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} http://www.miniclip.com/igloader/igloader.CAB (igLoader Content on Demand)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15034/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613FD09C-E86D-49AD-8B65-E2D3345F44F6}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Gone Fishing.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Gone Fishing.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/16 17:32:00 | 000,000,000 | —D | M] - G:\Autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/23 12:39:21 | 001,917,952 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 08:47:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/20 10:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/12/20 10:38:47 | 000,157,184 | —- | C] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/05 11:49:38 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/02 09:07:20 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/01 14:34:18 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/30 17:23:46 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/11/30 17:23:46 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/11/30 17:23:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/11/30 17:23:46 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/11/30 17:22:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/11/30 17:21:30 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/30 17:00:35 | 004,325,721 | R— | C] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/11/28 10:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files
[2011/11/28 08:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/11/23 14:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2008/01/27 11:07:40 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/23 12:39:29 | 001,917,952 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 11:55:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/23 10:32:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/23 10:32:18 | 1072,222,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 08:47:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/22 16:39:31 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Owner.job
[2011/12/21 11:49:01 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/21 09:13:51 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 09:13:51 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | M] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,157,184 | —- | M] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:04:17 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.CDF
[2011/12/19 19:20:38 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.BAK
[2011/12/19 16:51:28 | 000,001,554 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/12/15 16:39:59 | 000,120,320 | —- | M] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/14 09:40:19 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/14 03:38:37 | 000,169,096 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 03:18:07 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/08 11:48:35 | 000,242,176 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/06 11:24:22 | 000,000,058 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/12/06 11:24:22 | 000,000,020 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/12/05 18:00:15 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/12/03 16:33:39 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/12/02 09:07:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/02 09:04:55 | 004,325,721 | R— | M] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/12/01 13:40:49 | 000,000,339 | —- | M] () – C:\Boot.bak
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/20 15:55:02 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:42:31 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:28:21 | 1072,222,208 | -HS- | C] () – C:\hiberfil.sys
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/15 16:39:59 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/12 18:33:12 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/30 17:27:35 | 000,000,339 | —- | C] () – C:\Boot.bak
[2011/11/30 17:27:32 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/11/30 17:23:46 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/30 17:23:46 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/30 17:23:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/30 17:23:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/30 17:23:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/11/19 13:41:12 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\vUJh4.com.b
[2011/11/19 10:29:50 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\M70hHbEm.dat
[2011/10/25 19:58:29 | 000,000,057 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Ament.ini
[2011/10/23 10:18:51 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/09/22 16:15:55 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/09 08:18:45 | 000,165,155 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2011/07/09 08:18:44 | 000,007,262 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2011/04/06 16:50:00 | 000,019,333 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/10/10 14:56:23 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/10/10 14:56:23 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/09/30 16:01:04 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/30 16:01:00 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/30 16:01:00 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/09/15 07:07:37 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/10 05:03:00 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/04/24 23:04:15 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2009/04/24 23:00:51 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/04/24 22:12:34 | 000,000,468 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SamsungLiveUpdateConfig.ini
[2009/03/15 12:30:44 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/03/14 14:42:35 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PnkBstrK.sys
[2009/01/09 21:45:34 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/01/03 20:10:44 | 000,004,580 | —- | C] () – C:\WINDOWS\fred2_open_3_6_9.INI
[2008/11/30 21:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2008/11/27 09:29:04 | 000,018,523 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kibyjed.inf
[2008/11/27 09:29:04 | 000,018,463 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\opanogohi.vbs
[2008/11/27 09:29:04 | 000,017,581 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\xizumafuw._dl
[2008/11/27 09:29:04 | 000,017,525 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ober.scr
[2008/11/27 09:29:04 | 000,016,731 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\dujevule.com
[2008/11/27 09:29:04 | 000,015,568 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\nocox.pif
[2008/11/27 09:29:04 | 000,014,980 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nihivizi.dat
[2008/11/27 09:29:04 | 000,014,823 | —- | C] () – C:\Program Files\Common Files\alyxit._sy
[2008/11/27 09:29:04 | 000,014,730 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\apog.bat
[2008/11/27 09:29:04 | 000,011,969 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\sydyfubymu.scr
[2008/11/27 09:29:04 | 000,011,460 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\wybopom.ban
[2008/11/27 09:29:04 | 000,010,984 | —- | C] () – C:\Documents and Settings\All Users\Application Data\qijamete.sys
[2008/11/27 09:29:04 | 000,010,758 | —- | C] () – C:\WINDOWS\System32\naza.dat
[2008/11/27 08:59:41 | 000,013,285 | —- | C] () – C:\Documents and Settings\All Users\Application Data\deragytusy.dl
[2008/11/23 15:27:06 | 000,010,905 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\quluruve.pif
[2008/11/23 15:27:04 | 000,019,121 | —- | C] () – C:\Documents and Settings\All Users\Application Data\xozisixa.dl
[2008/11/23 15:27:04 | 000,013,147 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\zavi.lib
[2008/11/23 15:27:04 | 000,012,953 | —- | C] () – C:\WINDOWS\lizefo.sys
[2008/11/23 15:27:02 | 000,016,463 | —- | C] () – C:\Program Files\Common Files\vagawus.vbs
[2008/11/23 15:27:02 | 000,015,842 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edetamilo.sys
[2008/11/23 15:27:02 | 000,015,758 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\mypiryhive.lib
[2008/11/23 15:27:02 | 000,010,549 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xofiwu._sy
[2008/11/23 15:27:01 | 000,019,694 | —- | C] () – C:\Program Files\Common Files\uqorezyli._dl
[2008/11/23 15:27:01 | 000,014,346 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edynozyh.sys
[2008/11/23 15:27:00 | 000,012,439 | —- | C] () – C:\Program Files\Common Files\rabyrigit._sy
[2008/11/20 10:27:27 | 000,018,915 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\jobaf.inf
[2008/11/20 10:27:27 | 000,018,370 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nobogila.exe
[2008/11/20 10:27:27 | 000,016,794 | —- | C] () – C:\Documents and Settings\All Users\Application Data\cihyjamo.bin
[2008/11/20 10:27:27 | 000,016,036 | —- | C] () – C:\Program Files\Common Files\duxugi.sys
[2008/11/20 10:27:27 | 000,015,737 | —- | C] () – C:\Program Files\Common Files\yrura.com
[2008/11/20 10:27:27 | 000,014,557 | —- | C] () – C:\WINDOWS\System32\poxufe.com
[2008/11/20 10:27:27 | 000,012,088 | —- | C] () – C:\Program Files\Common Files\medaxoruh.lib
[2008/11/20 10:27:27 | 000,011,695 | —- | C] () – C:\Documents and Settings\All Users\Application Data\wasalagasi.dat
[2008/11/20 10:27:27 | 000,011,243 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\oqodezutub.ban
[2008/11/20 10:27:26 | 000,019,418 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\anucec.reg
[2008/11/20 10:27:26 | 000,017,242 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ticex.dl
[2008/11/20 10:27:26 | 000,014,664 | —- | C] () – C:\WINDOWS\refobuxo.sys
[2008/11/20 10:27:26 | 000,013,492 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\betuma.lib
[2008/11/20 10:27:26 | 000,012,888 | —- | C] () – C:\WINDOWS\System32\adiky.exe
[2008/11/20 10:27:26 | 000,011,632 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\iripo.dl
[2008/11/20 10:27:26 | 000,011,113 | —- | C] () – C:\WINDOWS\vyvuqa.com
[2008/11/20 09:50:13 | 000,018,974 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\warem.pif
[2008/11/20 09:50:13 | 000,015,151 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ulyxoto.exe
[2008/11/20 09:50:04 | 000,019,547 | —- | C] () – C:\WINDOWS\System32\doci.dll
[2008/11/20 09:50:04 | 000,018,231 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\gonyqeqeci.reg
[2008/11/20 09:50:04 | 000,017,881 | —- | C] () – C:\WINDOWS\omolygedy.bin
[2008/11/20 09:50:04 | 000,017,705 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sofozofufy.lib
[2008/11/20 09:50:04 | 000,016,990 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xosat.pif
[2008/11/20 09:50:04 | 000,010,386 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xesyca._sy
[2008/11/20 09:50:03 | 000,011,975 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\neqolim._dl
[2008/11/20 09:49:59 | 000,017,831 | —- | C] () – C:\Program Files\Common Files\akisyfus.dll
[2008/11/20 09:49:59 | 000,017,701 | —- | C] () – C:\Documents and Settings\All Users\Application Data\enilokax.vbs
[2008/11/20 09:49:59 | 000,016,902 | —- | C] () – C:\WINDOWS\System32\palon.sys
[2008/11/20 09:49:58 | 000,019,572 | —- | C] () – C:\Documents and Settings\All Users\Application Data\refux.dl
[2008/11/02 14:37:47 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/23 09:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/05/26 08:44:55 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/26 08:44:55 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/26 08:44:55 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/27 12:48:21 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/20 09:03:29 | 000,107,832 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/02/18 09:55:08 | 000,000,031 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:09:02 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/01/27 11:09:01 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2008/01/27 11:08:12 | 000,035,674 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2008/01/27 11:08:12 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/01/27 11:08:01 | 000,251,970 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2008/01/27 11:08:00 | 000,189,490 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2008/01/27 11:08:00 | 000,142,968 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2008/01/27 11:08:00 | 000,114,972 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2008/01/27 11:08:00 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2008/01/27 11:07:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2008/01/27 11:07:53 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2008/01/27 11:07:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2008/01/27 11:07:51 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/01/27 11:07:51 | 000,000,192 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/01/26 21:19:36 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2007/11/13 11:43:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/11/09 18:16:09 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2007/10/28 09:50:40 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\UPDATE.INI
[2007/10/28 09:28:46 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/09/22 17:33:40 | 000,020,394 | —- | C] () – C:\WINDOWS\W2BNEUnin.dat
[2007/08/10 20:11:13 | 000,078,848 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2007/03/07 21:30:47 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2007/03/07 21:30:46 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/02/17 20:19:58 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2007/02/02 09:29:23 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/18 23:05:38 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/11/18 23:05:38 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/11/18 23:05:38 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/18 23:05:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/11/18 23:05:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\vorbisfile.dll
[2006/11/18 23:05:36 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/11/18 23:00:05 | 000,242,176 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 16:57:03 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\jesterss.dll
[2006/09/08 16:54:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 16:53:25 | 000,550,912 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2006/09/08 16:53:25 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2006/09/08 16:53:25 | 000,042,040 | —- | C] () – C:\WINDOWS\PatchWnd.exe
[2006/09/08 16:53:25 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2006/09/08 16:53:25 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/09/08 16:53:25 | 000,011,776 | —- | C] () – C:\WINDOWS\HIDMNT.dll
[2006/09/08 16:53:04 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2006/09/08 16:50:04 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/09/08 16:41:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/08 16:16:44 | 000,112,421 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/08/11 18:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 18:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/30 03:27:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/30 02:53:00 | 000,352,256 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2006/05/31 20:35:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/31 20:29:32 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/31 20:17:16 | 000,001,202 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/31 20:17:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2006/05/31 20:16:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/05/31 20:16:58 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/31 20:16:58 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/05/31 20:16:58 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/31 20:16:58 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/05/31 20:16:57 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/05/31 20:16:57 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/05/31 20:16:57 | 000,049,156 | —- | C] () – C:\WINDOWS\System32\certstore.dat
[2006/05/31 20:16:57 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/05/31 20:16:57 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/05/31 20:16:57 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/31 20:16:52 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/05/31 20:16:51 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/05/31 13:24:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/31 13:23:17 | 000,169,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/03 23:15:54 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 11:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 16:04:24 | 001,163,264 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 16:04:24 | 001,040,384 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 16:04:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 16:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/06/27 12:31:00 | 000,039,611 | —- | C] () – C:\WINDOWS\System32\biosid.exe
[1999/01/22 11:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2009/10/02 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activision
[2009/10/16 13:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dingogames
[2009/12/23 19:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Divinity 2
[2008/04/27 14:28:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/09/09 17:00:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/09/03 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2008/11/14 18:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/02/02 11:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap Web Player
[2009/04/25 10:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/02/27 21:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell1
[2011/02/27 21:10:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell4
[2009/12/08 11:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/09/30 15:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/25 15:23:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/10 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/04/27 12:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/02/17 15:36:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Shockwave
[2009/10/30 17:14:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2010/01/15 08:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/15 17:07:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/30 17:14:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F8999601-BE77-433E-A70A-B7766E47AE73}
[2009/10/02 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\acccore
[2008/07/24 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Ace
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Activision
[2010/01/15 08:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Aim
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Belkin
[2010/04/30 17:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Bioshock
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\dingogames
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GamesFaction
[2009/09/12 07:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GrabPro
[2010/08/27 12:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Helios
[2007/03/22 21:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Leadertech
[2008/11/13 18:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mushroom Age
[2011/12/20 10:04:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Orbit
[2009/05/21 15:08:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Pi Eye Games
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PlayFirst
[2010/08/03 06:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ProgSense
[2008/06/21 18:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sahmon Games
[2006/09/08 16:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SampleView
[2008/02/08 15:19:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sierra Entertainment
[2011/02/11 16:37:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sony Online Entertainment
[2009/10/30 17:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Stardock
[2008/10/04 16:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\StoneLoopsSW
[2008/09/05 18:57:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\ApplicaLS\x00\x00\x00\x00
Thanks for the quick responses! I may have fired off the AswMBR log too, so I saved it again. I don't think it screwed anything up, but let me know if I need to rerun. It definitely found several problems.
BMan


OTL logfile created on: 12/23/2011 12:56:52 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 553.87 Mb Available Physical Memory | 54.17% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.61% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.60 Gb Total Space | 128.20 Gb Free Space | 70.60% Space Free | Partition Type: NTFS
Drive D: | 4.70 Gb Total Space | 2.73 Gb Free Space | 57.98% Space Free | Partition Type: FAT32
Drive F: | 56.76 Gb Total Space | 7.22 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive G: | 76.37 Gb Total Space | 11.18 Gb Free Space | 14.64% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 11.46 Gb Free Space | 58.68% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 3.58 Gb Free Space | 3.20% Space Free | Partition Type: NTFS

Computer Name: GAMEBOX | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr (OldTimer Tools)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\6to4v32.dll ()
MOD - C:\WINDOWS\system32\USB3Nw32.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PLFlash DeviceIoControl Service) – File not found
SRV - (6to4) – C:\WINDOWS\system32\6to4v32.dll ()
SRV - (NecUsb) – C:\WINDOWS\system32\NUSB3w32.dll (Intel Corporation )
SRV - (nvUpdatusService) – C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (SavRoam) – C:\Program Files\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (UserAccess7) SecuROM User Access Service (V7) – C:\WINDOWS\system32\UAService7.exe (Sony DADC Austria AG.)
SRV - (FolderSize) – C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (SPBBCSvc) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)


========== Driver Services (SafeList) ==========

DRV - (SSHDRV65) – C:\WINDOWS\system32\drivers\SSHDRV65.sys ()
DRV - (NAVEX15) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVEX15.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20111216.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (atksgt) – C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (Net6IM) – C:\WINDOWS\system32\drivers\net6im51.sys (Citrix Systems, Inc.)
DRV - (SAVRT) – C:\Program Files\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL) – C:\Program Files\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Serial) – C:\WINDOWS\system32\drivers\serial.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SSHDRV85) – C:\WINDOWS\system32\drivers\SSHDRV85.sys ()
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) – C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) – C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtlnicxp.sys (Realtek Semiconductor Corporation )
DRV - (OmniUsb) – C:\WINDOWS\system32\drivers\OmniUsb.sys (Ideazon)
DRV - (OmniUsbl) – C:\WINDOWS\system32\drivers\OmniUsbl.sys (Ideazon)
DRV - (bcgame) – C:\WINDOWS\system32\drivers\bcgame.sys (Belkin Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..extensions.enabledItems: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.126
FF - prefs.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - user.js..keyword.URL: "http://www.gisly.com/search/?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&rls=rWOh6jdt&q="

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll ()
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/08/18 09:27:04 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/12 18:33:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/12 18:33:08 | 000,000,000 | —D | M]

[2010/03/01 12:28:07 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Extensions
[2011/12/07 11:56:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions
[2010/07/29 14:23:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/29 16:24:51 | 000,000,000 | —D | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
[2011/02/13 01:02:50 | 000,000,000 | —D | M] (myBabylon English Toolbar) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2010/12/05 11:05:31 | 000,000,000 | —D | M] (Panda3D Game Engine Plug-In) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\[removed]
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\searchplugins\google-search.xml
[2011/12/12 18:33:17 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/11/06 18:38:12 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/12 18:32:59 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/02/13 01:02:43 | 000,002,191 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\babylon.xml
[2011/12/12 18:32:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/03/04 15:57:37 | 000,002,197 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google-search.xml
[2011/12/12 18:32:50 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.5.5 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome NaCl (Disabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\12.0.742.100\pdf.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Free Realms Installer (Enabled) = C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Unity Player (Enabled) = C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\

Hosts file not found
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CHotkey] C:\WINDOWS\zHotkey.exe ()
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe ( )
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe ()
O4 - HKLM..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\Recguard.exe ()
O4 - HKLM..\Run: [Reminder] C:\WINDOWS\creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Power2GoExpress] NA File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nostromo Loadout Manager.lnk = C:\WINDOWS\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe (Macrovision Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_24.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} http://www.creative.com/softwareupdate/su/…031/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://support.gateway.com/support/profiler/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab (System Requirements Lab Class)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemrequirementslab.com/sysreqlab2.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1164590853718 (MUWebControl Class)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} http://download.shockwave.com/pub/otoy/OTOYAX.cab (Groove Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin.disney.go.com/plugin/w…/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} http://support.gateway.com/support/serialharvest/gwCID.CAB (compid Class)
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} http://www.crucial.com/controls/cpcScanner.cab (Crucial cpcScan)
O16 - DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} http://ak.g.gametap.com/static/cab_headles…pWebUpdater.cab (GameTap Web Updater)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} http://www.miniclip.com/igloader/igloader.CAB (igLoader Content on Demand)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://www.creative.com/softwareupdate/su/…15034/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{613FD09C-E86D-49AD-8B65-E2D3345F44F6}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - (C:\WINDOWS\system32\NavLogon.dll) - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\NecUsb3Sevice: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O20 - Winlogon\Notify\USB3Nw32: DllName - (USB3Nw32.dll) - C:\WINDOWS\System32\USB3Nw32.dll ()
O24 - Desktop WallPaper: C:\WINDOWS\Gone Fishing.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Gone Fishing.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2008/08/16 17:32:00 | 000,000,000 | —D | M] - G:\Autorun – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*

NetSvcs: 6to4 - C:\WINDOWS\system32\6to4v32.dll ()
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/23 12:39:21 | 001,917,952 | —- | C] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 08:47:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/20 10:48:19 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/12/20 10:38:47 | 000,157,184 | —- | C] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/05 11:49:38 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2011/12/02 09:07:20 | 000,000,000 | RHSD | C] – C:\cmdcons
[2011/12/01 14:34:18 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/11/30 17:23:46 | 000,518,144 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2011/11/30 17:23:46 | 000,406,528 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2011/11/30 17:23:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2011/11/30 17:23:46 | 000,060,416 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2011/11/30 17:22:02 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2011/11/30 17:21:30 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/30 17:00:35 | 004,325,721 | R— | C] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/11/28 10:43:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files
[2011/11/28 08:48:25 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2011/11/23 14:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Sun
[2008/01/27 11:07:40 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/23 12:39:29 | 001,917,952 | —- | M] (AVAST Software) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\aswMBR.scr
[2011/12/23 12:36:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\OTL.scr
[2011/12/23 11:55:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/23 10:32:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/23 10:32:18 | 1072,222,208 | -HS- | M] () – C:\hiberfil.sys
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000001-00001102-00000002-80671102}.rfx
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2011/12/23 10:30:58 | 000,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 10:30:58 | 000,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2011/12/23 08:47:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\02159170.sys
[2011/12/22 16:39:31 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for Owner.job
[2011/12/21 11:49:01 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/21 09:13:51 | 000,103,733 | —- | M] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/21 09:13:51 | 000,000,197 | —- | M] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | M] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | M] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,157,184 | —- | M] (Intel Corporation ) – C:\WINDOWS\System32\NUSB3w32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | M] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:16:08 | 000,015,862 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 10:04:17 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.CDF
[2011/12/19 19:20:38 | 003,382,339 | —- | M] () – C:\WINDOWS\{00000002-00000000-00000001-00001102-00000002-80671102}.BAK
[2011/12/19 16:51:28 | 000,001,554 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
[2011/12/15 16:39:59 | 000,120,320 | —- | M] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/14 09:40:19 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/12/14 03:38:37 | 000,169,096 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/14 03:18:07 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/12/08 11:48:35 | 000,242,176 | —- | M] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/06 11:24:22 | 000,000,058 | -H– | M] () – C:\WINDOWS\popcreg.dat
[2011/12/06 11:24:22 | 000,000,020 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2011/12/05 18:00:15 | 000,107,888 | —- | M] (Sony DADC Austria AG.) – C:\WINDOWS\System32\CmdLineExt.dll
[2011/12/03 16:33:39 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/12/02 09:07:24 | 000,000,339 | RHS- | M] () – C:\boot.ini
[2011/12/02 09:04:55 | 004,325,721 | R— | M] (Swearware) – C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\ComboFix.exe
[2011/12/01 13:40:49 | 000,000,339 | —- | M] () – C:\Boot.bak
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/20 15:55:02 | 000,103,733 | —- | C] () – C:\WINDOWS\System32\itusbcore.dat
[2011/12/20 10:42:31 | 000,103,365 | —- | C] () – C:\WINDOWS\System32\itldvupd.dat
[2011/12/20 10:42:31 | 000,000,197 | —- | C] () – C:\WINDOWS\System32\itlsvc.dat
[2011/12/20 10:38:49 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\6to4v32.dll
[2011/12/20 10:38:47 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\USB3Nw32.dll
[2011/12/20 10:28:21 | 1072,222,208 | -HS- | C] () – C:\hiberfil.sys
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/20 09:57:26 | 000,015,862 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\441288x6v323s863q673j4kib3k3
[2011/12/15 16:39:59 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV65.sys
[2011/12/12 18:33:12 | 000,000,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/11/30 17:27:35 | 000,000,339 | —- | C] () – C:\Boot.bak
[2011/11/30 17:27:32 | 000,260,272 | RHS- | C] () – C:\cmldr
[2011/11/30 17:23:46 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/11/30 17:23:46 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/11/30 17:23:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/11/30 17:23:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/11/30 17:23:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/11/19 13:41:12 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\vUJh4.com.b
[2011/11/19 10:29:50 | 000,000,112 | —- | C] () – C:\Documents and Settings\All Users\Application Data\M70hHbEm.dat
[2011/10/25 19:58:29 | 000,000,057 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Ament.ini
[2011/10/23 10:18:51 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/09/22 16:15:55 | 002,130,002 | —- | C] () – C:\WINDOWS\System32\nvdata.data
[2011/07/09 08:18:45 | 000,165,155 | —- | C] () – C:\WINDOWS\hpoins21.dat
[2011/07/09 08:18:44 | 000,007,262 | —- | C] () – C:\WINDOWS\hpomdl21.dat
[2011/04/06 16:50:00 | 000,019,333 | —- | C] () – C:\WINDOWS\DIIUnin.dat
[2010/10/10 14:56:23 | 000,000,058 | -H– | C] () – C:\WINDOWS\popcreg.dat
[2010/10/10 14:56:23 | 000,000,020 | —- | C] () – C:\WINDOWS\popcinfot.dat
[2010/09/30 16:01:04 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2010/09/30 16:01:00 | 000,285,176 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2010/09/30 16:01:00 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2010/09/15 07:07:37 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/06/10 05:03:00 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2009/04/24 23:04:15 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2009/04/24 23:00:51 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/04/24 22:12:34 | 000,000,468 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SamsungLiveUpdateConfig.ini
[2009/03/15 12:30:44 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2009/03/14 14:42:35 | 000,022,328 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PnkBstrK.sys
[2009/01/09 21:45:34 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2009/01/03 20:10:44 | 000,004,580 | —- | C] () – C:\WINDOWS\fred2_open_3_6_9.INI
[2008/11/30 21:40:07 | 000,000,000 | —- | C] () – C:\WINDOWS\WININIT.INI
[2008/11/27 09:29:04 | 000,018,523 | —- | C] () – C:\Documents and Settings\All Users\Application Data\kibyjed.inf
[2008/11/27 09:29:04 | 000,018,463 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\opanogohi.vbs
[2008/11/27 09:29:04 | 000,017,581 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\xizumafuw._dl
[2008/11/27 09:29:04 | 000,017,525 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ober.scr
[2008/11/27 09:29:04 | 000,016,731 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\dujevule.com
[2008/11/27 09:29:04 | 000,015,568 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\nocox.pif
[2008/11/27 09:29:04 | 000,014,980 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nihivizi.dat
[2008/11/27 09:29:04 | 000,014,823 | —- | C] () – C:\Program Files\Common Files\alyxit._sy
[2008/11/27 09:29:04 | 000,014,730 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\apog.bat
[2008/11/27 09:29:04 | 000,011,969 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\sydyfubymu.scr
[2008/11/27 09:29:04 | 000,011,460 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\wybopom.ban
[2008/11/27 09:29:04 | 000,010,984 | —- | C] () – C:\Documents and Settings\All Users\Application Data\qijamete.sys
[2008/11/27 09:29:04 | 000,010,758 | —- | C] () – C:\WINDOWS\System32\naza.dat
[2008/11/27 08:59:41 | 000,013,285 | —- | C] () – C:\Documents and Settings\All Users\Application Data\deragytusy.dl
[2008/11/23 15:27:06 | 000,010,905 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\quluruve.pif
[2008/11/23 15:27:04 | 000,019,121 | —- | C] () – C:\Documents and Settings\All Users\Application Data\xozisixa.dl
[2008/11/23 15:27:04 | 000,013,147 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\zavi.lib
[2008/11/23 15:27:04 | 000,012,953 | —- | C] () – C:\WINDOWS\lizefo.sys
[2008/11/23 15:27:02 | 000,016,463 | —- | C] () – C:\Program Files\Common Files\vagawus.vbs
[2008/11/23 15:27:02 | 000,015,842 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edetamilo.sys
[2008/11/23 15:27:02 | 000,015,758 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\mypiryhive.lib
[2008/11/23 15:27:02 | 000,010,549 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xofiwu._sy
[2008/11/23 15:27:01 | 000,019,694 | —- | C] () – C:\Program Files\Common Files\uqorezyli._dl
[2008/11/23 15:27:01 | 000,014,346 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\edynozyh.sys
[2008/11/23 15:27:00 | 000,012,439 | —- | C] () – C:\Program Files\Common Files\rabyrigit._sy
[2008/11/20 10:27:27 | 000,018,915 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\jobaf.inf
[2008/11/20 10:27:27 | 000,018,370 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\nobogila.exe
[2008/11/20 10:27:27 | 000,016,794 | —- | C] () – C:\Documents and Settings\All Users\Application Data\cihyjamo.bin
[2008/11/20 10:27:27 | 000,016,036 | —- | C] () – C:\Program Files\Common Files\duxugi.sys
[2008/11/20 10:27:27 | 000,015,737 | —- | C] () – C:\Program Files\Common Files\yrura.com
[2008/11/20 10:27:27 | 000,014,557 | —- | C] () – C:\WINDOWS\System32\poxufe.com
[2008/11/20 10:27:27 | 000,012,088 | —- | C] () – C:\Program Files\Common Files\medaxoruh.lib
[2008/11/20 10:27:27 | 000,011,695 | —- | C] () – C:\Documents and Settings\All Users\Application Data\wasalagasi.dat
[2008/11/20 10:27:27 | 000,011,243 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\oqodezutub.ban
[2008/11/20 10:27:26 | 000,019,418 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\anucec.reg
[2008/11/20 10:27:26 | 000,017,242 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ticex.dl
[2008/11/20 10:27:26 | 000,014,664 | —- | C] () – C:\WINDOWS\refobuxo.sys
[2008/11/20 10:27:26 | 000,013,492 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\betuma.lib
[2008/11/20 10:27:26 | 000,012,888 | —- | C] () – C:\WINDOWS\System32\adiky.exe
[2008/11/20 10:27:26 | 000,011,632 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\iripo.dl
[2008/11/20 10:27:26 | 000,011,113 | —- | C] () – C:\WINDOWS\vyvuqa.com
[2008/11/20 09:50:13 | 000,018,974 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\warem.pif
[2008/11/20 09:50:13 | 000,015,151 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ulyxoto.exe
[2008/11/20 09:50:04 | 000,019,547 | —- | C] () – C:\WINDOWS\System32\doci.dll
[2008/11/20 09:50:04 | 000,018,231 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\gonyqeqeci.reg
[2008/11/20 09:50:04 | 000,017,881 | —- | C] () – C:\WINDOWS\omolygedy.bin
[2008/11/20 09:50:04 | 000,017,705 | —- | C] () – C:\Documents and Settings\All Users\Application Data\sofozofufy.lib
[2008/11/20 09:50:04 | 000,016,990 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xosat.pif
[2008/11/20 09:50:04 | 000,010,386 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\xesyca._sy
[2008/11/20 09:50:03 | 000,011,975 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\neqolim._dl
[2008/11/20 09:49:59 | 000,017,831 | —- | C] () – C:\Program Files\Common Files\akisyfus.dll
[2008/11/20 09:49:59 | 000,017,701 | —- | C] () – C:\Documents and Settings\All Users\Application Data\enilokax.vbs
[2008/11/20 09:49:59 | 000,016,902 | —- | C] () – C:\WINDOWS\System32\palon.sys
[2008/11/20 09:49:58 | 000,019,572 | —- | C] () – C:\Documents and Settings\All Users\Application Data\refux.dl
[2008/11/02 14:37:47 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/10/07 08:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/23 09:50:52 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/05/26 08:44:55 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/26 08:44:55 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/26 08:44:55 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/04/27 12:48:21 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2008/04/20 09:03:29 | 000,107,832 | —- | C] () – C:\WINDOWS\System32\PnkBstrB.exe
[2008/02/18 09:55:08 | 000,000,031 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 12:03:22 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000001-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:36:40 | 000,000,288 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000000-00001102-00000002-80671102}.dat
[2008/01/27 11:09:02 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/01/27 11:09:01 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2008/01/27 11:08:12 | 000,035,674 | —- | C] () – C:\WINDOWS\System32\Emu10kx.ini
[2008/01/27 11:08:12 | 000,000,029 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/01/27 11:08:01 | 000,251,970 | —- | C] () – C:\WINDOWS\System32\ctstatic.dat
[2008/01/27 11:08:00 | 000,189,490 | —- | C] () – C:\WINDOWS\System32\ctdlang.dat
[2008/01/27 11:08:00 | 000,142,968 | —- | C] () – C:\WINDOWS\System32\CTBAS2W.DAT
[2008/01/27 11:08:00 | 000,114,972 | —- | C] () – C:\WINDOWS\System32\ctbasicw.dat
[2008/01/27 11:08:00 | 000,053,674 | —- | C] () – C:\WINDOWS\System32\ctdaught.dat
[2008/01/27 11:07:54 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\REGPLIB.EXE
[2008/01/27 11:07:53 | 000,184,320 | —- | C] () – C:\WINDOWS\PSCONV.EXE
[2008/01/27 11:07:52 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\KILLAPPS.EXE
[2008/01/27 11:07:51 | 000,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/01/27 11:07:51 | 000,000,192 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/01/26 21:19:36 | 000,000,307 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2007/11/13 11:43:51 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2007/11/09 18:16:09 | 000,000,063 | —- | C] () – C:\WINDOWS\mdm.ini
[2007/10/28 09:50:40 | 000,000,258 | —- | C] () – C:\WINDOWS\System32\UPDATE.INI
[2007/10/28 09:28:46 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/09/22 17:33:40 | 000,020,394 | —- | C] () – C:\WINDOWS\W2BNEUnin.dat
[2007/08/10 20:11:13 | 000,078,848 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2007/03/07 21:30:47 | 000,281,504 | —- | C] () – C:\WINDOWS\System32\drivers\atksgt.sys
[2007/03/07 21:30:46 | 000,025,888 | —- | C] () – C:\WINDOWS\System32\drivers\lirsgt.sys
[2007/02/17 20:19:58 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2007/02/02 09:29:23 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/11/18 23:05:38 | 000,679,936 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/11/18 23:05:38 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2006/11/18 23:05:38 | 000,157,696 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2006/11/18 23:05:38 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/11/18 23:05:38 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\vorbisfile.dll
[2006/11/18 23:05:36 | 000,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2006/11/18 23:00:05 | 000,242,176 | —- | C] () – C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/09/08 16:57:03 | 000,023,552 | —- | C] () – C:\WINDOWS\System32\jesterss.dll
[2006/09/08 16:54:04 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/09/08 16:53:25 | 000,550,912 | —- | C] () – C:\WINDOWS\zHotkey.exe
[2006/09/08 16:53:25 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2006/09/08 16:53:25 | 000,042,040 | —- | C] () – C:\WINDOWS\PatchWnd.exe
[2006/09/08 16:53:25 | 000,036,864 | —- | C] () – C:\WINDOWS\ShowWnd.exe
[2006/09/08 16:53:25 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/09/08 16:53:25 | 000,011,776 | —- | C] () – C:\WINDOWS\HIDMNT.dll
[2006/09/08 16:53:04 | 000,000,004 | —- | C] () – C:\WINDOWS\Pix11.dat
[2006/09/08 16:50:04 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2006/09/08 16:41:43 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/09/08 16:16:44 | 000,112,421 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/08/11 18:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 18:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/06/30 03:27:33 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/06/30 02:53:00 | 000,352,256 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2006/05/31 20:35:05 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/05/31 20:29:32 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/05/31 20:17:16 | 000,001,202 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2006/05/31 20:17:16 | 000,000,491 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2006/05/31 20:16:59 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/05/31 20:16:58 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2006/05/31 20:16:58 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2006/05/31 20:16:58 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2006/05/31 20:16:58 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2006/05/31 20:16:57 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2006/05/31 20:16:57 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2006/05/31 20:16:57 | 000,049,156 | —- | C] () – C:\WINDOWS\System32\certstore.dat
[2006/05/31 20:16:57 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2006/05/31 20:16:57 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2006/05/31 20:16:57 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2006/05/31 20:16:52 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2006/05/31 20:16:51 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2006/05/31 13:24:17 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/05/31 13:23:17 | 000,169,096 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/03 23:15:54 | 000,064,512 | —- | C] () – C:\WINDOWS\System32\drivers\serial.sys
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/06 11:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 16:04:24 | 001,163,264 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 16:04:24 | 001,040,384 | —- | C] () – C:\WINDOWS\System32\vorbisenc.dll
[2002/10/04 16:04:16 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/05/15 16:38:40 | 000,091,136 | —- | C] () – C:\WINDOWS\System32\mp4fil32.dll
[2002/03/14 12:00:26 | 000,038,567 | —- | C] () – C:\WINDOWS\System32\pcpbios.exe
[2001/06/27 12:31:00 | 000,039,611 | —- | C] () – C:\WINDOWS\System32\biosid.exe
[1999/01/22 11:46:56 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2009/10/02 18:58:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Activision
[2009/10/16 13:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dingogames
[2009/12/23 19:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Divinity 2
[2008/04/27 14:28:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EscapeTheMuseum
[2008/09/09 17:00:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FarmFrenzy2
[2008/09/03 17:17:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2008/11/14 18:29:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fugazo
[2009/02/02 11:47:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameTap Web Player
[2009/04/25 10:31:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2011/02/27 21:10:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell1
[2011/02/27 21:10:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MinigolfVUG_TacoBell4
[2009/12/08 11:37:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/01/17 15:09:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2010/09/30 15:46:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/12/25 15:23:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2010/10/10 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/04/27 12:48:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2009/02/17 15:36:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Shockwave
[2009/10/30 17:14:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2010/01/15 08:41:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2007/06/15 17:07:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2009/10/30 17:14:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{F8999601-BE77-433E-A70A-B7766E47AE73}
[2009/10/02 19:02:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\acccore
[2008/07/24 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Ace
[2009/01/27 19:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Activision
[2010/01/15 08:41:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Aim
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Belkin
[2010/04/30 17:00:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Bioshock
[2010/08/13 08:27:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\dingogames
[2009/01/09 20:33:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GamesFaction
[2009/09/12 07:26:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\GrabPro
[2010/08/27 12:23:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Helios
[2007/03/22 21:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Leadertech
[2008/11/13 18:19:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Mushroom Age
[2011/12/20 10:04:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Orbit
[2009/05/21 15:08:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Pi Eye Games
[2009/02/06 19:34:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\PlayFirst
[2010/08/03 06:43:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\ProgSense
[2008/06/21 18:32:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sahmon Games
[2006/09/08 16:58:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\SampleView
[2008/02/08 15:19:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sierra Entertainment
[2011/02/11 16:37:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Sony Online Entertainment
[2009/10/30 17:14:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\Stardock
[2008/10/04 16:09:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\Application Data\StoneLoopsSW
[2008/09/05 18:57:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner.YOUR-880D7DC693\ApplicaLS\x00\x00\x00\x00

Attachments:

OTL Extras logfile created on: 12/23/2011 12:56:52 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.48 Mb Total Physical Memory | 553.87 Mb Available Physical Memory | 54.17% Memory free
2.40 Gb Paging File | 2.08 Gb Available in Paging File | 86.61% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 181.60 Gb Total Space | 128.20 Gb Free Space | 70.60% Space Free | Partition Type: NTFS
Drive D: | 4.70 Gb Total Space | 2.73 Gb Free Space | 57.98% Space Free | Partition Type: FAT32
Drive F: | 56.76 Gb Total Space | 7.22 Gb Free Space | 12.72% Space Free | Partition Type: NTFS
Drive G: | 76.37 Gb Total Space | 11.18 Gb Free Space | 14.64% Space Free | Partition Type: NTFS
Drive H: | 19.53 Gb Total Space | 11.46 Gb Free Space | 58.68% Space Free | Partition Type: NTFS
Drive M: | 111.79 Gb Total Space | 3.58 Gb Free Space | 3.20% Space Free | Partition Type: NTFS

Computer Name: GAMEBOX | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"58999:TCP" = 58999:TCP:*:Enabled:Pando Media Booster
"58999:UDP" = 58999:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"58999:TCP" = 58999:TCP:*:Enabled:Pando Media Booster
"58999:UDP" = 58999:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\drivers\svchost.exe" = %windir%\system32\drivers\svchost.exe:*:Enabled:svchost
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"G:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe" = G:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe:*:Enabled:Medal of Honor Pacific Assault™ – (Electronic Arts Inc.)
"G:\Program Files\EA GAMES\MOHAA\MOHAA.exe" = G:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault – (Electronic Arts Inc.)
"G:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe" = G:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:*:Enabled:Crysis_32_sp_demo – (Crytek GmbH)
"G:\Program Files\EA GAMES\MOHAA\moh_spearhead.exe" = G:\Program Files\EA GAMES\MOHAA\moh_spearhead.exe:*:Enabled:Medal of Honor Allied Assault™ Spearhead – (Electronic Arts Inc.)
"G:\Program Files\EA GAMES\MOHAA\moh_Breakthrough.exe" = G:\Program Files\EA GAMES\MOHAA\moh_Breakthrough.exe:*:Enabled:Medal of Honor Allied Assault™ Breakthrough – (Electronic Arts Inc.)
"G:\Program Files\Capcom\LOST_PLANET_TRIAL_DX9\LOST_PLANET_TRIAL_DX9\LostPlanetDX9.exe" = G:\Program Files\Capcom\LOST_PLANET_TRIAL_DX9\LOST_PLANET_TRIAL_DX9\LostPlanetDX9.exe:*:Enabled:LostPlanetDX9 – (CAPCOM CO., LTD.)
"G:\Program Files\THQ\Dawn Of War\W40k.exe" = G:\Program Files\THQ\Dawn Of War\W40k.exe:*:Enabled:W40k – (THQ Canada Inc.)
"G:\Program Files\THQ\Dawn Of War\W40kWA.exe" = G:\Program Files\THQ\Dawn Of War\W40kWA.exe:*:Enabled:W40kWA – (THQ Canada Inc.)
"G:\Program Files\Eidos\Conflict Denied Ops Demo\ConflictDeniedOps.exe" = G:\Program Files\Eidos\Conflict Denied Ops Demo\ConflictDeniedOps.exe:*:Enabled:Conflict: Denied Ops Demo – (Pivotal Games)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"G:\Combat Arms\NMService.exe" = G:\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core – (Nexon Corp.)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox – (Mozilla Corporation)
"C:\Program Files\LucasArts\Star Wars Republic Commando\GameData\System\SWRepublicCommando.exe" = C:\Program Files\LucasArts\Star Wars Republic Commando\GameData\System\SWRepublicCommando.exe:*:Enabled:SWRepublicCommando – ()
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"G:\Program Files\FireFly Studios\Stronghold\Stronghold.exe" = G:\Program Files\FireFly Studios\Stronghold\Stronghold.exe:*:Enabled:Stronghold – ()
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade – (GameSpy Industries, Inc.)
"C:\Program Files\THQ\DarkCrusade\DarkCrusade.exe" = C:\Program Files\THQ\DarkCrusade\DarkCrusade.exe:*:Enabled:DarkCrusade – (THQ Canada Inc.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe – (Hewlett-Packard)
"G:\Tri Synergy\Hired Guns\update.exe" = G:\Tri Synergy\Hired Guns\update.exe:*:Enabled:TrueUpdate Client – ()
"G:\Program Files\LucasArts\Star Wars Battlefront\GameData\Battlefront.exe" = G:\Program Files\LucasArts\Star Wars Battlefront\GameData\Battlefront.exe:*:Enabled:Battlefront – ()
"G:\Program Files\FireFly Studios\Stronghold 2 Demo\Stronghold2Demo.exe" = G:\Program Files\FireFly Studios\Stronghold 2 Demo\Stronghold2Demo.exe:*:Enabled:Stronghold 2 – (Firefly Studios)
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe" = C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe – (NVIDIA Corporation)
"C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\DeviceSetup.exe" = C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\DeviceSetup.exe:LocalSubNet:Enabled:HP Device Setup – (Hewlett-Packard Co.)
"C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe" = C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe:LocalSubNet:Enabled:HP Network Communicator – (Hewlett-Packard Co.)
"G:\Program Files\FireFly Studios\Stronghold Crusader\Stronghold Crusader.exe" = G:\Program Files\FireFly Studios\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader – ( )
"G:\Program Files\FireFly Studios\Stronghold Crusader\Stronghold_Crusader_Extreme.exe" = G:\Program Files\FireFly Studios\Stronghold Crusader\Stronghold_Crusader_Extreme.exe:*:Enabled:Stronghold Crusader Extreme – ( )
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Disabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"G:\Combat Arms\Engine.exe" = G:\Combat Arms\Engine.exe:*:Enabled:Combatarms – (Nexon)
"G:\Combat Arms\CombatArms.exe" = G:\Combat Arms\CombatArms.exe:*:Enabled:CombatarmsLauncher – (Nexon)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 SR-1 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0CAF318D-FD5E-4739-B480-DF26A1E4A7B2}" = Conflict: Denied Ops Demo
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0F3A1C5A-DA6A-4536-A058-CBB857CAC20C}" = Nostromo Array Programming Software
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{11F5D779-7BD9-465A-BBC4-10701386BCB9}" = FW LiveUpdate
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite Gateway
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{195F2C6C-A343-4b10-B1A4-3F00AB9E9DD9}" = Fax
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1C338B34-1BFB-4BAD-B4A3-7B71A2E221F6}" = GameTap Web Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Solution
"{20B30DC1-E423-4939-B51D-05C58B0F9BBB}" = HP Photosmart All-In-One Driver Software 10.0 Rel .2
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 24
"{2EC502F7-CBB0-44F8-8F5D-C9A6FC1E5A2A}" = LightScribe System Software
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{32F27FAA-60D1-4EC3-8502-51AEC72BF50F}" = DarkCrusade
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3AE5A1B4-D6AE-48D4-A07F-46A806CD53E6}" = HP Officejet Pro 8500 A910 Basic Device Software
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go 4.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}" = Medal of Honor Pacific Assault™
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5D95AD35-368F-47D5-B63A-A082DDF00111}" = Microsoft Digital Image Starter Edition 2006 Editor
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{679EC478-3FF9-4987-B2FF-C2C2B27532A2}" = DocProc
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{691F4068-81BF-49E3-B32E-FE3E16400111}" = Microsoft Digital Image Starter Edition 2006 Library
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B437F94-056F-4791-AF2C-0D10E2706AF0}" = PanoStandAlone
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}" = Multimedia Keyboard Driver
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7914BE1E-F186-4790-B8F4-9F63C52A41C1}" = Medal of Honor Allied Assault™ Spearhead
"{7EF15AAF-42AC-4CF6-B4B4-C4F0D1D92122}" = Far Cry (Patch 1.4)
"{80533B67-C407-485D-8B5D-63BB8ED9D878}" = Scan
"{823A68CC-3049-4A6B-8F63-7DC85E4BB1C9}" = Medal of Honor Allied Assault™ Breakthrough
"{824539D7-D27E-4CC3-B36F-6404B5EB726B}" = Medal of Honor Pacific Assault™ Patch2
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{871B2A9D-0F12-44B3-88C1-E0CB10A232E4}" = HP Officejet Pro 8500 A910 Help
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8C3727F2-8E37-49E4-820C-03B1677F53B6}" = Stronghold Crusader Extreme
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8F99E711-CE74-4718-BE04-19D1A53A735C}" = Warhammer 40,000: Dawn Of War - Platinum Edition
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{9262B08F-E183-4FED-A2BD-23FF1A84EB67}" = HPDiagnosticCoreDll
"{92AF2F5A-4407-4A03-A80A-5A2582264746}" = Crysis® SP Demo
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9862B19F-4CAD-4EED-920F-2F378D84393F}" = ATI Parental Control & Encoder
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{a1f89c34-f061-447d-ac10-b5f1896a5923}" = C4380_Help
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{ACDE260A-602B-4cfb-A650-D0DBA6FFAD85}" = NetDeviceManager
"{AD8A1013-4E46-4E02-85C2-3168C3328432}" = Symantec AntiVirus
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B29051F5-5D7D-443e-ABE9-7CBB29EAC200}" = C4380
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.95
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B6A1B7F8-E877-4352-B04A-FDC0B3EE9EA6}" = Dogfight - Battle for the Pacific
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{B8C3B479-1716-11D5-968A-0050BA84F5F7}" = Baldur's Gate™ II - Throne of Bhaal ™
"{b9be267c-e096-4cce-a4fd-f24eec004938}" = PS_AIO_02_ProductContext
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1583439-B034-4881-819C-D52A0587662B}" = Neverwinter Nights Platinum Edition
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{c4549405-195f-4450-8865-6be9dc5ad136}" = PS_AIO_02_Software_Min
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C6B7E731-A9E1-4AEC-A1E7-2E63646647FE}" = Prince of Persia Warrior Within (Demo)
"{C79CB9C7-10A4-4814-8402-F574672C2192}" = Star Wars Battlefront
"{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}" = Stronghold
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{cd0b9359-b716-4fd0-8e0a-09b3e312e8a4}" = PS_AIO_02_Software
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"{D992240F-649B-4DF7-8EC5-323D59ACC18B}" = Stronghold 2 Demo
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DFAE9340-E8BB-4433-9A08-C8334DAFE1B9}" = Star Wars Republic Commando
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F57A7C3E-AA0D-4F1A-B7EC-F7583571A517}" = DW6 Demo
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FC123EEA-330A-4685-911C-95B8F5E9DE68}" = Thief - Deadly Shadows
"{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}" = Folder Size for Windows
"3DGroove" = OTOY
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Age of Mythology 1.0" = Age of Mythology
"AIM_6" = AIM 6
"All ATI Software" = ATI - Software Uninstall Utility
"AnalogX NetStat Live" = AnalogX NetStat Live
"AOL Instant Messenger" = AOL Instant Messenger
"ATI Display Driver" = ATI Display Driver
"AVI Codec Pack" = AVI Codec Pack
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Belarc Advisor 2.0" = Belarc Advisor 7.2
"BFGC" = Big Fish Games Client
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F40&SUBSYS_200014F1" = Soft Data Fax Modem with SmartCP
"Combat Arms" = Combat Arms
"Diablo II" = Diablo II
"Divinity II - Ego Draconis - Demo_is1" = Divinity II - Ego Draconis - Demo
"DivX Setup" = DivX Setup
"Earth 2150 Demo" = Earth 2150 Demo
"ESET Online Scanner" = ESET Online Scanner v3
"Feeding Frenzy® 2: Shipwreck Showdown" = Feeding Frenzy® 2: Shipwreck Showdown
"FLV Player" = FLV Player 2.0 (build 25)
"Freelancer 1.0" = Freelancer
"GameSpy Arcade" = GameSpy Arcade
"HijackThis" = HijackThis 2.0.2
"Hired Guns1.07.000" = Hired Guns
"Hot Wheels" = Hot Wheels Screen Saver
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPOCR" = OCR Software by I.R.I.S. 10.0
"Impulse" = Impulse
"InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C}" = Call of Duty® - World at War™ 1.6 Patch
"InstallShield_{149464D9-B06F-4505-9968-FD1206F67AD3}" = Call of Duty® - World at War™ 1.3 Patch
"InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE}" = Call of Duty® - World at War™ 1.2 Patch
"InstallShield_{3BD633E0-4BF8-4499-9149-88F0767D449C}" = Call of Duty® 4 - Modern Warfare™ 1.4 Patch
"InstallShield_{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875}" = Digital Media Reader
"InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4}" = Call of Duty® - World at War™ 1.4 Patch
"InstallShield_{B6A1B7F8-E877-4352-B04A-FDC0B3EE9EA6}" = Dogfight - Battle for the Pacific
"InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E}" = Call of Duty® - World at War™ 1.5 Patch
"InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}" = Far Cry
"InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}" = Call of Duty® - World at War™
"InstallShield_{EF7E931D-DC84-471B-8DB6-A83358095474}" = EA Download Manager
"KLiteCodecPack_is1" = K-Lite Codec Pack 2.48 Full
"LiveReg" = LiveReg (Symantec Corporation)
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"LiveUpdate1.6" = LiveUpdate 1.6 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 8.0.1 (x86 en-US)" = Mozilla Firefox 8.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetDevil_LEGO_Universe_is1" = LEGO Universe
"Norton PC Checkup" = Norton PC Checkup
"NSS" = Norton Security Scan
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"Orbit_is1" = Orbit Downloader
"PerformanceTest 7_is1" = PerformanceTest v7.0
"PictureItSuiteTrial_v11" = Microsoft Digital Image Starter Edition 2006
"ratDVD" = ratDVD 0.78.1444
"Sacred_is1" = Sacred
"SK_USBMillenniumKeyboard" = USB Millennium Keyboard
"SystemRequirementsLab" = System Requirements Lab
"The Three Musketeers Game" = The Three Musketeers Game
"UnityWebPlayer" = Unity Web Player
"ViewpointMediaPlayer" = Viewpoint Media Player
"Warcraft II BNE" = Warcraft II BNE
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{F57A7C3E-AA0D-4F1A-B7EC-F7583571A517}" = DYNASTY WARRIORS 6 Playable Demo
"SOE-Clone Wars" = Clone Wars
"SOE-Free Realms" = Free Realms

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/1/2011 4:27:23 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\32788R22FWJFW\License\iexplore.exe (PID 3676) Time: Thursday, December 01,
2011 1:27:22 PM

Error - 12/1/2011 4:31:07 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\32788R22FWJFW\License\iexplore.exe (PID 2004) Time: Thursday, December 01,
2011 1:31:07 PM

Error - 12/1/2011 6:46:56 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711726
Description = Security Risk Found!Risk: Trojan.Gen.2 in File: C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP1\A0000165.dll
by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The
file was quarantined successfully.

Error - 12/1/2011 6:46:56 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711685
Description = Risk Found!Risk: Trojan.Gen.2 in File: C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP1\A0000165.dll
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 12/1/2011 6:47:07 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711731
Description = Security Risk Found!Risk: Trojan.Gen.2 in File: C:\System Volume Information\_restore{1E2B5DEE-A9DF-4BEB-80A4-D17E3B9C3CEA}\RP1\A0000165.dll
by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description:
The file was quarantined successfully.

Error - 12/2/2011 12:03:50 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\32788R22FWJFW\License\iexplore.exe (PID 1328) Time: Friday, December 02, 2011
9:03:50 AM

Error - 12/2/2011 12:05:08 PM | Computer Name = GAMEBOX | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec
AntiVirus\VPTray.exe Event Info: Terminate Process Action Taken: Blocked Actor Process:
C:\32788R22FWJFW\License\iexplore.exe (PID 3396) Time: Friday, December 02, 2011
9:05:08 AM

Error - 12/2/2011 12:29:15 PM | Computer Name = GAMEBOX | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error Initialization of the COM subsystem failed.
Error code: 0x8007041D

Error - 12/5/2011 9:03:07 PM | Computer Name = GAMEBOX | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.6148, fault address 0x0006969d.

Error - 12/5/2011 9:25:01 PM | Computer Name = GAMEBOX | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 6.0.2900.5512, faulting
module mshtml.dll, version 6.0.2900.6148, fault address 0x0006969d.

[ System Events ]
Error - 12/20/2011 1:31:34 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 3:44:44 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/23/2011 1:34:22 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7000
Description = The PLFlash DeviceIoControl Service service failed to start due to
the following error: %%2

Error - 12/23/2011 1:34:22 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Symantec AntiVirus service
to connect.

Error - 12/23/2011 1:34:41 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7022
Description = The HP CUE DeviceDiscovery Service service hung on starting.

Error - 12/23/2011 1:34:41 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep

Error - 12/23/2011 2:56:03 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/23/2011 2:56:15 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/23/2011 3:07:56 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/23/2011 3:09:03 PM | Computer Name = GAMEBOX | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127


< End of report >




aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-23 13:14:59
—————————–
13:14:59.343 OS Version: Windows 5.1.2600 Service Pack 3
13:14:59.343 Number of processors: 2 586 0x409
13:14:59.343 ComputerName: GAMEBOX UserName: Owner
13:15:01.000 Initialize success
13:17:55.843 AVAST engine defs: 11122301
13:21:20.390 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-17
13:21:20.390 Disk 0 Vendor: WDC_WD2000BB-22RDA0 20.00K20 Size: 190782MB BusType: 3
13:21:20.406 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP4T1L0-1f
13:21:20.406 Disk 1 Vendor: Maxtor_6Y160P0 YAR41VW0 Size: 156334MB BusType: 3
13:21:22.421 Disk 0 MBR read successfully
13:21:22.421 Disk 0 MBR scan
13:21:22.468 Disk 0 unknown MBR code
13:21:22.468 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 185955 MB offset 9879975
13:21:22.484 Disk 0 Partition 2 00 0B FAT32 RECOVERY 4824 MB offset 63
13:21:22.500 Disk 0 scanning sectors +390716865
13:21:22.562 Disk 0 scanning C:\WINDOWS\system32\drivers
13:21:37.562 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
13:21:42.281 Service scanning
13:21:43.562 Modules scanning
13:21:48.734 Module: C:\WINDOWS\system32\DRIVERS\serial.sys **SUSPICIOUS**
13:21:55.390 Disk 0 trace - called modules:
13:21:55.406 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x870c7f10]<<
13:21:55.406 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87364030]
13:21:55.406 3 CLASSPNP.SYS[f7570fd7] -> nt!IofCallDriver -> [0x87236a70]
13:21:55.421 \Driver\00000712[0x871bb5f0] -> IRP_MJ_CREATE -> 0x870c7f10
13:21:56.671 AVAST engine scan C:\WINDOWS
13:22:19.406 AVAST engine scan C:\WINDOWS\system32
13:22:20.453 File: C:\WINDOWS\system32\6to4v32.dll **INFECTED** Win32:Malware-gen
13:24:13.468 File: C:\WINDOWS\system32\NUSB3w32.dll **INFECTED** Win32:Malware-gen
13:25:07.656 File: C:\WINDOWS\system32\USB3Nw32.dll **INFECTED** Win32:Malware-gen
13:25:45.828 AVAST engine scan C:\WINDOWS\system32\drivers
13:26:05.093 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot [Rtk]
13:26:18.375 AVAST engine scan C:\Documents and Settings\Owner.YOUR-880D7DC693
13:39:41.578 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files\MBR.dat"
13:39:41.593 The log file has been saved successfully to "C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files\aswMBR.txt"
13:49:48.796 AVAST engine scan C:\Documents and Settings\All Users
13:53:23.109 Scan finished successfully
13:53:33.000 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files\MBR.dat"
13:53:33.015 The log file has been saved successfully to "C:\Documents and Settings\Owner.YOUR-880D7DC693\Desktop\Ping removal files\aswMBR.txt"
Hi BMan,

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you wish to continue we'll start with clearing up the .exe problem.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTL
O37 - HKCU\…exe [@ = DqF] – "C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe" -a "%1" %*
:Services

:Files
C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe
:Commands
[purity]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer



Next

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • OTL fix log
  • combofix log
How is the computer?

Thanks
Ugh, that's nasty, but rarely use this computer for anything secure, so I'd like to fix it. I ran the OJT again, here's the output. the exe is functioning again (Thank you!), but I missed the download rename and pulled down ComboFix.exe into my folder that I'm using for this project. Am I hosed? I deleted that copy (which never went to the Desktop). Or can I go ahead and pull it down again as jgh.exe directly to the desktop still? Thanks! ========== OTL ========== Registry key HKEY_CURRENT_USER\Software\Classes\.exe\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Classes\DqF\ deleted successfully. HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully! ========== SERVICES/DRIVERS ========== ========== FILES ========== File\Folder C:\Documents and Settings\Owner.YOUR-880D7DC693\Local Settings\Application Data\ncg.exe not found. ========== COMMANDS ========== OTL by OldTimer - Version 3.2.31.0 log created on 12232011_154210
Hmmm..I can't seem to get Symantec AV v10 to 'disable.' The method listed in the link above isn't working (right click, uncheck 'Enable Auto Protect'). when I do, it disbales for a second or so, then pops right back on. I've unchecked each 'auto-protect' flag in the configuration and confirmed they STAY unchecked, still nothing. Seen this before? If necessary, can I run ComboFix in Safe Mode where I can control if Symantec comes on at all?
I'll give it a try from Administrator instead of my normal User profile (although that should the same rights). If that doesn't work, I'll have to come up with something else or run ComboFix from Safe mode if that will work.
Hi BMan. Combofix can be ran in safe mode. If you want to run it safe mode be sure boot back to safe mode when combofix reboots your computer. Wait for it to complete and save the log. Boot back to normal windows and post the log. You probably won't be able to access Symantec to disable it but it won't be running anyway.
Hi, OldMan960,
Thanks for your patience, I was able to get it to run in Safe Mode and the results are promising. CF did initially note the rootkit infection seen earlier,but it doesn't appear to be finding it any longer…One odd note in the log:

Infected copy of c:\windows\system32\drivers\serial.sys was found and disinfected
Restored copy from - The cat found it :)

Not sure what to say about that… :-D

anyhow, please let me know what you think, I'm here all day.
Thanks, Bman

ComboFix 11-12-27.01 - Owner 12/27/2011 8:31.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.299 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
AV: AVG Anti-Virus *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Symantec AntiVirus Corporate Edition *Enabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\documents\setup.exe
c:\windows\$NtUninstallKB38979$
c:\windows\$NtUninstallKB38979$\2648678807
c:\windows\$NtUninstallKB38979$\791590765\@
c:\windows\$NtUninstallKB38979$\791590765\bckfg.tmp
c:\windows\$NtUninstallKB38979$\791590765\cfg.ini
c:\windows\$NtUninstallKB38979$\791590765\Desktop.ini
c:\windows\$NtUninstallKB38979$\791590765\keywords
c:\windows\$NtUninstallKB38979$\791590765\kwrd.dll
c:\windows\$NtUninstallKB38979$\791590765\L\xjiijbar
c:\windows\$NtUninstallKB38979$\791590765\lsflt7.ver
c:\windows\$NtUninstallKB38979$\791590765\U\00000001.@
c:\windows\$NtUninstallKB38979$\791590765\U\00000002.@
c:\windows\$NtUninstallKB38979$\791590765\U\00000004.@
c:\windows\$NtUninstallKB38979$\791590765\U\80000000.@
c:\windows\$NtUninstallKB38979$\791590765\U\80000004.@
c:\windows\$NtUninstallKB38979$\791590765\U\80000032.@
c:\windows\alcrmv.exe
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\NUSB3w32.dll
c:\windows\system32\USB3Nw32.dll
c:\windows\Update.bat
.
Infected copy of c:\windows\system32\drivers\serial.sys was found and disinfected
Restored copy from - The cat found it :)
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Service_6to4
——-\Legacy_NecUsb
——-\Service_NecUsb
.
.
((((((((((((((((((((((((( Files Created from 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))))
.
.
2011-12-27 15:22 . 2008-04-13 19:15 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2011-12-23 22:42 . 2011-12-23 22:42 ——– d—–w- C:\_OTL
2011-12-23 15:47 . 2011-12-23 15:47 94896 —-a-w- c:\windows\system32\drivers\02159170.sys
2011-12-20 17:48 . 2011-12-20 17:48 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-12-20 17:20 . 2011-12-20 17:20 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-12-15 23:39 . 2011-12-15 23:39 120320 —-a-w- c:\windows\system32\drivers\SSHDRV65.sys
2011-12-13 01:33 . 2011-12-13 01:33 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-13 01:32 . 2011-12-13 01:32 134104 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-12-13 01:32 . 2011-12-13 01:32 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-12-13 01:32 . 2011-12-13 01:32 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-12-13 01:32 . 2011-12-13 01:32 478168 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-12-13 01:32 . 2011-12-13 01:32 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-12-13 01:32 . 2011-12-13 01:32 1989592 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-12-13 01:32 . 2011-12-13 01:32 801752 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-12-01 21:34 . 2011-12-01 21:34 ——– d—–w- c:\program files\ESET
2011-11-28 15:48 . 2011-12-07 17:57 ——– d—–w- c:\windows\system32\NtmsData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-14 16:40 . 2011-06-09 01:25 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-06 01:00 . 2007-10-14 15:33 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2011-12-03 23:33 . 2011-10-23 17:18 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2011-11-23 13:25 . 2006-06-01 03:17 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 20:35 . 2006-06-01 03:17 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2006-06-01 03:17 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:35 . 2006-06-01 03:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-11-01 16:07 . 2006-06-01 03:16 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2006-06-01 03:16 369664 —-a-w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2006-06-01 03:16 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2006-06-01 03:16 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-04 05:59 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2006-06-01 03:16 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2006-06-01 03:30 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-08 04:50 . 2011-09-22 23:17 602432 —-a-w- c:\windows\system32\easyupdatusapiu.dll
2011-10-08 04:50 . 2011-01-07 01:30 919872 —-a-w- c:\windows\system32\nvdispco32.dll
2011-10-08 04:50 . 2011-01-07 01:30 877376 —-a-w- c:\windows\system32\nvgenco32.dll
2011-10-08 04:50 . 2010-10-16 19:04 54272 —-a-w- c:\windows\system32\nvwddi.dll
2011-10-08 04:50 . 2010-10-16 19:04 203072 —-a-w- c:\windows\system32\nvmctray.dll
2011-10-08 04:50 . 2010-10-16 19:04 16744256 —-a-w- c:\windows\system32\nvcpl.dll
2011-10-08 04:50 . 2010-10-16 19:04 298304 —-a-w- c:\windows\system32\nvsvc32.exe
2011-10-08 04:50 . 2010-10-16 19:04 220992 —-a-w- c:\windows\system32\nvcolor.exe
2011-10-08 04:50 . 2010-09-30 22:59 65536 —-a-w- c:\windows\system32\OpenCL.dll
2011-10-08 04:50 . 2010-09-30 22:59 17240064 —-a-w- c:\windows\system32\nvcompiler.dll
2011-10-08 04:50 . 2009-06-10 12:03 2099520 —-a-w- c:\windows\system32\nvcuvenc.dll
2011-10-08 04:50 . 2009-02-18 20:44 2398016 —-a-w- c:\windows\system32\nvcuvid.dll
2011-10-08 04:50 . 2007-12-05 08:41 5595136 —-a-w- c:\windows\system32\nvcuda.dll
2011-10-08 04:50 . 2006-08-12 01:43 2449408 —-a-w- c:\windows\system32\nvapi.dll
2011-10-08 04:50 . 2006-08-12 01:42 17956864 —-a-w- c:\windows\system32\nvoglnt.dll
2011-10-08 04:50 . 2006-08-12 01:42 4226688 —-a-w- c:\windows\system32\nv4_disp.dll
2011-10-08 04:50 . 2006-08-12 01:42 12791488 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2008-11-23 22:27 . 2008-11-23 22:27 16463 —-a-w- c:\program files\Common Files\vagawus.vbs
2008-11-20 17:27 . 2008-11-20 17:27 16036 —-a-w- c:\program files\Common Files\duxugi.sys
2008-11-20 17:27 . 2008-11-20 17:27 15737 —-a-w- c:\program files\Common Files\yrura.com
2008-11-20 16:49 . 2008-11-20 16:49 17831 —-a-w- c:\program files\Common Files\akisyfus.dll
2011-12-13 01:32 . 2011-12-13 01:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"CHotkey"="zHotkey.exe" [2004-12-09 550912]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"CTHelper"="CTHELPER.EXE" [2003-06-09 28672]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\FWManager.exe" [2009-07-16 692340]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-06-25 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2008-09-30 125368]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10c.exe" [2009-07-18 257440]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-6-23 442368]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Nostromo Loadout Manager.lnk - c:\windows\Installer\{548C7B77-8B04-427E-ACD0-D0E6E6E59BCF}\NewShortcut2_548C7B778B04427EACD0D0E6E6E59BCF.exe [2007-10-28 45056]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2010-3-1 1835069]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"g:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault™\\mohpa.exe"=
"g:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"g:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe"=
"g:\\Program Files\\EA GAMES\\MOHAA\\moh_spearhead.exe"=
"g:\\Program Files\\EA GAMES\\MOHAA\\moh_Breakthrough.exe"=
"g:\\Program Files\\Capcom\\LOST_PLANET_TRIAL_DX9\\LOST_PLANET_TRIAL_DX9\\LostPlanetDX9.exe"=
"g:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"g:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"g:\\Program Files\\Eidos\\Conflict Denied Ops Demo\\ConflictDeniedOps.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"g:\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Republic Commando\\GameData\\System\\SWRepublicCommando.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"g:\\Program Files\\FireFly Studios\\Stronghold\\Stronghold.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\THQ\\DarkCrusade\\DarkCrusade.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"g:\\Tri Synergy\\Hired Guns\\update.exe"=
"g:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe"=
"g:\\Program Files\\FireFly Studios\\Stronghold 2 Demo\\Stronghold2Demo.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"g:\\Program Files\\FireFly Studios\\Stronghold Crusader\\Stronghold Crusader.exe"=
"g:\\Program Files\\FireFly Studios\\Stronghold Crusader\\Stronghold_Crusader_Extreme.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"g:\\Combat Arms\\Engine.exe"=
"g:\\Combat Arms\\CombatArms.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58999:TCP"= 58999:TCP:Pando Media Booster
"58999:UDP"= 58999:UDP:Pando Media Booster
.
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2008-09-30 116664]
R3 XDva375;XDva375;c:\windows\system32\XDva375.sys [x]
S1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2011-12-15 120320]
S1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [2007-08-11 78848]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-08 2253120]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-07-23 22821]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-12-14 106104]
S3 Net6IM;Net6;c:\windows\system32\DRIVERS\net6im51.sys [2008-06-26 48280]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
NecUsbSevice REG_MULTI_SZ NecUsb
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 21:08 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2006-11-08 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-06-01 00:12]
.
2011-12-24 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\progra~1\NORTON~2\NORTON~1\Engine\301~1.8\Nss.exe [2011-01-15 06:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aol.com\free
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
DPF: {C8AEB218-8B7A-4E15-AC17-0EE8D99B80EB} - hxxp://ak.g.gametap.com/static/cab_headless/GameTapWebUpdater.cab
FF - ProfilePath - c:\documents and settings\Owner.YOUR-880D7DC693\Application Data\Mozilla\Firefox\Profiles\0mshh979.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.gisly.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=rWOh6jdt&q;=
FF - user.js: keyword.URL - hxxp://www.gisly.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=rWOh6jdt&q;=
.
- - - - ORPHANS REMOVED - - - -
.
Notify-NecUsb3Sevice - USB3Nw32.dll
Notify-USB3Nw32 - USB3Nw32.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-27 09:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3820171473-1669922343-3560239215-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:8f,22,f7,c8,4b,93,f3,11,f3,e4,62,89,1a,74,ec,fc,1a,df,ab,33,f3,e3,65,
b1,63,35,1b,fd,40,ef,8b,5f,07,23,de,72,21,06,e2,f9,c1,41,07,b6,81,d3,ec,bd,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3068)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\UAService7.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\zHotkey.exe
c:\windows\system32\CTHELPER.EXE
c:\windows\system32\RunDLL32.exe
c:\program files\Orbitdownloader\orbitnet.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-12-27 10:04:47 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-27 17:04
ComboFix2.txt 2011-12-02 16:39
ComboFix3.txt 2011-12-01 21:14
ComboFix4.txt 2011-12-01 15:10
ComboFix5.txt 2011-12-27 15:15
.
Pre-Run: 137,349,279,744 bytes free
Post-Run: 138,118,258,688 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 7CD39391AB48348338CD873245B8D064
Hi BMan,

Infected copy of c:\windows\system32\drivers\serial.sys was found and disinfected
Restored copy from - The cat found it

That's a good thing :thumbup: .

AV: AVG Anti-Virus *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

Did you at one time have AVG installed?


I need some information on a unidentified file. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

VirusTotal

copy and paste the following into the upload a file box (f you can't copy and paste the file path use the browse button)

c:\windows\system32\drivers\02159170.sys


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete.


Next
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • UNCheck the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following

    /md5start
    02159170.sys
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will opena notepad window, OTL.Txt, no Extras.Txt this time.


Please post back with
  • VirusTotal results
  • OTL.txt
What are the remaining issues?

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI